GA4 Hostname Include Filters: How to Block Spam Without Deleting Real Orders

Spam in Google Analytics 4 (GA4) is a small reporting annoyance until it starts shaping decisions. Fake sessions inflate traffic, drag down conversion rate and muddy the channel mix your board pack is built on. Google has just given properties a stronger defence: an allowlist of the website addresses you trust, with everything else refused.

There is a catch directors need to hear before anyone switches it on. If a genuine domain is missing from that list, its data is deleted for good, including purchases. In this blog, we’ll explain what changed, why it matters for the P&L, and the checklist that gets you cleaner data without losing real orders.

What Google actually shipped

On 21 September 2026, Google’s What’s new in Google Analytics page announced Include data filters for hostnames. A hostname is simply the website address an event was recorded on, such as www.yourstore.co.uk.

  • Before: since June 2026, hostname filters could only exclude. Someone had to spot each new spam domain and add it to a block list.
  • Now: you can list the approved domains allowed to send data. Events from any other hostname are filtered out.
  • Measurement Protocol is exempt: Google says Include filters are not applied to events sent from the Measurement Protocol (a way of sending data to GA4 from servers rather than browsers).
  • Blank hostnames are blocked: Include filters automatically block events with an empty hostname, because Google says a missing hostname typically indicates spam or abnormal traffic.

Google’s release note gives no rollout schedule, so check Admin → Data filters to see whether the Include option is live on your property yet.

Why it matters for the P&L

Clean data is a commercial asset. Spam that never touches your site still lands in reports, which can:

  • Understate conversion rate by adding sessions that could never buy
  • Distort channel and referral reporting that budget conversations rely on
  • Waste analyst time explaining odd spikes instead of finding growth

But the downside of a wrong allowlist is far bigger than the upside of a tidy one. Google’s Data filters help page is explicit: once a filter is applied, the effect is permanent. Filtered data is never processed and will never be available in Google Analytics or BigQuery. Filters also only work from the moment they are created, so they do not clean up historical spam either.

In plain terms: forget your checkout or booking subdomain and those purchases simply never arrive. Revenue in GA4 drops, conversion rate looks worse, and if Google Ads bids on conversions imported from GA4, it loses those signals too.

The domains teams most often forget

Every hostname that carries your tag and matters to revenue has to be on the list. Typical candidates to check:

  • www and non-www versions of your main domain
  • Country or regional domains (.co.uk, .ie, .com) and regional subdomains
  • A separate shop, checkout, booking or payment domain that carries your tag
  • Campaign microsites and landing-page tools
  • Translated or cached copies of your pages served from Google-owned hostnames

Test and staging sites usually should not be on the production list. If you want to measure them, give them their own GA4 property.

Director checklist (20 minutes with your analyst)

Ask your analyst to walk you through these steps before anything goes Active:

  1. Size the problem first. Pull a report by Hostname for the last 90 days. How much traffic and how many events come from hostnames you do not recognise, or show as (not set)?
  2. Build the inventory. List every hostname, who owns it and whether it carries purchase or lead events. Sign it off with ecommerce, paid media and development.
  3. Create the filter in Testing. In Admin → Data collection and modification → Data filters, create a web hostname filter, choose Include, add the approved list and set the state to Testing, not Active.
  4. Wait, then validate. Google says filters can take 24 to 36 hours to apply. Then build a Free form exploration with Test data filter name, Hostname and Event name as rows and Event count as the value. Check both what the filter would keep and what it would drop.
  5. Look for revenue in the wrong pile. If purchase or generate_lead events appear on a hostname the filter would remove, a genuine domain is missing. Fix the list and test again.
  6. Reconcile to Shopify (or your OMS). Compare orders and revenue with GA4 purchases for the testing window. Your platform remains order truth.
  7. Activate and log it. Switch to Active, record the date and owner, and add “update the GA4 allowlist” to the launch checklist for every new domain, microsite or market.

Caveats before you rely on it

  • Matching rules are not documented yet. Google has not said whether subdomains, wildcards, or www versus bare domains are matched automatically. Test rather than assume.
  • Server-side data is a grey area. Measurement Protocol events are exempt, so spam sent that way will not be stopped. PPC Land also notes the release does not say how events sent via Google’s newer Data Manager API are treated, which matters for stores sending purchases server to server.
  • The “gtag.js” wording is ambiguous. Google’s note gives gtag.js traffic as an example of empty-hostname events. Testing is how you confirm your normal web tracking is unaffected.
  • No undo. If you only want to hide spam from a report, Google recommends report filters instead, which do not delete anything.

Final thoughts

#5/100 — A filter you can’t undo deserves a test you don’t skip.

GA4’s hostname allowlist is a genuinely useful way to keep spam out of the numbers your team trades on. Treat it like a finance control, not a settings tweak: inventory every domain, test for at least a day and a half, reconcile to your order data, then switch it on.

Want a second pair of eyes on your hostname list before you activate it? Email info@taggurus.co.uk or book a meeting today to discuss.


FAQ

Q: Is the hostname Include filter available on every GA4 property?
A: Google has not published a rollout schedule. Check Admin → Data filters. If you only see Exclude, the option has not reached your property yet.

Q: Will it remove the spam already in our reports?
A: No. Data filters only apply from the moment they are created. Use report filters or comparisons to set historical spam aside.

Q: What happens if we forget a domain?
A: Data from that hostname is never processed while the filter is Active, and it cannot be recovered in GA4 or BigQuery. That is why testing and an agreed domain inventory come first.

Next
Next

How to Read GA4's Conversion Attribution Analysis Report Without Killing Upper-Funnel Spend