How to Stop Websites From Tracking You Across Sites (October 2026)

Cross-site tracking is the practice of companies following your activity from one website to the next using cookies, tracking pixels and device fingerprints, so an ad about running shoes keeps appearing on a news site and a recipe site. To stop it, you turn on your browser’s built-in tracking protection, block or limit third-party cookies, run a tracker-blocking extension, reduce what your fingerprint reveals, and clear old website data.

This guide is written for people who are not technical. Everything here works in a current version of Chrome, Edge, Firefox or Safari, and each step tells you how to confirm it actually took effect. Work through the steps in the order given — each one builds on the last, and the first three do most of the work.

Last updated October 2026. We have no relationship with any browser or privacy product mentioned here, and nothing on this page is sponsored. Settings names shift between releases, so I note which app each step applies to.

Table of Contents

What You Need

What You Need

You need less than people expect. A browser you already have, ten minutes, and the willingness to change three or four settings that are almost always in the wrong state.

Before you start, update your browser and your operating system. Tracking protection features have been added and renamed repeatedly over the past few years, and an outdated browser will not show the controls described below.

Essential, and where to skip ahead

  • A current browser. Chrome, Edge, Firefox and Safari all ship with some form of tracking protection. This is step one and it is the highest-impact change on this page.
  • About ten minutes, once. Most of the work is a one-time setup. After that, maintenance takes a few minutes every few months.
  • Your account passwords. Needed for step five, where you check how many accounts are signed in on your devices.

Optional, but useful

A tracker-blocking browser extension such as uBlock Origin or Privacy Badger costs nothing, installs in about a minute, and catches the requests your browser’s own protection misses. Some readers also run a DNS-level blocker such as Pi-hole on their home network, which stops tracker requests before they reach the browser at all.

You do not need a paid privacy suite, and you do not need anything technical beyond being able to follow a menu path. If a step here looks daunting, skip it for now and come back — steps one and two alone remove a large share of cross-site tracking.

Step-by-Step: How to Stop Websites From Tracking You Across Sites

Step-by-Step: How to Stop Websites From Tracking You Across Sites

Cross-site tracking comes from two directions: identifiers your browser stores, and signals your browser gives away without storing anything. The six steps below close both. Do them in order and the effect compounds.

Use Your Browser’s Built-in Tracking Protection

Every major browser now has a setting that blocks known tracking scripts. Most people never open it. This is the single biggest win available to you.

In Chrome, open the menu at the top right and go to Settings > Privacy and security > Third-party cookies. Choose the option that sends a “Do Not Track” request with your browsing traffic, and confirm when prompted. Separately, check Privacy and security > Site settings > Additional content settings and set Ad blocking to the standard or strict level if your version offers it.

In Edge, go to Settings > Privacy, search, and services > Tracking prevention. Edge gives you three levels. Balanced keeps sites working while blocking the trackers most likely to follow you; Strict blocks more but occasionally breaks logins and video players. Start on Balanced and move up if you want more.

In Firefox, open Settings > Privacy & Security and scroll to Enhanced Tracking Protection. Standard blocks social media trackers, tracking pixels and cryptominers. Strict adds fingerprinting protection. Custom lets you pick.

In Safari on a Mac, go to Safari > Settings > Privacy & Security and tick Prevent Cross-Site Tracking. Also set Hide IP from Trackers, and use Standard or Strict for the cross-site tracking pop-up option.

How to tell it worked: in Edge, click the padlock icon at the left of the address bar on any page and you will see a list of trackers it blocked. Firefox shows a shield icon in the address bar when Enhanced Tracking Protection stops something. That visible confirmation is the only reliable proof you have.

Limit Cross-Site Cookies and Website Data

Third-party cookies are the small files a site you never visited writes into your browser, then reads again on ten other sites. Blocking or limiting them removes the most persistent link between one site and the next.

Chrome and Edge both want you to choose a behaviour for third-party cookies. In Chrome, that path is Settings > Privacy and security > Third-party cookies; pick “Block third-party cookies” if you are willing to accept occasional sign-in prompts. In Edge the setting sits under Privacy, search, and services next to tracking prevention.

Firefox uses a separate control: Settings > Privacy & Security > Cookies and Site Data, then “Block third-party cookies” plus “Block cookies from trackers”. Safari’s equivalent is the Prevent Cross-Site Tracking setting above.

Then clear what is already there. Chrome and Edge use Settings > Privacy and security > Clear browsing data, and both let you set cookies and other site data to delete automatically when you close the browser. Firefox calls it Delete cookies and site data when Firefox is closed. Turning that on means you stop carrying a growing pile of identifiers around.

How to tell it worked: visit any large news site, then open a second unrelated site. If your browser is enforcing the block, you will see no stored third-party entries in Settings > Privacy and security > Third-party cookies > See all site data and permissions for domains you never signed into.

Run a Reputable Tracker Blocker

Browser protection blocks scripts the browser already knows about. A content blocker works differently: it stops the request before it loads, using lists that anyone can inspect and contribute to.

uBlock Origin is the most widely used option for Chrome, Edge and Firefox. Privacy Badger takes a different approach — instead of lists, it watches which third parties appear on many sites and blocks them as they start tracking you, so it needs no configuration. Both are free and open source. Both run entirely in your browser; nothing is sent to a company.

If you would rather change nothing inside your browser, a privacy-focused browser does the same job by default. Brave blocks third-party trackers and fingerprinting out of the box. Tor Browser routes traffic so that no single site, network or browser can see the whole journey, and it is the closest thing to untraceable that exists.

Expect breakage. Blockers occasionally stop a login form, a payment page or an embedded video from loading. That is normal and it is fixable: in Chrome and Edge, open Extensions, find the blocker, choose Details and set “This can read and change site data” to “When you click the extension”. Add the site to its own allow list, and it will work again while the rest of the web stays protected.

Reduce What Your Browser Fingerprint Reveals

Some trackers never store a cookie at all. They read things your browser exposes on every request — your screen size, installed fonts, graphics capabilities, language and time zone — and combine them into a device fingerprint unique enough to recognise you again. Blocking cookies does nothing about these.

The defence is not a single setting but consistency. Keep your browser, font size and display settings at their defaults. Avoid extensions that change how pages render, since each one adds a distinguishing signal. Standard Tracking Protection in Firefox and the Fingerprinting Protection toggle in Brave are the direct options if you use either.

On a phone, the equivalent surface is the advertising identifier. On iPhone, go to Settings > Privacy & Security > Tracking and turn off “Allow Apps to Request to Track”, then open each app’s page and switch off “Allow Data Tracking”. On Android, open Settings > Privacy > Ads and tap “Delete Advertising ID”, then open Google Settings > Ads and switch off both Ad Personalization and Ad Topics.

Keep your system fonts at default sizes and your display scaling where it is. Small changes, but every one you avoid is a variable an observer has to guess at.

Strengthen Account and Device Privacy

Here is the part that surprises people. If you are signed in to Google, Meta or Microsoft, you carry an account identifier that no browser setting can remove. Blocking cookies stops the anonymous cross-site trail, but a signed-in session tells those companies directly what you looked at and when.

Turn on two-step verification for every account that matters, and use a different password for each one. Those are the two habits that matter most on this whole page. Review which accounts are signed in on each device: Google is at myaccount.google.com > Security > Your devices, Apple at Settings > [your name], Microsoft at account.microsoft.com > Privacy, and sign out of anything you no longer use.

If you share a family or work device, use separate browser profiles rather than a shared one. A profile keeps cookies, history and sign-ins apart, which is more effective than clearing data after everyone is done.

On any device, keep automatic system updates on so security patches land without you thinking about it. Install extensions only from your browser’s official store, and remove the ones you stopped using — every extra extension is another script with access to the pages you visit.

Every site with a banner has a reject button, and most people click accept by habit. On each banner, choose reject all, or manage preferences and switch off anything you did not deliberately agree to.

Global Privacy Control is the stronger version of this request. It tells sites outright not to sell or share your data, and a growing number of US states now require sites to honour it. Chrome and Edge send it when you enable “Do Not Track” in their privacy settings. Firefox sends it if you install the Global Privacy Control extension, or turn on Enhanced Tracking Protection and enable the strict setting. Safari in recent versions supports it directly in Privacy settings.

Test in a private window. Open a private or incognito window, visit a few sites, and confirm the tracker-blocking icon still appears on each one. Then log into one account inside that window and notice which trackers reappear — that is your answer to whether cookie blocking is enough on its own.

Finally, set a reminder to recheck after a major browser update. Privacy settings are occasionally reset or renamed, and the cross-site tracking question in search results usually comes with people who did everything correctly and then lost a setting without noticing.

What Each Tracking Method Is and How to Block It

Tracking methodHow it identifies youWhat stops it
Third-party cookiesA file a site you never visited writes into your browser, then reads on othersBlock third-party cookies, or clear site data on a schedule
Tracking pixels and web beaconsA tiny invisible image loaded from an ad network when you open an email or pageEnhanced Tracking Protection or a content blocker
Browser fingerprintingScreen size, fonts, graphics and language combined into a unique device signatureFingerprinting protection, plus keeping default browser settings
Advertising IDA resettable identifier your phone carries across every appDelete Advertising ID on Android, turn off App Tracking Transparency on iPhone
Session replay scriptsRecords clicks and keystrokes to watch how visitors use a pageContent blocker on the site that loads the script
Signed-in accountYour Google, Meta or Microsoft session, handed over directlyTwo-step verification, sign-out reviews, and limiting where you stay logged in
IP addressYour network location is visible to every site you loadA VPN — and nothing else on this list

Notice the last row. A VPN changes one identifier and nothing else in this table, which is why it belongs in the setup but never replaces it.

Common Mistakes

Believing private browsing makes you untraceable. It does not. A private window stops your history and cookies from being stored on that device, but every site you visit still sees your IP address and can still run fingerprinting scripts. It protects other people using your computer far more than it protects you.

Treating a VPN as the whole solution. It hides your IP address and shifts your apparent location. It does not block cookies, does not stop fingerprinting and does not touch your signed-in accounts. One row of that table, out of seven.

Relying on Do Not Track alone. The setting was widely ignored for years. It is more useful now because Global Privacy Control rides along with it in Chrome, Edge and Firefox, and GPC carries legal weight in a growing number of US states. The old header on its own still gets ignored by plenty of sites.

Clearing cookies and expecting it to last. You wipe your identifiers, and the next page load hands you new ones within seconds. Clearing helps when you want a genuinely clean slate, such as before selling a device. As a daily habit, automatic deletion on close is the better version of the same idea.

Blocking everything at once. Blanket-blocking every script breaks the sites you actually use, and a workaround you find out of frustration is usually “turn the blocker off”. Block the defaults, then allow individual sites deliberately.

Installing ten extensions. Every extension is a script with access to the pages you open, and each one adds a fingerprint signal. One content blocker plus your browser’s built-in protection is a complete setup. Anything else is mostly fear-driven.

Assuming one setting finishes the job. Cross-site tracking is a chain of identifiers, not a single switch. The table above is the chain, and each link needs its own cut.

Frequently Asked Questions

How do I disable cross-site tracking?

In Chrome and Edge, open Settings, go to Privacy and security, and turn on tracking protection or send a Do Not Track request. In Firefox, open Settings, Privacy u0026amp; Security and select Enhanced Tracking Protection, choosing Strict for fingerprinting coverage too. On Safari, go to Safari Settings, Privacy u0026amp; Security and tick Prevent Cross-Site Tracking. Then block third-party cookies in the same area of settings.

How do I stop my browsing history from being tracked?

Turn on your browser’s tracking protection, block third-party cookies, and set site data to clear automatically when the browser closes. Add a content blocker such as uBlock Origin. Also review where you stay signed in, because being logged into Google, Meta or Microsoft shares your activity directly, and cookie blocking does not touch that. On shared devices, use separate browser profiles rather than one shared session.

Is it normal for websites to track me across sites?

Yes, it is standard practice and mostly legal under consent-based regimes like GDPR and CCPA, because sites are expected to ask before setting tracking cookies. What is not normal is feeling you have no way to object. Rejecting the banner, enabling Do Not Track, and switching off personalised ads in your Google and Facebook settings all reverse it. The tracking itself is common; the absence of control is the problem.

Is there a way to browse without being tracked at all?

Not completely, and anyone promising it is overselling. Tor Browser gets closest, because it is designed so no single party sees the whole journey. For everyday use, Brave or Firefox with Enhanced Tracking Protection plus a content blocker removes the large majority of cross-site identifiers, while signed-in accounts and IP-based location still reveal something. Privacy here is about reducing your profile, not erasing it.

Which browser is the hardest to track?

Tor Browser is the most private by design, resisting fingerprinting and routing traffic so no single observer sees everything. Among everyday browsers, Brave blocks third-party trackers and fingerprinting by default without configuration, and Firefox with Enhanced Tracking Protection set to Strict is a close second. Chrome and Edge can be tightened substantially, but they start from a position where tracking protection is off until you switch it on.

Does clearing cookies stop websites from tracking me across sites?

It removes the identifiers you have accumulated right now, which genuinely helps before selling a device or after a period of heavy searching. It does not solve the problem long term, because trackers re-establish themselves on the very next page load. Blocking third-party cookies and clearing site data automatically when you close the browser is the version that lasts.

Conclusion

Start with step one. Open your browser’s privacy settings and switch its tracking protection on — that single change removes more cross-site tracking than anything else on this page, and it takes about a minute.

Then block third-party cookies and add a content blocker. After that, check which accounts are signed into your devices and turn on two-step verification, since that protects you well beyond advertising.

A short maintenance checklist: confirm your tracking protection is still on after a major browser update, clear site data if your settings ever reset, sign out of accounts you no longer use, and re-test in a private window whenever an ad starts following you again. Tracking will not disappear entirely — but layered like this, it stops following you in a way you can actually notice.

Leave a Comment