Google Analytics added hostname Include filters on September 21. You give GA4 a list of the domains that are allowed to send data to your property, and it ignores events from anywhere else.
Until now, hostname filtering only worked the other way. Google introduced hostname Exclude filters in June, which meant spotting a spam domain in your reports, adding it to the block list, and repeating that every time a new one showed up. An allowlist turns that around. You say which domains are yours once, and everything else is filtered out.
Why bank marketers should care
Spam and ghost traffic inflate sessions, drag down engagement rates and throw off channel reports. For a bank or credit union, that bad data flows straight into budget decisions: which campaigns get credit for account opens, whether a rate page is working, how much to spend on paid search next quarter. A cleaner property means fewer arguments about whether a traffic spike was real.
It also cuts maintenance. Most marketing teams at community banks and credit unions don’t have someone checking GA4 for new spam referrers every week. An allowlist mostly runs itself once it’s set up.
Two details that can trip you up
Server-side events aren’t affected. Google says Include filters don’t apply to events sent through the Measurement Protocol. If you push account openings or funded loans into GA4 from your CRM, core or loan origination system that way, those events will keep coming through.
Events with no hostname get blocked. An Include filter automatically drops any event that arrives without a hostname. Google’s reasoning is that a missing hostname usually signals spam or something abnormal, and it notes this can include some traffic sent through gtag.js. Before you turn the filter on, check whether any of your legitimate tagging is sending events without a hostname.
The risk for banks: forgetting a domain
This is where financial institutions need to be careful. Most banks don’t run on a single domain. A typical setup might include:
- The main website
- A separate subdomain for mortgage or wealth management
- Online and mobile banking login pages
- Third-party account opening or loan application platforms, often on the vendor’s domain or a custom subdomain
- Rate calculators, promo microsites and landing pages built in a separate tool
- Staging or test sites (which you probably want excluded anyway)
If your account opening flow runs on a vendor’s domain and you leave it off the allowlist, GA4 will quietly stop recording those events. Your application starts and completions could drop to zero in reports while real customers are still opening accounts. That’s worse than a bit of spam.
How to set it up without breaking your reporting
- Pull a list of every hostname sending data now. In GA4, build an exploration or report with the Hostname dimension over the last 90 days. You’ll see your real domains mixed in with the junk.
- Check it against your vendor list. Ask digital banking, lending and deposit teams which third-party platforms carry your GA4 tag. Don’t rely only on what shows up in reports; a seasonal campaign page may not have had traffic recently.
- Run the filter in testing mode first. GA4 data filters can be set to a testing state, where matching data is labeled rather than removed. Let it run for a couple of weeks and compare filtered and unfiltered numbers, especially for conversion events.
- Then activate it. Once a filter is active, excluded data is gone for good. It isn’t applied retroactively and can’t be recovered later.
- Add new domains before launch. Put “update the GA4 hostname allowlist” on the checklist for every new microsite, vendor integration or domain change.
Where to find it
The option lives in GA4 Admin under data filters, alongside the existing hostname Exclude filter. Google announced the change in its “What’s new in Google Analytics” release notes on September 21, 2026.



