Clarity tracking disabled: domain not authorized and cross-origin iframe data collection
0 reputation · 01 Jan 2025, 06:29 UTC
Clarity deployment diagnostics are anchored to documented failure signals in the JavaScript loader and the interaction reporting component. The relevant signals include domain authorization checks, script load errors, and content security policy enforcement.
Documentation describes a console message when a site domain is not added to the Clarity project, and notes that an incorrect script URL or CDN block can result in a 404 for the script request. CSP restrictions such as script-src can produce a CSP violation log entry that prevents loading. Do-Not-Track handling is stated as ignored, though the exact implementation details are not fully documented. An unresolved behavior concerns interaction data from content rendered inside cross-origin iframes; documentation references limitations without a definitive statement on whether events are collected, filtered, or omitted.
What conditions distinguish the domain not authorized message from a 404 script load failure in the loader? Is interaction data from a Clarity-enabled page ever transmitted when the page is embedded in a cross-origin iframe, and how is that distinguished from first-party events? How is Do-Not-Track header handling implemented across script tag and async loader integrations?