Skip to main content

appconsent.io

Jan 2nd 2028 05:22 PM

Key-Systems GmbH

unsigned

No

May 12th 2026 12:38 PM

Appconsent.io appears to be a domain related to obtaining user consent for app usage, possibly for data collection or privacy purposes. It's a relatively new domain, registered in 2020, and lacks DNSSEC security, which may pose a risk.

Data on this page is collected by cside's crawler, which monitors third-party scripts across the public web.

Copy Summary
Copy Link
Helpful
Not Helpful
Rarely seen
Vendor

AppConsent (SFBX)

Category: consent

Description

AppConsent is a Consent Management Platform (CMP) by the French company SFBX, helping websites and apps collect GDPR/ePrivacy user consent and supporting Google Consent Mode v2. appconsent.io is its serving domain.

AI Review

The scripts associated with sfbx.io facilitate compliance with privacy regulations such as GDPR and CCPA, emphasizing user consent management for data processing across multiple domains. They utilize the IAB Transparency and Consent Framework (TCF) to gather user preferences regarding analytics and advertising cookies, thereby activating tracking mechanisms solely based on user consent. This approach balances the need for user engagement monitoring through analytics, primarily via Google Analytics, with a commitment to respecting user privacy choices. However, the data collection mechanism is extensive, creating a potential risk of overreach where sensitive user interactions could be inadvertently tracked, complicating data minimization efforts on payment pages. Despite the absence of alerts indicating security concerns, the reliance on third-party services for consent management introduces additional dependencies that could be vulnerable to breaches. The scripts' operations suggest a heavy reliance on tracking user behavior, which, while compliant, could result in collecting data during sensitive interactions, requiring stringent measures to ensure that sensitive fields remain exempt from tracking. The lack of recent alerts may indicate that scripts are functioning within expected parameters, but ongoing scrutiny is necessary to ensure compliance with data minimization principles and the integrity of third-party dependencies.

Script hostnames

appconsent.io
WHOIS Information
Registrar Key-Systems GmbH
Registration: January 2nd, 2018
Expires: January 2nd, 2028
Updated: May 12th, 2026
Nameservers
ns-cloud-b3.googledomains.com. 216.239.36.107
ns-cloud-b2.googledomains.com. 216.239.34.107
ns-cloud-b1.googledomains.com. 216.239.32.107
ns-cloud-b4.googledomains.com. 216.239.38.107
Meta Tags
viewport
width=device-width,initial-scale=1,maximum-scale=1,user-scalable=0
google
notranslate
Security Posture
HSTS
CSP
DNSSEC

appconsent.io is one of thousands of third-party scripts on the web.

Most sites run dozens of third-party scripts and can't say what each one does. cside monitors every script on your site and catches the ones that change or turn malicious.

DNS Records
Hostname Type TTL Priority Content
appconsent.io NS 21600
ns-cloud-b3.googledomains.com.
appconsent.io NS 21600
ns-cloud-b2.googledomains.com.
appconsent.io NS 21600
ns-cloud-b1.googledomains.com.
appconsent.io NS 21600
ns-cloud-b4.googledomains.com.
appconsent.io A 300
35.240.88.119
appconsent.io MX 300 10
alt3.aspmx.l.google.com.
appconsent.io MX 300 1
aspmx.l.google.com.
appconsent.io MX 300 5
alt1.aspmx.l.google.com.
appconsent.io MX 300 5
alt2.aspmx.l.google.com.
appconsent.io MX 300 10
alt4.aspmx.l.google.com.
appconsent.io TXT 5
"v=spf1 include:_spf.google.com include:spf.mandrillapp.com ~all"
appconsent.io TXT 5
"google-site-verification=Uzwi0Cv-RL2RDXessk9EPjZOdKLzF0rzEwg1g_ZwIR0"
appconsent.io TXT 5
"proxy-ssl.webflow.com"
appconsent.io SOA 21600
ns-cloud-b1.googledomains.com. cloud-dns-hostmaster.google.com. 3 21600 3600 259200 300

FAQ

Frequently Asked Questions

View all

This domain is analyzed as part of cside's domain directory to identify third-party scripts and their purposes. The summary provides information about what services, tools, or scripts this domain hosts, helping website owners understand which third-party services are being loaded on their sites.

The risk score is calculated based on multiple security factors including SSL certificate validity, DNSSEC status, domain registration details, and historical security data. A higher score indicates lower risk, while a lower score suggests potential security concerns that should be investigated.

The SSL certificate information shows whether the domain uses HTTPS encryption, when the certificate was issued, when it expires, and who issued it. This helps verify the domain's security posture and identify potential certificate-related vulnerabilities that could affect your website's security.

Third-party script domains can be compromised or used maliciously. By monitoring domain information like registration details, SSL certificates, and DNS records, you can identify suspicious changes, expired certificates, or domains that may pose security risks to your website and users.

Domain information is regularly scanned and updated to provide the most current security intelligence. The last scanned timestamp shows when the most recent analysis was performed, ensuring you have up-to-date information about the domain's security status.

If you identify a high-risk domain loading scripts on your website, you should investigate why it's being used, verify its legitimacy, and consider removing or replacing it if it's not essential. Use cside's platform to monitor and block suspicious third-party scripts to protect your users from potential security threats.

Subscribe to our newsletter to get the full picture

Stay updated with our latest news, offers and blog posts. Subscribe for exclusive updates delivered straight to your inbox.

Your inbox stays chill, we pop in monthly.

A pixelated, glitchy rendition of the cside shield
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

We'll show you:

Which third-party scripts are running on your site right now
Where you stand on PCI DSS 6.4.3 and 11.6.1
How much of your traffic is bots and AI agents

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead