🔐 Fix CSP Blocking Your OTTO Pixel and GTM

Camilo Aponte

Camilo Aponte

Last updated on Sep 30, 2026

🧩 What Is This Issue?

Your OTTO pixel may show as Engaged in the Search Atlas dashboard, yet changes still fail to push to your site. A common cause is a Content Security Policy (CSP) — a browser-level security header — that blocks external scripts, network requests, or tracking pixels from loading on your pages.

This is a client-side browser issue, not a server-side crawler or bot-blocking problem. Whitelisting IPs or adjusting bot-protection rules will not resolve it. You need to update your CSP headers to explicitly allow Search Atlas domains.

🔍 CSP vs. Crawler IP Blocking — Know the Difference

These are two separate systems and require different fixes:

  • Crawler IP blocking (403 errors): Your server refuses requests from Search Atlas crawlers. Fix by whitelisting Search Atlas IP ranges in your firewall or WAF settings.
  • Content Security Policy (CSP) blocking: Your browser refuses to load or communicate with external scripts and endpoints. Fix by adding Search Atlas domains to your CSP header directives. This is the issue described in this article.

🌐 Which Domains Do You Need to Whitelist?

The wildcard *.searchatlas.com covers all current and future Search Atlas subdomains, including dashboard.searchatlas.com and bots.searchatlas.com. Using the wildcard is the recommended approach so you do not need to update your CSP each time a new subdomain is introduced.

Add the following entries to your CSP header:

  • script-src: Allows Search Atlas GTM and pixel scripts to execute in the browser. Add *.searchatlas.com.
  • connect-src: Allows the pixel to send data back to Search Atlas endpoints via XHR or Fetch requests. Add *.searchatlas.com.
  • img-src: Allows tracking pixels loaded as 1×1 image beacons. Add *.searchatlas.com.

If your CSP is managed via an HTTP response header, your updated directives should look similar to this example:

script-src 'self' *.searchatlas.com;

connect-src 'self' *.searchatlas.com;

img-src 'self' *.searchatlas.com;

If you also use a meta http-equiv CSP tag in your HTML, apply the same domain additions there. Note that connect-src and some directives are not supported in meta tags — use HTTP headers for full coverage.

✅ Step-by-Step: Applying the CSP Fix

  1. Open your server, CDN, or hosting control panel where HTTP response headers are managed (for example, Cloudflare, Nginx, Apache, or your CMS security plugin).
  2. Locate your existing Content-Security-Policy header.
  3. Add *.searchatlas.com to the script-src, connect-src, and img-src directives. Do not remove any existing trusted domains.
  4. Save and deploy the updated header configuration.
  5. Open your browser's developer tools (F12), navigate to the Console tab, and reload your page. Confirm there are no remaining CSP violation errors referencing searchatlas.com.
  6. Check the Network tab to verify that GTM and pixel requests to searchatlas.com domains return a 200 status rather than being blocked.

📋 Verify GTM Script Placement

A correct CSP alone is not enough if your GTM snippet is not placed properly on the page. Confirm the following:

  • The GTM script tag is placed immediately after the opening <head> tag on every page.
  • The GTM noscript iframe is placed immediately after the opening <body> tag.
  • No other script or plugin is stripping or deferring the GTM tags before the CSP evaluation occurs.

If you manage your site through a CMS such as WordPress, use an official GTM integration plugin to ensure correct placement and avoid tag removal during theme updates.

🗺️ Reprocess Your Sitemap After CSP Updates

Once your CSP is updated and the pixel is confirmed loading correctly in the browser, trigger a sitemap reprocess inside Search Atlas so OTTO can re-evaluate your pages with the pixel now active:

  1. In the left sidebar, go to Site Metrics (Site Explorer).
  2. Locate your project and open its settings.
  3. Resubmit or reprocess your sitemap to prompt a fresh crawl and allow OTTO to detect the correctly firing pixel across all indexed URLs.

Changes pushed by OTTO will only apply to pages that are successfully crawled after the pixel is verified as active.

🛠️ Quick Troubleshooting Checklist

  • Pixel shows Engaged but changes not applying: CSP is the most likely cause — follow the steps above.
  • CSP updated but errors persist: Check for a separate Content-Security-Policy-Report-Only header that may indicate additional blocked resources.
  • Changes applied but not visible on site: Clear your CDN or server-side cache after OTTO pushes updates.
  • Wildcard not supported by your setup: Add dashboard.searchatlas.com and bots.searchatlas.com as explicit entries to each directive.

💬 Need More Help?

If you need further assistance, open the chat widget in the bottom-right corner of the platform and type human teammate to be connected with a member of our team.