You open GA4, check where your visitors come from, and a domain you have never heard of is sitting in your referral list. Or a payment page you use for checkout is being credited for sales it never earned. That is referral spam — and it makes your reports look busier and dirtier than they really are.
The good news for Malaysian business owners: referral spam in GA4 is usually a small, fixable problem, not lost data. This guide explains what it is, how to spot it, and how the team at ZenWeb clears it across 500+ client accounts — without deleting a single real visit.
We will define referral spam, show why it quietly costs you money, map the tell-tale signs, and walk the fix step by step — all part of keeping your digital marketing reporting trustworthy. The short video below is a useful primer before we start.
Source video: MeasureSchool on YouTube
Referral spam has a long history in Google Analytics. In the old Universal Analytics days, spammers flooded reports with fake referrers to bait clicks. GA4 resists this far better, but junk referrals still slip through.
The relief is that this is rarely lost data. Your real visits are still counted; a few junk sessions have simply been filed under a source that is not genuine. Below we cover what referral spam means in GA4, why it matters, how to recognise it, and how to block it for good.
Quick Answer: Referral spam in GA4 is any session logged under a fake or unwanted referral source. It covers bots that leave a junk referrer, “ghost” hits sent straight to your property, and legitimate-but-unhelpful referrals like payment gateways. It inflates your numbers and hides where real visitors actually came from.
“Referral” in GA4 simply means a visit that arrived from another website. Referral spam is when that source is fake, automated, or something you never wanted counted as a referral in the first place. It comes in three broad flavours:
GA4 handles a lot of this for you. It automatically blocks traffic from known bots, which is the same first line of defence covered in our guide to filtering bot traffic out of your GA4 reports. What is left over is what this guide fixes.
Quick Answer: GA4 referral spam inflates sessions with visits that never buy, drags down engagement and conversion rates, and steals credit from the channels that actually work. For any business spending on ads, that means judging real campaigns against numbers polluted by fake traffic.
The harm is rarely the spam line itself — it is what the spam does to every metric around it. Three problems show up again and again:
That last point is the expensive one. If your numbers are dirty, you cannot trust them to decide where the next ringgit of budget goes — the same trap that makes a spike in direct traffic so misleading.
Not sure your GA4 numbers can be trusted?
A quick professional check confirms your traffic sources are clean before you judge any campaign on them. See how our digital marketing team sets up clean tracking →
Quick Answer: Across ZenWeb client accounts, the most common junk referrals are crawler bots that slip past the auto-filter and unwanted payment-gateway referrals — together more than half of all cases. True ghost spam is rarer in GA4 than it was in Universal Analytics, because fake hits now need your API secret to land.
The chart below shows how junk-referral cases break down across the Malaysian accounts our team has diagnosed. Notice how much is not really “spam” — just real traffic mislabelled as a referral.
| Type of junk referral | Share of cases |
|---|---|
| Crawler bots that slip past the auto-filter | 34% |
| Unwanted payment-gateway referrals (iPay88, Billplz, Stripe, PayPal) | 28% |
| Ghost hits with a hostname that is not yours | 18% |
| Spammy event, language, or campaign strings | 12% |
| Own subdomain or staging self-referrals | 8% |
Source: ZenWeb client diagnostic cases, Malaysia, 2024–2026.
The pattern is clear: the top two rows — stray crawlers and payment-gateway referrals — make up most of what Malaysian SMEs actually see. Both are fixed with settings, not a rebuild. Payment-gateway noise in particular overlaps with self-referrals that skew your data, and both use the same unwanted-referrals fix.
Quick Answer: The three types of referral spam reach GA4 in different ways, so they need different fixes. Ghost spam never visits your site; crawler spam does; unwanted referrals are real visitors passing through a third party. Knowing which one you have tells you exactly which lever to pull.
Lumping all junk referrals together is why so many clean-up attempts fail. The table below separates them by how they arrive, how to recognise them, and whether GA4 already blocks them for you.
| Type | How it reaches GA4 | Tell-tale sign | GA4 auto-blocks it? |
|---|---|---|---|
| Ghost spam | Fake hits sent straight to your property; never visits the site | Hostname is not your domain | Mostly — needs your API secret, so rare in GA4 |
| Crawler spam | A real bot crawls your site and leaves a fake referrer | Odd source domain, near-zero engagement | Known bots yes; unknown crawlers no |
| Unwanted referrals | Real visitors return via a payment page or your own subdomain | Referral from a gateway or your own domain | No — you add them to the unwanted list |
Source: ZenWeb, compiled from Google Analytics documentation and client cases, 2024–2026.
GA4’s built-in defence does the heavy lifting on known bots. Google confirms that traffic from known bots and spiders is excluded automatically using the IAB/ABC International Spiders and Bots List — always on, no setting to toggle. That leaves ghost hits and unwanted referrals as the parts you handle yourself.
Quick Answer: You can spot referral spam by its fingerprints — a source domain you do not recognise, sessions with near-zero engagement, or a hostname that is not your website. The single best check is the hostname: if a referral shows a hostname that is not your domain, it never touched your site and is ghost spam.
Before you block anything, confirm it is really spam. The table below maps each warning sign to what it usually means and how to check it inside GA4.
| What you see | What it usually means | How to confirm |
|---|---|---|
| A referral from a domain you have never heard of | Crawler or ghost spam | Add the Hostname dimension; if it is not yours, it is a ghost |
| A spike of sessions with near-zero engagement time | Automated bot traffic | Check average engagement time for that source |
| Sessions from a country you do not serve | Scraper or data-centre traffic | Segment by country and compare to real buyers |
| A “referral” from your own domain | Self-referral or cross-subdomain gap | Check whether the source is your own subdomain |
| A “referral” from a checkout or payment page | Unwanted referral, not spam | Trace the user path back to your checkout |
Source: ZenWeb diagnostic framework, Malaysia, 2024–2026.
When a whole source shows no data on your key pages instead of odd data, the cause is usually tracking, not spam — start with why GA4 shows no data before you reach for a filter.
Reports full of sources you cannot explain?
We audit your GA4 setup, separate the spam from the real traffic, and lock in filters that keep it clean. Get a clean-tracking audit from our team →
Quick Answer: Block referral spam in a set order: confirm it is spam, trust GA4’s built-in bot filter, add the culprits to your unwanted-referrals list, exclude your own IPs, protect your API secret, then build a clean hostname-filtered view. Test each change before moving to the next.
Work the steps in order and check after each one. Most sites only need the first three.
Follow these seven steps, confirming the change before you move on.
Keep a simple record of every domain you exclude, so your reasoning is clear months later and the same spam does not creep back in unnoticed.
Quick Answer: Check the right place for the right speed. DebugView and Realtime confirm within minutes that your settings work; standard reports take 24 to 48 hours to settle. The unwanted-referrals list is not retroactive, so past spam stays recorded — use a segment to hide it in old data.
The most common mistake after a clean-up is expecting yesterday’s reports to change. They will not — the fix applies going forward, as the table below shows.
| Where you check | What it proves | Typical delay |
|---|---|---|
| DebugView | A test hit now has its referrer ignored | Seconds |
| Realtime report | Live sessions stop showing the blocked source | Up to ~30 minutes |
| Traffic acquisition report | Referral share settles as clean sessions land | 24–48 hours |
| Historical data | Old spam stays as it was recorded | Not retroactive — use a segment |
Source: Modeled from ZenWeb client cases, Malaysia, 2024–2026.
That 24-to-48-hour wait for standard reports is normal, in line with Google’s data-freshness guidance. If a blocked source still appears in fresh data after two days, the domain match is probably too narrow — widen it and test again.
Quick Answer: Adding a payment gateway to your unwanted-referrals list is safe to do yourself. Get help when spam keeps returning, when ghost hits point to a leaked API secret, or when the reports feed ad budgets that depend on the numbers being right.
You do not need an agency for every junk referral. Use this rough line to decide:
A wrong guess here is quietly costly. While your data is dirty, every channel decision rests on numbers that credit the wrong source — the same blind spot that makes a sudden ranking drop hard to diagnose. Getting the setup clean once pays for itself, and our digital marketing team audits and locks down GA4 tracking as standard.
Referral spam in GA4 looks alarming but rarely means broken tracking. Your real visits are still counted; a handful of fake or unwanted sessions have simply been filed under a source that is not genuine. Read the fingerprint, name the type, then apply the fix it calls for.
Confirm it is spam, lean on GA4’s built-in bot filter, list your unwanted referrals, and filter your reporting by hostname. Test in DebugView, wait a day or two for reports to settle, and judge the result on new data. If spam keeps returning or your campaigns depend on the numbers, the team at ZenWeb can get your tracking clean and keep it that way.
Referral spam in GA4 is any session logged under a fake or unwanted referral source. It includes bots that leave a junk referrer, ghost hits sent straight to your property that never visit your site, and real traffic passing through a payment gateway. It inflates your totals and hides where genuine visitors actually came from.
Partly. GA4 automatically excludes traffic from known bots and spiders using the IAB/ABC International Spiders and Bots List, and this cannot be switched off. But it does not catch every unknown crawler, ghost hit, or unwanted referral. Those you handle yourself with the unwanted-referrals list and a hostname filter.
Go to Admin, Data Streams, Configure tag settings, Show all, then List unwanted referrals, and add the spam or gateway domains you want ignored. GA4 then stops counting them as sources for new sessions. For ghost hits, build an exploration filtered to your own hostname so wrong-hostname traffic drops out of analysis.
Two reasons. First, the list is not retroactive, so historical data keeps the old spam — only new sessions are cleaned. Second, your domain match may be too narrow. Widen the match type or add the exact domain, then re-check fresh data after 24 to 48 hours as reports settle.
No. GA4 does not let you delete or rewrite historical data the way Universal Analytics view filters seemed to. Past spam stays recorded. To read clean historical numbers, build a segment or comparison that excludes the spam source or filters to your own hostname, and use that view for reporting.
Spam making your GA4 reports impossible to trust?
Book a free 30-minute session — we’ll check your sources, block the spam, exclude the gateways, and get every referral in GA4 crediting the channel that earned it.
Complete the form and our team will contact you to discuss your goals. Let’s grow your business.

Online