DecryptAds Tracker Lookup: How to Check a Site's Ad Partners
Search "espn.com" on DecryptAds and the results page lists 143 declared ad partners spread across the site's ads.txt and app-ads.txt files. Nineteen of those partner domains also show up as registered data brokers under state disclosure laws passed in recent years, according to Krebs on Security. Those are two separate facts: the domains appear in ESPN's own authorization files, and some of them are independently registered as brokers elsewhere.
That layered result, one file describing a declared ad relationship, a separate registry describing a legal status, is what a DecryptAds tracker lookup is designed to surface. DecryptAds is a free, continuously updated service that scrapes the disclosure files publishers post about their own ad businesses, then cross-references them into a searchable database (Krebs on Security). Learning how to use DecryptAds means learning to find who is tracking a website without over-reading what the results actually prove.
One distinction matters throughout this guide: a company on this list has been declared or permitted to run ads or collect data on a site, per that site's own published files. That's not proof the company actually collected anything during a specific visit. Keep that line in mind and the rest of this reads correctly.
What ads.txt and app-ads.txt actually show about adtech companies on a website
Video of the Day

Ads.txt and app-ads.txt are files publishers post themselves, naming every company permitted to run ads or collect user data on their site or app (Krebs on Security). For years, next to nobody checked whether those files were accurate. "The problem we have right now is that for years we've had almost no one policing these ads.txt and app-ads.txt files," DecryptAds co-founder Zach Edwards told Krebs on Security.
sellers.json and buyers.json are a different layer of records. They identify who's buying, selling, or reselling inventory tied to the IDs that show up in those files, but they don't map cleanly onto any one site's live auctions (Krebs on Security).
DecryptAds' actual value is stitching these files together. Individually they don't reveal much. Cross-referenced, they surface things like broken links between a site's ads.txt and its sellers.json entries, identical declaration sets copied across unrelated domains, and supply paths that turn up in bid logs but never in any publisher's own authorized-seller list, per the company's own explanation of its work (Krebs on Security).
That's also the ceiling on what any search shows. A result reflects whatever the most recent scrape found. A clean result means clean declarations at that moment, not a permanent guarantee.
Video of the Day
How to use DecryptAds for a website ad tracker lookup

-
Search a domain at decryptads.com. Use the bare domain, such as espn.com, rather than a full URL. The results combine partners declared in a site's ads.txt file, which covers the website itself, with partners declared in its app-ads.txt file, which covers any associated mobile or smart TV app, since publishers post these as two separate disclosure files (Krebs on Security). For espn.com, the combined total is 143 declared entities (Krebs on Security). This guide focuses on interpreting those results rather than walking through every screen in the interface.
-
Read the partner count as scope, not a verdict. A high number just means a site sells inventory through a lot of intermediaries. It isn't automatically damning. Some partners, though, will carry a broker registration flag: ESPN's page lists 19 domains registered as data brokers under laws passed in recent years in California, Oregon, Texas, and Vermont, which require any broker handling those states' residents' data to register publicly. That registration requirement sits entirely outside ads.txt itself (Krebs on Security).
-
Check what the registered brokers disclose about themselves. DecryptAds reports that almost half of ESPN's registered brokers collect geolocation data from visitors who aren't blocking ads, and three more disclose gathering device fingerprints or other sensitive personal information (Krebs on Security). Those are self-reported disclosures the brokers made in their own registry filings. They aren't evidence of what happened on any one visit to espn.com.
-
Weigh geo-risk flags against their scale. DecryptAds flags partners based in, or with strong financial and political ties to, jurisdictions it treats as higher risk: China, Russia, Cyprus, and the UAE (Krebs on Security). ESPN's own profile shows four ad entities tied to Russia, China, or the UAE, including a firm called Between Digital that lists a New York address (Krebs on Security). Opera.com's profile carries a longer geo-risk list, 27 brokers spanning the UAE, China, Cyprus, Russia, Hong Kong, and Ukraine. DecryptAds notes that's only 7% of Opera's total declared partners, a reminder to check scale before reacting to a flag (Krebs on Security).
-
Open the Legal Dossier for ownership questions, and treat it as a lead, not a finding. It surfaces registration history and domain aliases, though it takes several minutes to run per search. The dossier adds an ownership-related signal on Between Digital: despite the New York address, it lists the firm as Russian-linked because its publisher payments are processed through Alfa Bank, an institution the U.S. sanctioned in 2022 after Russia's invasion of Ukraine (Krebs on Security). That's DecryptAds' characterization, based on the payment-routing evidence Krebs reviewed, not a settled legal finding, and Krebs on Security had received no response from Between Digital or its founder as of publication (Krebs on Security). Pivoting on the firm's own app-ads.txt file inside the dossier turns up hundreds of domains featuring simple, ad-heavy web games, evidence those sites list Between Digital as a partner, not evidence of what code runs on them (Krebs on Security). Edwards said Between Digital's own declarations list it as both publisher and reseller across roughly two-thirds of its portfolio, an arrangement he says "creates opportunities to direct client spend at your owned and operated properties or client infrastructure, essentially creating opportunities for conflicts of interest" (Krebs on Security).
-
Decide what the result actually means. A large partner count alone isn't a reason to avoid a site. A disclosed collection capability is a reason to check that site's privacy policy or consent tool more closely. A geo-risk or ownership flag needs independent confirmation before you draw any conclusion from it. And no result, however clean, proves a site collected nothing from your visit.
Using a lookup to size up unfamiliar sites before you click
Malvertising, ads that deliver malware or redirect to phishing pages, hasn't gone away. Edwards told Krebs it shows up far more often on newly generated, low-quality "AI slop" sites than on major publishers, mostly because those sites don't pay for the fraud-screening tools bigger outlets use (Krebs on Security).
That's the practical case for a quick lookup before clicking an unfamiliar link from a search result. If a site's declared partner list looks unusually thin, inconsistent, or concentrated in flagged jurisdictions compared with known publishers in the same category, that's a preliminary signal worth noticing, not a tested risk score DecryptAds has validated.
A related feature built more for researchers than casual readers: DecryptAds' "quiet removals" feed tracks sellers that disappear from an exchange's sellers.json file without any public explanation. Edwards said ad networks often drop suspected bad actors quietly rather than disclose the fraud publicly, which makes the removals feed a useful lead for security teams and journalists trying to reconstruct who got cut and why (Krebs on Security).
DecryptAds does not scan pages for malicious code, and it can't confirm that a specific ad you saw was the harmful one. It assesses declared supply-chain relationships and narrows down where to look. It doesn't tell you what actually happened.
Why a declared partner list matters, and where DecryptAds' reach ends

Most online advertisements involve real-time bidding: a publisher auctions off ad space, and a single opportunity can broadcast pieces of user data to dozens of bidders within milliseconds. The FTC has said there's no fixed rule governing exactly what gets shared in that broadcast (FTC).
That structure produced one of the agency's more pointed cases. In December 2024, the FTC alleged that data broker Mobilewalla had been retaining data from ad auctions it didn't even win, amassing more than 500 million unique device identifiers tied to precise location data (FTC). The case closed in January 2025 with a finalized order barring Mobilewalla from retaining real-time bidding data for anything beyond the auction itself. The FTC noted this marked the first time it had alleged that collecting or retaining auction data for other purposes was an unfair practice, not that it was the agency's first remedy of any kind (FTC).
That's the system a long declared-partner list sits inside, one that moves data fast and, historically, hasn't had many brakes on where it ends up.
DecryptAds' own reach stops at the declaration. It shows relationships a site's public files say exist. It can't show which of those companies actually received or kept data from a given device, because that record, known in the industry as the supply chain object, isn't broadly shared even among ad networks themselves (Krebs on Security).
That gap is exactly what's worth checking once a lookup turns up a flag, instead of treating the flag as a finished answer. A high partner count or a broker disclosure is a reason to check that site's privacy policy and consent tool for what it actually claims to collect. A geo-risk or ownership flag, like the one on Between Digital, is a reason to check independent registration records or reporting rather than stop at DecryptAds' own characterization. Sort any flag by its source: a declared partnership in ads.txt, a state broker registration, and a researcher's own assessment are three different levels of confidence, not interchangeable evidence.
DecryptAds also covers app-related files, but this report does not establish a complete app-search workflow, so treat any app advertising tracker lookup as a more manual, separate project for now. App privacy deserves that separate scrutiny regardless. The FTC's January 2024 complaint against data broker X-Mode/Outlogic alleged the company collected precise location data through a software kit embedded in other companies' apps, as well as its own apps (FTC). That was an allegation tied to a proposed consent agreement at the time, not a claim about how any specific app store operates today.
Running your own lookup
A DecryptAds tracker lookup turns scattered, self-published disclosure files into a starting point: a way to see who a site has authorized and judge whether that list looks reasonable for the kind of site it is. It won't tell you what a specific ad did on your device, and it isn't a validated risk score, just a public record with real gaps in it.
Run the search, read the partner count as scope rather than a verdict, and chase every flag, whether it's a broker registration, a geo-risk tag, or a Legal Dossier entry, back to its own source before deciding what it means.