How ETP works
Firefox ships with Enhanced Tracking Protection switched on, so nobody has to choose it. The browser keeps a list of domains known to follow people from site to site. When a page asks for a script, an image or a cookie from one of those domains, Firefox refuses the request. The visitor sees a normal page and never learns anything was blocked.
Three settings sit behind it. Standard is the default and covers known cross-site trackers, cryptominers and tracking cookies inside private windows. Strict blocks further categories, including analytics scripts that Standard allows, and that is where most of the measurement damage happens. Custom lets someone pick category by category. Firefox also partitions cookies, so a cookie set while a person is on one site cannot be read from another — cross-site linking breaks even when the script itself loads.
None of this depends on the visitor doing anything. There is no prompt, no banner, and nothing a site owner can set to influence it.
Why ETP matters
Every blocked request is a real person who arrived, read your page and perhaps bought something, without ever appearing in your reports. The loss is not spread evenly. It lands on people who chose a privacy-minded browser, and it lands hardest on remarketing lists, cross-site audiences and any measurement that depends on a tag served from a domain other than your own.
It also explains a gap you would otherwise argue about for months. Ad platforms count conversions their own way, analytics counts them another way, and browser blocking widens the difference. If most of your audience browses with Chrome on Android, the effect is smaller than Safari’s tracking prevention causes in markets with heavy iPhone use — but it is never nothing.
Common mistakes with ETP
The first is reading a reporting dip as a business dip. If analytics sessions fall while orders in your own system hold steady, browser blocking is the likelier explanation, not lost demand. Check the source that cannot be blocked before you move a budget.
The second is trying to work around it. Rotating domains, disguising a tracker as first-party content, or leaning on device fingerprinting all get caught eventually, damage trust, and in the case of fingerprinting sit badly with both browser policy and data-protection law. Firefox’s strict mode already targets it directly.
The third is quoting one tool’s number to a client as though it were the truth. Name the tool that produced it and say what that tool can and cannot see.
How to act on it
Move the measurement you genuinely need onto ground the browser trusts. Cookies set from your own domain survive far better than third-party ones. Server-side tagging, where the browser talks to an endpoint on your domain and your server forwards the data onward, removes several of the blocked hops — although it does not, and should not, override a person’s stated preference.
Then anchor every campaign decision to something the browser cannot touch: enquiries in your CRM, orders in your shop admin, calls answered, quotes sent. Use analytics for direction and shape, and use those records for the count. If tags, consent and platform data need untangling properly, that is the job of a proper analytics and tracking setup.