Google Analytics added an Include mode to its hostname data filters on September 21, 2026, letting property owners define an allowlist of approved domains authorized to send event data rather than only blocking known bad ones after the fact. Under the previous Exclude-only filters, which shipped roughly 102 days earlier, an admin had to add each new spam or spoofed hostname to a blocklist as it appeared. Under Include mode, any hostname not on the approved list is filtered out automatically, and events with no hostname at all, the kind gtag.js spam traffic tends to produce, are blocked by default. Google’s own change notes carry one exception: hits sent through the Measurement Protocol are exempt from Include filtering and will not be blocked even if their hostname is unlisted.
The change matters most to marketing leaders who have stopped fully trusting their own Analytics dashboards. Referral spam and hostname spoofing, where a bot fires an event carrying a real site’s tracking ID from an unrelated domain, has been a known way to quietly inflate or distort session counts and conversion data feeding attribution models. An allowlist closes that door structurally instead of chasing every new spoofed domain individually, the same shift this publication has tracked as measurement vendors race to catch up with new sources of dirty data.
The original insight is in what Google left unstated. Its change notes carry no figures on how much spam volume the prior Exclude filters actually caught, how many properties adopted them, or how much legitimate data an aggressive Include list could accidentally strip if an admin forgets to list a legitimate subdomain or a syndication partner’s hostname. That silence is itself a signal: a marketing leader turning Include mode on should audit every hostname currently sending real, wanted traffic before flipping the switch, the same discipline behind treating marketing mix modeling as an audit system rather than a black box.
Source: Google Analytics Help