Docs

GA4 Hostname Include Filter Tracking

GA4 hostname include filters let you allowlist domains. Track blocked events and spam before you switch one on, so real data isn't lost.

Analytics

Spam hits, staging sites and copied tracking snippets can all send events to your GA4 property. Until now, most teams fought this with an ever-growing list of exclude filters. That approach is always one step behind, and it leaves you guessing how much of your data is junk.

On 21 September 2026, Google Analytics added Include data filters for hostnames. You create an allowlist of approved domains, and events from any other hostname are blocked. It is a cleaner model, but a filter that drops data is a risky thing to switch on blind. Without measurement, you may lose real traffic and never notice.

Two details matter. Hostname include filters are not applied to events sent through the Measurement Protocol, so server-side events stay unblocked. And events with an empty hostname, such as those from gtag.js in some setups, are blocked automatically, because a missing hostname usually signals spam.

Data Points to Track

Capture these before and after enabling the filter, so you can compare like for like:

  • hostname – the domain on each event, grouped by property
  • event_count_by_hostname – daily volume per hostname, including unexpected ones
  • empty_hostname_events – events arriving with no hostname
  • filter_state – testing, active or inactive, recorded as an annotation
  • measurement_protocol_events – server-side volume, which should not change
  • key_event_count – purchases, sign-ups and other key events, per hostname
  • unexpected_hostname_share – percentage of events from domains not on your allowlist

Setup Steps

  1. In GA4, break down the last 30 days of events by hostname and list every domain you see.
  2. Sort the list into approved domains (production, checkout, help centre, app webview host) and unapproved ones (staging, spam, copied snippets).
  3. Check which of your apps and embeds send events without a hostname, such as WebViews or custom gtag setups, because the filter will block these.
  4. Confirm your server-side pipeline uses the Measurement Protocol, which the filter does not touch.
  5. Create the include filter in testing state first, and compare the filtered view against the unfiltered baseline for at least a week.
  6. Record the date you activate it as an annotation, and track key event counts per hostname for two weeks afterwards.
  7. Review the allowlist whenever you launch a new domain, subdomain or embedded checkout.

Actionable Insights

A sharp drop in key events after activation means a legitimate source was left off the allowlist. Check for payment provider domains, translated sites and WebView hosts first.

A rise in empty-hostname events points to an app or embed that the filter will now silently block. Fix the instrumentation rather than loosening the filter.

Unexpected hostnames with real engagement are usually forgotten microsites or partner pages. Decide whether to approve them or ask the owner to remove your tag.

Stable Measurement Protocol volume confirms your server-side data is safe. If it moves, something else changed.

Over time, the unexpected-hostname share tells you how clean your data really is, and gives you a number to show stakeholders when you explain why reported traffic fell after the clean-up.

Expert help

Need help tracking this in your app?

Our team sets up analytics pipelines for mobile and web teams every day. Talk to us and get your first events flowing in under an hour.

Talk to an expert