|
/ Documentation /Troubleshooting & FAQ/ Whitelisting the SureCookie Scanner

Whitelisting the SureCookie Scanner

SureCookie scans your website from our cloud servers to discover the cookies and scripts your visitors actually receive. The same servers also make a one-time request to your site when you first connect it, to verify that you own the domain.

Firewalls and bot-protection services (Cloudflare, 20i StackProtect, security plugins, and similar) sometimes mistake these requests for unwanted bot traffic and block them. When that happens, connecting your site can fail, or your scan results can look almost empty. This guide shows you how to recognize the problem and allow SureCookie through.

How to Tell the Scanner Is Being Blocked

You are likely affected if you see any of these:

  • Connection fails – connecting your site ends with an error such as “The verification URL did not return a 2xx response.”
  • Scan log errorsSureCookie → Cookie Scanner → Scanning Logs shows lines like “Registration step 2 returned unexpected response (HTTP 422).”
  • Nearly empty scan results – a scan completes but finds only one or two cookies (often a security cookie such as stackprotect or __cf_bm), even though your site clearly uses more.

That last one matters: when bot protection intercepts the scanner, it is shown a security check page instead of your real website, so the scan reports the security page’s cookies rather than yours.

Note: Your site is not broken, and your page builder or theme is not the cause. This is a security layer on your hosting or CDN doing its job a little too well.

Step 1: Get Your Scanner Details From Support

We share our current scanner IP addresses privately, through support, rather than publishing them. This keeps them accurate as our infrastructure changes and avoids anyone misusing them.

  1. Open a ticket through Contact Support.
  2. Tell us your website URL and that a firewall is blocking the scanner. If you know your host or CDN (for example Cloudflare or 20i), mention it, and include any error text from your scanning log.
  3. We reply with the exact IP address (or addresses) to allow, plus a User-Agent to match if your firewall needs one.

Keep that reply handy for the next step.

Step 2: Add the Exception in Your Firewall

Use the IP address (or addresses) we sent you. Apply the rule to your whole site, not a single URL, so the scanner can reach every public page you want scanned. If your site sits behind more than one layer (for example Cloudflare plus a security plugin), add the exception in each layer.

Cloudflare

  1. Log in to your Cloudflare dashboard and select your site.
  2. Go to Security → WAF → Tools.
  3. Under IP Access Rules, enter an IP address we provided.
  4. Choose Allow as the action and This website as the zone.
  5. Click Add, then repeat for any additional IP address.

Note: Cloudflare’s Bot Fight Mode (on the Free plan) does not support exceptions. If it is enabled under Security → Bots and the scan still comes back empty after adding the Allow rules, turn Bot Fight Mode off, run your scan, then turn it back on.

20i Hosting (StackProtect)

20i’s platform protection is called StackProtect. If your host runs on 20i (you may see a StackCache plugin in your wp-admin), there is no setting you can change yourself: only 20i’s support team can add exceptions.

  1. Open a support ticket with 20i (via My20i, or through your hosting provider if you bought hosting from a 20i reseller).
  2. Ask them to whitelist the IP address (or addresses) SureCookie gave you, for your whole site rather than a single URL. You can use this wording:

An external service I use (SureCookie, a cookie compliance scanner) is being challenged by StackProtect on my site [your-domain.com]. Please whitelist these IP addresses site-wide: [the IP addresses SureCookie provided]. The same servers run the cookie scanner, so a site-wide exception is needed for accurate results.

Once 20i confirms the exception, move on to Step 3.

Security Plugins

If you run a WordPress security plugin with its own firewall (Wordfence, Sucuri, Solid Security, or similar), add the IP address (or addresses) we provided to its allowlist or trusted IPs setting. The setting name varies by plugin; look for “allowlist”, “whitelist”, or “trusted IP addresses” in the firewall section.

Step 3: Run the Scan Again

Once the exception is in place:

  1. Go to SureCookie → Cookie Scanner.
  2. Click Start Scan.
  3. When the scan completes, review the results. You should now see your site’s full cookie list instead of one or two entries.

Troubleshooting

  • The scan still finds only one or two cookies – the exception is not active yet, or it covers only part of your site. Confirm the rule applies site-wide and to the correct domain (with and without www).
  • Connection still fails with a verification error – check that the rule was added to the domain you are connecting, and that no second security layer (host firewall plus plugin firewall) is still blocking.
  • You cannot find any firewall setting – your protection likely runs at the hosting level. Ask your host to allow the IP addresses we provided.
  • You are not sure which service is blocking, or it still fails – reply to your support ticket with your domain and we will help identify the layer and confirm the current scanner details.
Was this doc helpful?
What went wrong?

We don't respond to the article feedback, we use it to improve our support content.

Need help? Contact Support
Table of Contents
Scroll to Top