Apple's Safari Blocklist Broke Tracking, Not Your Campaign: A One-Hour Domain Audit
marketing October 8, 2026 · Mintec

Apple's Safari Blocklist Broke Tracking, Not Your Campaign: A One-Hour Domain Audit

iOS 27 blocks Safari from calling ad-tech domains like The Trade Desk's adsrvr.org, ID5, LiveRamp and Permutive, and Safari 27 adds IP-level blocking of Microsoft's ad servers plus fingerprinting restrictions on the LinkedIn Insight Tag. If your conversion volume dropped right after a phone update, the OS changed — not your audience. This is the one-hour domain audit we run to find which layer broke and what actually fixes it.

Apple's Safari Blocklist Broke Tracking, Not Your Campaign: A One-Hour Domain Audit

A tracking gap that opens the week your users upgrade their phones is an operating-system change, not a performance change — and the fix starts with an inventory of every domain your stack calls home, not a bid adjustment. iOS 27 shipped on September 14, 2026, and with it Safari began refusing cross-site requests to a list of ad-tech domains maintained by Apple outside the browser binary. The Trade Desk's core ad-delivery domain, adsrvr.org, is on it. So are identity and audience vendors used across the industry. Meanwhile Safari 27 adds connection-level blocking of Microsoft's ad servers and fingerprinting restrictions on the LinkedIn Insight Tag. Nothing in Ads Manager tells you any of this happened.

What Apple actually changed

Three separate mechanisms landed around the same time. They get conflated in coverage, and conflating them sends you to the wrong fix.

1. The domain blocklist. The hook is a WebKit pull request merged on February 13, 2026, which added an IS_REQUEST_UNCONDITIONALLY_BLOCKABLE check to the network process. Requests are judged by the registrable domain of their destination. Cross-site requests to a listed domain are refused; main-frame navigations and requests back to your own domain are exempt. The list itself sits in an Apple-internal file that is not in the public codebase — it ships through a system library and can change without a new iOS release.

The only public description of the contents comes from WebKit bug 324771, filed September 21, 2026 by an engineer at The Trade Desk, priority P1, platform iPhone and iPad. The ticket names eight vendor domains plus a placeholder: uidapi.com, adsrvr.org, id5-sync.com, eu-1-id5-sync.com, rlcdn.com, pippio.com, permutive.com and ad.gt. Trade coverage ties them to The Trade Desk and UID2, LiveRamp, ID5, Permutive and Audigent. As of October 8, nine entries were still listed and the bug status had not moved off NEW.

2. The expanded list. On October 2, AdExchanger reported — citing two sources with direct knowledge — that the original short list had been replaced by a library of hundreds of CDPs, ad-tech and martech vendors, data sellers and ID-graph operators. The full list sits in a private repository. Whether Google's ad.doubleclick.net is on it has not been confirmed; the publication is still checking.

3. Network-layer and fingerprinting blocking in Safari 27. A source-code review of WebKit's repository found a second layer that checks the destination IP address of an outbound connection and terminates it before any data leaves the device. Microsoft's bat.bing.com resolves into an ad-infrastructure range found blocked in the beta. Separately, the LinkedIn Insight Tag (snap.licdn.com) landed on the fingerprinting-classification list: it loses access to URL query parameters and referrer data, which means no click identifier can be read and no traffic source can be determined — even where the connection itself still opens. Customer data platforms including Tealium and Segment joined the same classification, and every tag they containerize inherits the restriction.

Why this reaches paid media even if you never bought programmatic

None of the eight domains in the public ticket is a Meta, Google or standard analytics collection endpoint. Read that twice before you panic: your Meta pixel and your GA4 tag are not on the reported list, and this article is not a "Meta broke" story. The exposure sits around your tags.

  • Identity and audience layers — ID graphs, enrichment, and audience platforms that sync segments server-to-server through browser calls. When those domains go dark, seed quality and match rates drift long before anyone notices a dashboard.
  • LinkedIn conversion measurement — the Insight Tag classified as fingerprinting means B2B accounts lose click IDs and referrer data inside Safari.
  • Microsoft Advertising — UET endpoint blocked at the network layer in the reviewed build.
  • Tag containers — a CDP-classified container restricts everything deployed through it, regardless of how each individual tag is configured.
  • Link Tracking Protection — Safari 27 adds Threads' xmt, YouTube's si and X's twclid, cn and cxt to the strip list in Private Browsing, Mail and Messages, with normal-session enforcement following the pattern Apple has used before: list first, enforcement later. Google and Meta click IDs were already covered.

The volume makes it impossible to shrug off. Safari holds roughly 17-18% of global page views and about a quarter of mobile traffic in current StatCounter-based tallies. On an iOS-heavy account with meaningful LinkedIn or Microsoft spend, that is not a rounding error in your conversion column.

The bug ticket also names iPhone and iPad only — macOS behavior is unconfirmed, and browsers on iOS use WebKit regardless of brand, with alternative engines permitted only in the EU. Scope differs by market.

The one-hour domain audit

This is the checklist we run on a client stack when conversion volume moves without a campaign change. It has five passes and needs one analyst with a network panel open.

Pass 1 — Inventory every outbound domain (20 min). Open your site in Safari with the network panel recording, then load the same pages in Chrome for comparison. Export from your tag manager, your CDP config, your server-side container, and your consent platform. You are building one list: every third-party registrable domain any tag, pixel, beacon or sync calls.

Pass 2 — Classify by blocking layer (15 min). Not all blocks behave alike, and the symptom tells you which layer you hit:

LayerMechanismWhat you actually see
Domain blocklistRequest refused by registrable domain, cross-site onlyVendor tag never fires in Safari; zero requests in the panel; other browsers unaffected
IP-range blockConnection terminated at the network transport layerDNS resolves, request starts, connection dies; works on desktop or off-device
Fingerprinting classificationScript loses query parameters and referrerTag fires but sends no click ID and no traffic source; conversions de-dupe or go unattributed
Click-ID strippingParameter removed from the URL before navigationShared links and UTM-tagged journeys lose their identifier only in Safari sessions

Pass 3 — Map each hit to what it costs (10 min). Ask of every blocked domain: was it delivering ads, resolving identity, enriching an audience, or measuring a conversion? Delivery and identity losses do not show up as tracking errors — they show up as auctions you never entered and segments that quietly stop matching. Measurement losses show up as the attribution gap itself.

Pass 4 — Check the platform tags by name (10 min). Test the LinkedIn Insight Tag for click-ID and referrer loss. Test bat.bing.com for a cut connection. Confirm whether your CDP container is classified as fingerprinting, because if it is, everything inside it is restricted regardless of per-tag configuration.

Pass 5 — Reconcile against a system with no attribution opinion (5 min). Compare the affected period against orders or CRM records, not against another dashboard. A Safari-only gap with flat CRM revenue is a measurement fault. We covered how to read that split in Meta and GA4 Disagree on Purpose, and the same rule applies here.

What actually fixes each layer

Move conversion calls off the browser. This is the reliable fix and it works for the same reason every time: the request Safari would intercept never originates in the browser. LinkedIn's Conversions API replaces the Insight Tag's browser call; the Microsoft Ads API replaces UET; server-side tagging routes your own events through a server you control. This is the architecture we already recommend as standard — see the March attribution rebuild and why the pixel alone misses 30-60% of events.

Do not assume server-side solves everything. This is where most coverage overpromises. Server-side routing delivers a record that already exists — but if Safari blocks a browser call before any first-party record exists, there is nothing to forward. Server-side also cannot restore cross-site identity synchronization or ad delivery whose entire purpose was a cross-site browser call. Those need a vendor-level answer: a different enrichment path, a server-to-server audience integration, or acceptance that the segment shrinks.

First-party proxying will not save a blocked connection. Loading a vendor script from your own subdomain is the standard workaround for domain-level restrictions. It does not work against IP-range blocking, because the check targets the destination address, not the script's origin.

For audiences, verify rather than assume. If any domain in your enrichment or audience-sync chain is listed, your lookalike seed quality decays — which eventually shows up as unstable delivery rather than a clean error. That pattern overlaps with what we documented in the Event Match Quality breakdown, and before you blame a platform for bad traffic, the four-check diagnostic separates OS-level signal loss from genuinely bad placements.

What we tell clients this week

Three opinions, in order of how much pushback they usually get.

Stop chasing Apple's list. It is private, it has already grown from a handful to hundreds of entries, and it can change without an OS release. Any article that publishes the current contents is describing a snapshot that may be stale before you finish reading it. Inventory your own domains — the only list you can act on is the one built from your stack.

Do not rebuild campaigns mid-storm. If Safari conversions dipped in late September, the first move is the audit, not a bid or budget change. We watched accounts take exactly this wrong turn in previous rollouts: performance teams optimize into a measurement fault and spend two weeks teaching the algorithm on degraded signal.

Treat server-side as the default, not the emergency. Accounts that already ran pixel plus Conversions API with deduplication absorbed this rollout as a rounding error. Accounts running browser-only tracking are learning, again, that the browser is the least durable place to hang a measurement strategy.

What is still unresolved

Apple offered a beta test, not a fix. On October 5 an Apple engineer asked The Trade Desk to test an iOS 27.2 build on the public bug tracker — the first two-way exchange on the subject — while conceding nothing about what changed, whether the other entries moved, or whether the change reaches the production release. The bug remains open at P1.

Two questions will decide how much this matters by Q1: whether the expanded list includes the big programmatic and analytics endpoints trade press is still trying to confirm, and whether macOS inherits the same treatment. Meanwhile publishers, per Digiday's October 8 reporting, are moving audience work back to IAB Tech Lab's Trusted Server after eighteen months of ignoring it — which tells you how seriously the supply side reads this.

Until Apple confirms scope, the discipline is the same: know every domain your stack calls, know which layer could cut it, and make sure the layer that matters most — conversion measurement — never depends on a browser that updates itself.

FAQ

How do I know if my tracking is affected by the Safari blocklist? Load your conversion pages in Safari with the network panel open and compare against Chrome. A vendor request that fires in Chrome and never appears in Safari is a domain-level block. A tag that fires in both but sends no click ID in Safari is fingerprinting classification. If only UTM-tagged parameters are missing, it is link tracking protection. The symptom identifies the layer, and the layer determines the fix.

Is this why my LinkedIn conversions dropped? It is a plausible cause if the drop started after users upgraded to iOS 27 and you are running the Insight Tag without LinkedIn's Conversions API. Check whether your Safari traffic still sends click IDs and referrer data before drawing conclusions — the tag fires, it just sends less.

Should we pause our LinkedIn or Microsoft campaigns until this is resolved? No. The measurement layer degraded; the auctions did not. Moving conversions server-side restores most of the signal within a day, and pausing spend hands your competitors the impressions you paid to build history on.

Frequently Asked Questions

What did Apple block in Safari with iOS 27?

Safari now refuses cross-site requests to a list of ad-tech domains that lives in an Apple-maintained system library. The public WebKit bug report names eight vendor domains plus a placeholder — including adsrvr.org (The Trade Desk), id5-sync.com, rlcdn.com, permutive.com and ad.gt — and trade reporting says the list has since grown to hundreds of data and ad-tech vendors. Safari 27 also cuts connections to some Microsoft ad-server IP ranges and classifies scripts like the LinkedIn Insight Tag as fingerprinting utilities.

Does the Safari blocklist affect Meta and Google conversion tracking?

None of the domains named in the public bug ticket is a Meta, Google or standard analytics collection endpoint, so this is not a Meta pixel or GA4 story. What is exposed is the identity, audience and CDP layer around your tags — plus the LinkedIn Insight Tag and Microsoft's UET endpoint specifically. Whether Google's ad.doubleclick.net sits on Apple's expanded list has not been confirmed.

How do you fix conversion tracking blocked by Safari 27?

Move the conversion call off the browser: route it through your own server into the platform's Conversions API — LinkedIn CAPI for the Insight Tag, the Microsoft Ads API for UET, server-side tagging for your own events. Server-side routing works because the request Safari would intercept never originates in the browser. It does not restore cross-site identity sync or ad delivery that a blocked domain was responsible for, so audiences and enrichment need their own check.

Related Articles

Meta Can Now Show an AI-Generated Page Instead of Yours. Here Is What It Does to Your Data.
marketingOct 4, 2026

Meta Can Now Show an AI-Generated Page Instead of Yours. Here Is What It Does to Your Data.

Meta is testing a Landing Page Experience Enhancement that uses AI to build a visual landing page from your website and may show it to people who tap your ad instead of your site. It sits behind the 'test new AI generation features' switch in Advertising Settings, Meta caps those tests at fewer than 5% of ad impressions, and as of October 2026 there is no public documentation on whether your pixel, GA4 or forms ever fire on it.

Read Article →Mintec.Blog
Meta's AI Now Creates Your Conversion Events. Here's the Audit That Keeps the Signal Clean.
marketingOct 1, 2026

Meta's AI Now Creates Your Conversion Events. Here's the Audit That Keeps the Signal Clean.

Since August 3, 2026 every new Meta pixel is provisioned with Automatic Events switched on, letting Meta's AI identify and add missing standard events like Purchase and Lead from your site. Here is what actually changed, the three ways an AI-invented conversion corrupts optimization, and the five-step Events Manager audit we run before that signal touches a live campaign.

Read Article →Mintec.Blog
Your Event Match Quality Is Below 7.0? Here's How Meta Silently Punishes Your Ad Performance
marketingJul 28, 2026

Your Event Match Quality Is Below 7.0? Here's How Meta Silently Punishes Your Ad Performance

Meta requires an Event Match Quality score above 70% for reliable attribution, yet most advertisers never check theirs. After auditing 15+ client accounts, we found EMQ below 6.0 is the #1 hidden cause of unstable campaigns — worse than bad creative. Here's how EMQ actually works, the benchmarks that matter, and how to fix it with Conversions API Gateway.

Read Article →Mintec.Blog