TL;DR
Two things landed in GA4 on the same day and they do opposite kinds of work. Source Group is cosmetic in the best sense: it folds the six ways a platform spells its own name into one value, and Google applies it backward across data you already collected [1]. The hostname filter is surgical and one-directional: it stops events from an unapproved hostname entering your property from the moment you turn it on, and Google's own documentation flags it in an Important callout at the top of the page: traffic filters only apply to new data [2]. Neither one cleans up the referral junk in last quarter's acquisition report. And before you reach for either, check which of the two referral tools you actually need, because the unwanted referrals list on your data stream and the hostname data filter on your property are not alternative routes to the same result.
Key Takeaways
- Source Group consolidates source values so one platform reports under one name. Google's example is a single "Facebook" instead of "facebook", "fb", and "Meta-facebook" [1].
- Google's announcement names Facebook, Instagram and TikTok as the consolidated platforms, with built-in grouping for ChatGPT (OpenAI) and Perplexity as emerging sources [1].
- Source Group is populated retroactively [1]. The hostname filter is not: Google states that traffic filters only apply to new data and will not change previously collected data [2].
- The hostname filter lives at Admin → Data collection and modification → Data filters, as the Web hostname traffic type, matching Exactly matches or Contains [2].
- Data filters have three states: Testing, Active and Inactive. Google recommends Testing first, and an Active filter is permanent [2].
- Unwanted referrals is a data stream setting that works at the attribution level with a cap of 50 entries. The hostname filter is a property-level data filter that works at the event level [2][5].
- GA4 treats the medium as paid when it contains cp (cpc, cpm, social-cpc), is exactly ppc, retargeting, display or appremarketing, or starts with paid (paid_search, paid_social) [4]. Anything outside that reports its Source Platform as "Unlabeled" [4].
Start With the Action You Cannot Take Back
Most GA4 housekeeping is reversible. This one is not, so it goes first.
A data filter has three states. Testing marks the matching events without excluding them, Active excludes them, and Inactive stops the filter from doing anything [2]. Once a filter has been Active, the events it excluded during that period are gone from the property [2]. There is no undo, no reprocessing, no support ticket that gets them back. Google ships a Testing state for exactly this reason: you validate the match value before it is permanent [2].
The realistic failure on a Shopify store is not typing a domain wrong. It is not knowing your own hostname list. Storefront traffic, a preview theme, a headless front end and an app-served page can all report hostnames you never think about, and a Contains filter on your brand name will quietly take some of them with it. Before you write anything into that field, run the Hostname dimension over the last 90 days and read the whole list. You have probably never looked at it.
The one thing a hostname filter genuinely fixes is traffic that was never yours: hits sent to your measurement ID from hostnames you do not own. That is the classic referral spam shape, and it is why the filter type exists.
Which Tool Does Which Job?
Two different features address unwanted referrals, and the difference is where they act.
| Unwanted referrals list | Hostname data filter | |
|---|---|---|
| Where it lives | Web data stream tag settings [5] | Admin → Data collection and modification → Data filters [2] |
| Scope | The stream | The property [2] |
| What it acts on | Attribution. The referrer is ignored via ignore_referrer=true [5] |
The event itself, excluded from processing [2] |
| Event still collected? | Yes [5] | No, once the filter is Active [2] |
| Reversible | Yes, the conditions are editable [5] | No, an Active filter is permanent [2] |
| Documented limit | Up to 50 entries [5] | Not stated in Google's hostname-filter documentation. |
Read that table as a decision rule. If the traffic is real traffic on your own store that simply should not be credited as a traffic source, the unwanted referrals list is the right tool, because you want to keep the session and only correct where it gets credited. If the traffic is not yours at all, the data filter is the right tool, because keeping the event has no value.
The forward-only rule is documented for traffic filters and Google states it plainly [2]. The referral exclusion sets a flag on the hit as it is sent, so plan on the same behavior there. Google adds one wrinkle: a user first referred by a domain before you excluded it can keep being attributed to that domain on later visits under last-non-direct-click [5].
What Source Group Fixes, and What It Leaves Behind
Source Group is the June 11 release most people noticed, and it solves a naming problem rather than a hygiene problem. GA4 now consolidates the variants a platform arrives under so that reports show one value: Google's example is "Facebook", not "facebook", "fb", and "Meta-facebook" [1]. Google's announcement names Facebook, Instagram and TikTok as the consolidated platforms, with built-in grouping for ChatGPT (OpenAI) and Perplexity as emerging sources [1].
The retroactive part is the reason this matters for cleanup work. Google populates the dimension backward, so your historical data groups too [1]. That is the opposite of every filter behavior in this article, and it is worth holding the two facts side by side: grouping reaches into the past, filtering never does.
What Source Group does not do is remove anything. Consolidating the variants of a spam source under one label does not reduce the traffic behind it. Grouping tidies the label on the row; the sessions, the bounce rate they drag in and the revenue they never produced all stay exactly where they were. If your acquisition table has junk in it today, this feature makes the junk easier to read.
We covered the dimension itself (the interface also labels it "Source grouping"), including where it surfaces and how it differs from the AI Assistant channel that shipped in May, in our guide to GA4 grouping ChatGPT and Perplexity traffic. This article is the cleanup half of the same release.
Running a Hostname Filter Through Testing
The path is Admin → Data collection and modification → Data filters, then create a filter of the Web hostname traffic type [2]. You choose a match condition of Exactly or Contains, and you enter the hostname value [2].
Set the state to Testing and leave it there. In Testing, GA4 tags the events the filter would have caught instead of dropping them, and you evaluate the result through the "Test data filter name" dimension, which shows you exactly what the Active version would have removed [2]. Google's guidance is to allow 24 to 36 hours for filter results to appear before you judge them [2].
Google documents the exploration to build: use the dimensions Test data filter name and Event name, the metric Event count, and filter the report to the name of your filter [2].
The operator layer goes on top of that. What you are checking during that window is one thing: did the filter catch anything you wanted to keep? Add Purchases to the same exploration and look for any purchase at all in the matched rows. A single transaction under a hostname you were about to exclude is the whole reason the Testing state exists.
Only then flip it to Active, knowing that the flip is one-way.
Why Does Paid Traffic Still Read Wrong After the Cleanup?
Cleaning referrals does not fix the other classification problem merchants run into, and the mechanism behind it is public.
GA4 treats the medium as paid when it contains cp (cpc, cpm, social-cpc), is exactly ppc, retargeting, display or appremarketing, or starts with paid (paid_search, paid_social) [4]. If the medium passes, GA4 then maps the source to a platform. Values matching %facebook%, meta, fbook, fb or messenger report as Meta Ads. Values matching %tiktok%, tt, %tik-tok% or %bytedance% report as TikTok Ads. Values matching %gemini%, %openai% or %perplexity% report as "Other Ads" [4]. If the medium fails that test, Source Platform reports "Unlabeled" no matter what the source says [4].
That last sentence is the one that costs money. A campaign tagged utm_medium=email or utm_medium=social cannot be labeled as a paid platform, because the medium never entered the paid branch. Tag a paid social campaign with a medium of paid_social and it passes; tag it social and it does not. The source string is irrelevant until the medium has already qualified.
There is a second-order effect for stores buying on the newer AI ad surfaces. OpenAI and Perplexity sources currently land in "Other Ads" rather than a named platform of their own [4], so a Source Platform report will not separate them from each other. Group them by source instead if you need that split.
What Order Should a Shopify Store Do This In?
The sequence matters more than any individual setting, because two of these steps are permanent and one of them is retroactive.
- Pull the Hostname dimension for the last 90 days and write down every value with sessions attached. This is the audit that prevents the expensive mistake.
- Decide per hostname: not my traffic (filter candidate) or my traffic reporting oddly (leave it, investigate the source). Junk hostnames that never produced a purchase are the safe filter candidates.
- Create the hostname filter in Testing, wait 24 to 36 hours, and check the test dimension for anything that converted [2].
- Separately, list genuine referrers that should not be credited as a traffic source on your data stream's unwanted referrals list, remembering the 50-entry cap [5].
- Fix your mediums so paid campaigns pass the paid-medium test before you spend another week reading "Unlabeled" rows [4].
- Set the filter Active only after step 3 came back clean.
Nothing in this list recovers a number you already reported wrong. If your Shopify numbers and your GA4 numbers disagree for reasons that predate all of this, the causes are usually elsewhere, and we walked through them in why Shopify and GA4 revenue never match. If the disagreement shows up as sessions with no source, that is a different problem again and it lives in (not set) and unattributed orders.
One more thing to keep straight before you start clicking: the referral that shows as Direct on a Shopify order is frequently not a referral problem at all. How Shopify attributes first click, last click and direct orders is the place to check that before you filter anything.
FAQ
Does the GA4 hostname filter remove referral spam from my existing reports?
No. Google states that traffic filters only apply to new data and will not change previously collected data [2]. Data that arrived before the filter went Active stays in your reports permanently. A filter changes what the property collects from now on, and leaves everything already collected untouched.
What is the difference between the unwanted referrals list and the hostname filter?
The unwanted referrals list is a data stream setting that acts on attribution: the event is still collected, but the referrer is ignored via ignore_referrer=true, so the referrer is not displayed as a traffic source [5]. The hostname filter is a property-level data filter that acts on the event itself, excluding it from processing entirely [2]. The referrals list holds up to 50 entries and stays editable; an Active data filter is permanent [2][5].
Is Source Group retroactive?
Yes. Google states the dimension is populated retroactively, so historical source values group as well [1]. Source Group is the part of the June 11, 2026 release that reaches backward into data you already collected [1].
Why does my paid campaign show Source Platform as "Unlabeled"?
Because the medium did not match GA4's paid pattern. GA4 treats the medium as paid when it contains cp (cpc, cpm, social-cpc), is exactly ppc, retargeting, display or appremarketing, or starts with paid (paid_search, paid_social) [4], and only then maps the source to a platform. A medium of email or social never reaches the mapping step, so the session reports as Unlabeled regardless of which platform sent it.
Should I use Exactly or Contains for the hostname match?
Exactly, unless you have a real reason not to. Contains is what turns a filter on one spam hostname into a filter on a family of hostnames you did not intend to include, and the Testing state is the only thing standing between that mistake and permanent data loss [2].
If the underlying problem is that your GA4 property is not receiving clean, server-side purchase data in the first place, install WeltPixel Conversion Tracking and start from events you can trust before you start deleting any.
Sources
- [GA4] What's new in Google Analytics, June 11, 2026 entry, support.google.com/analytics/answer/9164320, accessed August 24, 2026
- [GA4] Filter out web hostname traffic in Google Analytics, support.google.com/analytics/answer/16608575, accessed August 24, 2026
- [GA4] Data filters, support.google.com/analytics/answer/10108813, accessed August 24, 2026
- [GA4] About the Source Platform dimension, support.google.com/analytics/answer/17041930, accessed August 24, 2026
- [GA4] Identify unwanted referrals, support.google.com/analytics/answer/10327750, accessed August 24, 2026