Checks run on the server. Detection probes candidate endpoints for Google's health check rather than
reading tag markup, so it catches both the same-origin and subdomain serving methods. No credentials are used.
Checking, this can take 10 to 20 seconds while candidate endpoints are probed…
Known limits. Candidate endpoints come from the served HTML plus common naming
conventions, so an endpoint on an unusual hostname that never appears in page source will be missed. Sites behind
aggressive bot protection may refuse the request. A negative result is not proof of absence. Catching every case needs
a real browser loading the page and watching network traffic, which is what Tag Inspector already does.