They use CNAME aliasing to make the requests seem like they're coming from your own domain, so you'd have block a specific URL on a site-by-site basis, and there are also fully server-side APIs so you don't even know when data is being captured or shared.