DSW

dsw.com

Compare

https://dsw.com

Scanned Apr 17, 2026 · 37.1s

Your website score is

0/100
Critical

Grade

F0

Banner

No

Regulatory Compliance

Multi-regulation overview — click any regulation for details

Technical scan only. A passing score does not equal legal compliance. Consult qualified legal counsel for your jurisdiction.

Tag Leak detected 27 user data leaks before consent on dsw.com, including Optimizely, Signifyd (Tracker Tracker), Advertising Tracker and 1 more.

Security Headers

0/6 present

Strict-Transport-Security

Add HSTS header to enforce HTTPS connections and prevent downgrade attacks

Content-Security-Policy

Add a Content-Security-Policy header to prevent XSS and code injection attacks

X-Frame-Options

Add X-Frame-Options header to prevent clickjacking attacks

X-Content-Type-Options

Set X-Content-Type-Options to 'nosniff' to prevent MIME type sniffing

Referrer-Policy

Set a Referrer-Policy header to control how much referrer information is shared

Permissions-Policy

Add a Permissions-Policy header to restrict browser features like camera, microphone, and geolocation

Google Consent Mode

Not Detected

Google Consent Mode v2 was not found on this page. GCM v2 allows Google's tags to adjust their behavior based on user consent, and is required for compliant advertising measurement in the EU. Without it, your Google Ads and GA4 conversions may be impacted after consent is declined.

Post-Rejection Audit

Reject Button

Missing

Post-Rejection Fires

0 vendors

Consent Mode

Not Detected

GTM Load

Not detected

Consent Mode V2: Not Detected

Google Consent Mode was not detected on this site.

Consent Record Audit

Pass

Consent record stored after interaction

GDPR Art. 7(1)

Found: OptanonConsent (OneTrust)

Record contains timestamp

Art. 7(1)

Timestamp field detected

Record contains consent state

Art. 7(1)

Accept/reject state detected

Record contains consent categories

Art. 7(1)

Consent categories (analytics, marketing, etc.) not found in record

Consent withdrawal mechanism accessible

GDPR Art. 7(3)

Cookie settings link / floating button found

Consent record and withdrawal mechanism are both correctly implemented

Tracker categories detected

Advertising7 vendors
Analytics5 vendors
Marketing12 vendors
Security6
Functional3 vendors
Critical10

Data was transmitted to a third-party or storage was written on the user’s device before consent. This is a GDPR/ePrivacy violation, not just a script load.

Optimizely
Optimizely2 findings

cdn.optimizely.com, logx.optimizely.com

Optimizely
criticalNetworkAnalyticsOptimizely

Optimizely (Optimizely) loaded before consent: Optimizely experimentation and A/B testing

Host: cdn.optimizely.comFired: 2621ms after load
Optimizely
criticalNetworkAnalyticsOptimizely

Optimizely (Optimizely) loaded before consent: Optimizely event logging endpoint

Host: logx.optimizely.comFired: 6222ms after load
Signifyd (Tracker Tracker)
Signifyd (Tracker Tracker)2 findings

cdn-scripts.signifyd.com, dp.signifyd.com

Signifyd (Tracker Tracker)
criticalNetworkSignifyd (Tracker Tracker)

Signifyd (tracker) loaded before consent

Host: cdn-scripts.signifyd.comFired: 2621ms after load
Signifyd (Tracker Tracker)
criticalNetworkSignifyd (Tracker Tracker)

Signifyd (tracker) loaded before consent

Host: dp.signifyd.comFired: 5329ms after load
Advertising Tracker
criticalNetworkAdvertisingAdvertising Tracker

advertising tracker at imgs.signifyd.com loaded before consent

Host: imgs.signifyd.comFired: 3218ms after load
RELX (Tracker Tracker)
RELX (Tracker Tracker)3 findings

h.online-metrix.net, h64.online-metrix.net, w2txo5aasxrqhysv76nli3n3yi3ymeajgsywmn3sc2804d48b5f57943am1.e.aa.online-metrix.net

RELX (Tracker Tracker)
criticalNetworkRELX (Tracker Tracker)

RELX (tracker) loaded before consent

Host: h.online-metrix.netFired: 4202ms after load
RELX (Tracker Tracker)
criticalNetworkRELX (Tracker Tracker)

RELX (tracker) loaded before consent

Host: h64.online-metrix.netFired: 4252ms after load
RELX (Tracker Tracker)
criticalNetworkRELX (Tracker Tracker)

RELX (tracker) loaded before consent

Host: w2txo5aasxrqhysv76nli3n3yi3ymeajgsywmn3sc2804d48b5f57943am1.e.aa.online-metrix.netFired: 4316ms after load
criticalNetwork

No consent banner detected — all cookies and tags fire without user consent

criticalConsent

No "reject all" option found — users cannot refuse non-essential cookies (ICO guidance requires this)

Warnings18

A tag container or script loaded before consent but tags appear correctly gated (e.g. GTM with Consent Mode v2). Not a violation on its own — review to confirm downstream tags stay blocked.

vendor logo
warningNetwork

Unknown third-party request to js.braintreegateway.com before consent

Host: js.braintreegateway.comFired: 403ms after load
vendor logo
warningNetwork

Unknown third-party request to a40.usablenet.com before consent

Host: a40.usablenet.comFired: 466ms after load
vendor logo
warningNetwork

Unknown third-party request to product-initjs.prod.rfksrv.com before consent

Host: product-initjs.prod.rfksrv.comFired: 568ms after load
vendor logo
warningNetwork

Unknown third-party request to prod-east-alweb-mt.rfksrv.com before consent

Host: prod-east-alweb-mt.rfksrv.comFired: 1006ms after load
vendor logo
warningNetwork

Unknown third-party request to applepay.cdn-apple.com before consent

Host: applepay.cdn-apple.comFired: 2621ms after load
vendor logo
warningNetwork

Unknown third-party request to assets.designerbrands.com before consent

Host: assets.designerbrands.comFired: 5030ms after load
warningStorage

sessionStorage key "sentryReplaySession" written before consent

Key: sentryReplaySessionType: sessionStorageFired: 882ms after load
warningStorage

sessionStorage key "statusFrameState.previewVisitorContext" written before consent

Key: statusFrameState.previewVisitorContextType: sessionStorageFired: 2522ms after load
warningStorage

sessionStorage key "visualSearchState" written before consent

Key: visualSearchStateType: sessionStorageFired: 2522ms after load
warningStorage

sessionStorage key "sameDayDeliveryState" written before consent

Key: sameDayDeliveryStateType: sessionStorageFired: 2522ms after load
warningStorage

sessionStorage key "isPdpReloaded" written before consent

Key: isPdpReloadedType: sessionStorageFired: 2586ms after load
warningStorage

sessionStorage key "signifydId" written before consent

Key: signifydIdType: sessionStorageFired: 2586ms after load
warningStorage

localStorage key "__test__localStorage__" written before consent

Key: __test__localStorage__Type: localStorageFired: 2696ms after load
warningStorage

localStorage key "__paypal_storage__" written before consent

Key: __paypal_storage__Type: localStorageFired: 2697ms after load
warningStorage

localStorage key "ed73f20edbf2b74" written before consent

Key: ed73f20edbf2b74Type: localStorageFired: 3207ms after load
warningStorage

localStorage key "active_experiments" written before consent

Key: active_experimentsType: localStorageFired: 4922ms after load
warningStorage

sessionStorage key "paymentState" written before consent

Key: paymentStateType: sessionStorageFired: 5193ms after load
warningStorage

localStorage key "fs_optly_pending_events" written before consent

Key: fs_optly_pending_eventsType: localStorageFired: 6217ms after load
Info4

Neutral observations — activity we detected that isn’t a violation but is useful context (e.g. essential cookies, CMP initialisation).

Paypal (Cdn)
infoNetworkPaypal (Cdn)

Paypal (cdn) loaded before consent

Host: www.paypal.comFired: 406ms after load
Sentry
infoNetworkAnalyticsSentry

Sentry (Sentry) loaded before consent: Sentry error reporting endpoint

Host: o4505784036032512.ingest.sentry.ioFired: 948ms after load
AfterPay (Cdn)
infoNetworkAfterPay (Cdn)

AfterPay (cdn) loaded before consent

Host: portal.afterpay.comFired: 2621ms after load
infoCookieFunctional

DataDome bot protection — necessary for site security

Cookie: datadomeDomain: .dsw.com
Compliant41

Tags that fired only after the user gave consent — working as intended.

Snapchat
CompliantCookieFunctionalSnapchat

Snapchat cookie "X-AB" set correctly after consent

Cookie: X-ABDomain: sc-static.netRetention: 1 day
Adobe Audience Manager
Adobe Audience Manager3 findings

demdex, AMCVS_A8683BC75245AF560A490D4D%40AdobeOrg, dpm

Adobe Audience Manager
CompliantCookieMarketingAdobe Audience Manager

Adobe Audience Manager cookie "demdex" set correctly after consent

Cookie: demdexDomain: .demdex.netRetention: 180 days after last activity or 10 years when opting out
Adobe Audience Manager
CompliantCookieMarketingAdobe Audience Manager

Adobe Audience Manager cookie "AMCVS_A8683BC75245AF560A490D4D%40AdobeOrg" set correctly after consent

Cookie: AMCVS_A8683BC75245AF560A490D4D%40AdobeOrgDomain: .dsw.comRetention: Session
Adobe Audience Manager
CompliantCookieMarketingAdobe Audience Manager

Adobe Audience Manager cookie "dpm" set correctly after consent

Cookie: dpmDomain: .dpm.demdex.netRetention: 180 days
Adform
Adform2 findings

uid, c

Adform
CompliantCookieMarketingAdform

Adform cookie "uid" set correctly after consent

Cookie: uidDomain: .turn.comRetention: 60 days
Adform
CompliantCookieMarketingAdform

Adform cookie "c" set correctly after consent

Cookie: cDomain: .creativecdn.comRetention: 60 days till 3650 days
TikTok Pixel
TikTok Pixel5 findings

_ttp, _tt_enable_cookie, tt_sessionId, tt_appInfo, tt_pixel_session_index

TikTok Pixel
CompliantCookieAdvertisingTikTok Pixel

TikTok Pixel cookie "_ttp" set correctly after consent

Cookie: _ttpDomain: .tiktok.com
TikTok Pixel
CompliantCookieAdvertisingTikTok Pixel

TikTok Pixel cookie "_tt_enable_cookie" set correctly after consent

Cookie: _tt_enable_cookieDomain: .dsw.com
TikTok Pixel
CompliantStorageAdvertisingTikTok Pixel

TikTok Pixel (TikTok) wrote "tt_sessionId" to sessionStorage correctly after consent

Key: tt_sessionIdType: sessionStorageFired: -22829ms after load
TikTok Pixel
CompliantStorageAdvertisingTikTok Pixel

TikTok Pixel (TikTok) wrote "tt_appInfo" to sessionStorage correctly after consent

Key: tt_appInfoType: sessionStorageFired: -22769ms after load
TikTok Pixel
CompliantStorageAdvertisingTikTok Pixel

TikTok Pixel (TikTok) wrote "tt_pixel_session_index" to sessionStorage correctly after consent

Key: tt_pixel_session_indexType: sessionStorageFired: -22762ms after load
Adobe Advertising
CompliantCookieMarketingAdobe Advertising

Adobe Advertising cookie "everest_g_v2" set correctly after consent

Cookie: everest_g_v2Domain: .everesttech.netRetention: 2 years
Adobe Analytics
Adobe Analytics2 findings

s_ecid, AMCV_A8683BC75245AF560A490D4D%40AdobeOrg

Adobe Analytics
CompliantCookieMarketingAdobe Analytics

Adobe Analytics cookie "s_ecid" set correctly after consent

Cookie: s_ecidDomain: .dsw.comRetention: 2 years
Adobe Analytics
CompliantCookieAnalyticsAdobe Analytics

Adobe Analytics cookie "AMCV_A8683BC75245AF560A490D4D%40AdobeOrg" set correctly after consent

Cookie: AMCV_A8683BC75245AF560A490D4D%40AdobeOrgDomain: .dsw.com
Snapchat Pixel
Snapchat Pixel2 findings

_scid, _scid_r

Snapchat Pixel
CompliantCookieAdvertisingSnapchat Pixel

Snapchat Pixel cookie "_scid" set correctly after consent

Cookie: _scidDomain: .dsw.com
Snapchat Pixel
CompliantCookieAdvertisingSnapchat Pixel

Snapchat Pixel cookie "_scid_r" set correctly after consent

Cookie: _scid_rDomain: .dsw.com
Amazon Web Services
CompliantCookieFunctionalAmazon Web Services

Amazon Web Services cookie "AWSALBCORS" set correctly after consent

Cookie: AWSALBCORSDomain: dsw.am3t9s.netRetention: Session
LinkedIn
CompliantCookieMarketingLinkedIn

LinkedIn cookie "brwsr" set correctly after consent

Cookie: brwsrDomain: .am3t9s.netRetention: 2 years
Snowplow3 findings

_sp_ses.77b1, _sp_id.77b1, sp

CompliantCookieAnalyticsSnowplow

Snowplow cookie "_sp_ses.77b1" set correctly after consent

Cookie: _sp_ses.77b1Domain: .dsw.comRetention: 30 minutes
CompliantCookieAnalyticsSnowplow

Snowplow cookie "_sp_id.77b1" set correctly after consent

Cookie: _sp_id.77b1Domain: .dsw.comRetention: 2 years
CompliantCookieAnalyticsSnowplow

Snowplow cookie "sp" set correctly after consent

Cookie: spDomain: t.getletterpress.comRetention: 1 year
Reddit Pixel
CompliantCookieAdvertisingReddit Pixel

Reddit Pixel cookie "_rdt_uuid" set correctly after consent

Cookie: _rdt_uuidDomain: .dsw.com
Neustar
CompliantCookieMarketingNeustar

Neustar cookie "ab" set correctly after consent

Cookie: abDomain: .agkn.comRetention: 1 year
Braze
Braze2 findings

ab.storage.sessionId.e48d56a6-2d88-46de-bc1a-bccd8f79536a, ab.storage.deviceId.e48d56a6-2d88-46de-bc1a-bccd8f79536a

Braze
CompliantCookieAnalyticsBraze

Braze cookie "ab.storage.sessionId.e48d56a6-2d88-46de-bc1a-bccd8f79536a" set correctly after consent

Cookie: ab.storage.sessionId.e48d56a6-2d88-46de-bc1a-bccd8f79536aDomain: .dsw.comRetention: Session
Braze
CompliantCookieAnalyticsBraze

Braze cookie "ab.storage.deviceId.e48d56a6-2d88-46de-bc1a-bccd8f79536a" set correctly after consent

Cookie: ab.storage.deviceId.e48d56a6-2d88-46de-bc1a-bccd8f79536aDomain: .dsw.comRetention: Unknown
CompliantCookieFunctionalPayPal

PayPal cookie "ts" set correctly after consent

Cookie: tsDomain: .creativecdn.comRetention: 3 years
CompliantCookieMarketingCreativeCDN

CreativeCDN cookie "g" set correctly after consent

Cookie: gDomain: .creativecdn.comRetention: 364 days
Meta Pixel
CompliantCookieAdvertisingMeta Pixel

Meta Pixel cookie "_fbp" set correctly after consent

Cookie: _fbpDomain: .dsw.com
DoubleClick/Google Marketing
DoubleClick/Google Marketing2 findings

ar_debug, IDE

DoubleClick/Google Marketing
CompliantCookieMarketingDoubleClick/Google Marketing

DoubleClick/Google Marketing cookie "ar_debug" set correctly after consent

Cookie: ar_debugDomain: .pinterest.comRetention: Persistent
DoubleClick/Google Marketing
CompliantCookieMarketingDoubleClick/Google Marketing

DoubleClick/Google Marketing cookie "IDE" set correctly after consent

Cookie: IDEDomain: .doubleclick.netRetention: 2 years
Pinterest Tag
CompliantCookieAdvertisingPinterest Tag

Pinterest Tag cookie "_pin_unauth" set correctly after consent

Cookie: _pin_unauthDomain: .dsw.com
Microsoft Ads
Microsoft Ads2 findings

_uetsid, _uetvid

Microsoft Ads
CompliantCookieAdvertisingMicrosoft Ads

Microsoft Ads cookie "_uetsid" set correctly after consent

Cookie: _uetsidDomain: .dsw.com
Microsoft Ads
CompliantCookieAdvertisingMicrosoft Ads

Microsoft Ads cookie "_uetvid" set correctly after consent

Cookie: _uetvidDomain: .dsw.com
Bing / Microsoft
CompliantCookieMarketingBing / Microsoft

Bing / Microsoft cookie "MUID" set correctly after consent

Cookie: MUIDDomain: .bing.comRetention: 1 year
Pinterest
CompliantCookieMarketingPinterest

Pinterest cookie "_pinterest_ct_ua" set correctly after consent

Cookie: _pinterest_ct_uaDomain: .ct.pinterest.comRetention: session
OneTrust
CompliantCookieConsent MgmtOneTrust

OneTrust cookie "OptanonConsent" set correctly after consent

Cookie: OptanonConsentDomain: .www.dsw.com
Xandr
Xandr3 findings

XANDR_PANID, uuid2, anj

Xandr
CompliantCookieMarketingXandr

Xandr cookie "XANDR_PANID" set correctly after consent

Cookie: XANDR_PANIDDomain: .adnxs.comRetention: 400 days
Xandr
CompliantCookieMarketingXandr

Xandr cookie "uuid2" set correctly after consent

Cookie: uuid2Domain: .adnxs.comRetention: 90 days
Xandr
CompliantCookieMarketingXandr

Xandr cookie "anj" set correctly after consent

Cookie: anjDomain: .adnxs.comRetention: 90 days
TikTok
TikTok2 findings

ttcsid, ttcsid_C85RVFVV9S6R0CDU8610

TikTok
CompliantCookieMarketingTikTok

TikTok cookie "ttcsid" set correctly after consent

Cookie: ttcsidDomain: .dsw.comRetention: 1 year
TikTok
CompliantCookieMarketingTikTok

TikTok cookie "ttcsid_C85RVFVV9S6R0CDU8610" set correctly after consent

Cookie: ttcsid_C85RVFVV9S6R0CDU8610Domain: .dsw.comRetention: 1 year

Is this your site?

Run a full multi-page scan with monitoring and get detailed remediation steps

Scan dsw.com

This audit is based on publicly observable website behavior. To request removal from the index, email support@tagleak.com