How to Reclaim Your Google Analytics Data from Spambots and Fake Traffic

Fake website traffic spams your Google Analytics with new (false) keywords, languages, hostnames, and referrers - skewing your Google Analytics data. Learn how to recognize, block, and filter it, and reclaim your metrics and reporting.
June 13, 2017

Discovering traffic increases and new referring sites in Google Analytics reports is a great feeling. SEO is time-consuming work, so it’s incredibly rewarding to discover that the effort you’re putting into it is paying off. But before celebrating, it’s important to make sure those successes aren’t the result of fake traffic—Google Analytics spam.

Recently, industry experts have seen an increase in website traffic from spambots, which cause new (false) keywords, languages, hostnames, and referrers to appear in Analytics.

To enjoy the benefits of Google Analytics for measuring SEO and marketing campaigns, you need clean data. By identifying and filtering Google Analytics referrer spam, you can ensure data and reports are clean, accurate, and a reflection of interactions from real users.

What Is Google Analytics Spam?

Google Analytics spam is inflated data that appears when malicious bots send fake traffic to Analytics properties. Many of these fake hits never actually occur—meaning the bots don’t really visit your website. Instead, they spam Analytics accounts with fake data in hopes of conning webmasters into visiting their websites.

Spambots do this by falsifying keyword, language, hostname, and referrer data. When webmasters see this data in their Google Analytics accounts, the natural reaction is to investigate it, searching for the falsified keywords or navigating to the referring websites. This behavior helps spammers increase traffic to their own properties.

But it also completely sabotages the data you need to make good decisions for your marketing strategies. Identifying, blocking, and filtering Google Analytics spam ensures that the data you rely on:

  • Is as accurate as possible.
  • Is representative of your real audience.
  • Reflects a true bounce rate from organic search for key pages.
  • Isn’t distorted by spam visits that cause spikes in direct traffic, fake referrals, fake organic keywords, or falsified events and goals.

How to Identify Google Analytics Spam

The first step in eliminating Google Analytics spam is identifying it. Most often, Analytics spam appears in organic keyword, language, hostname, and referral reports.

Organic Keyword Report Spam:

organic keyword spam

Keywords that specify the web address of an unrelated site are likely the result of spam hits.

Language Report Spam:

analytics language report

Google formats languages as “xx-xx,” so anything in the language report that doesn’t match that format is likely spam.

Hostname Report Spam:

analytics hostname report

Hostname spam can be more difficult to spot. Additional steps are required to confirm that hostname traffic is the result of Analytics spam.

Referral Report Spam:

analytics referral report

Referrals should point to pages on your property. If the landing page for the referral is another websites, it’s likely a spam referrer.

Some spam is obvious—anything in the language report that isn’t a language is clearly spam. Other times, you’ll have to conduct a few tests to confirm that what you’re seeing is spam and not legitimate visits or referrers.

  1. Compare Google Analytics Data to Google Search Console Data. If a new referring site appears in referral acquisition reports, make sure the referring website appears in Google Search Console under, “Links to Your Site.” Also, compare keywords in Google Analytics that seem suspicious with keywords listed in Google Search Console’s, “Search Analytics” report. If the questionable keyword isn’t listed in Search Console, it’s spam.
  2. Conduct a search for the questionable keyword, hostname, language, or referrer. But preface the search query with “referral spam” (example: referral spam Many sites cover Google Analytics spam and post about new spammers as soon as they’re discovered, so a quick search can provide clarification.
  3. Look for “(not set)” hostnames. If hostnames display as “(not set),” the traffic didn’t originate from your website.

Once you have a list of all of the spambots that are attacking your Analytics property, it’s time to block future report data from those spammers, and filter their data from historical reports.

How to Block and Filter Spam from Google Analytics Reports

With a list of sites that are sending referral spam in hand, set up filters in Google Analytics to block fake traffic from spambots in the future and to remove historical spam data from reports.

First, to make this easier next time, enable automatic bot filtering. Google is aware of the spambot problem and will automatically filter out known spammers when auto-filtering is turned on. Within the “Admin” tab, click “View Settings,” and check the box to enable bot filtering. Save changes to have Google automatically filter spambot hits.

automatic filtering analytics

analytics automatic bot filter

This doesn’t solve the problem, though. New spambots are created every day, and spammers use masked IP addresses and other deceptive approaches to overcome auto-filtering. For this reason—and to eliminate historical spambot data—you’ll need to manually add filters for existing and new spammers.

Before creating any filters, create a sandbox environment where you can test changes so you don’t accidentally skew your data:

  1. Open Google Analytics, and select the property you want to manage.
  2. Click the “Admin” tab to navigate to the admin section.
  3. In the admin section, click the dropdown under “View.”
  4. Select “Create new view.”

    how to create analytics filter

  5. Give the new view a name, and click the “Create View” button.

Creating a separate view allows you to test filters without accidentally skewing data, and ensures you have ongoing access to unfiltered data in the default “All Web Site Data” view.

With a filtered view created, you’re ready to establish spambot filters.

Create a Hostname Inclusion Filter

A hostname inclusion filter tells Google Analytics to only record hostnames for your site. This will filter out a lot of the spam, and will give you the added bonus of potentially filtering out traffic being sent from dev, staging, or other hosting environments. To create a hostname inclusion filter:

  1. Click the “Admin” tab, make sure your new filtered view is selected in the “View” dropdown, and select “Filters.”

    analytics inclusion filter

  2. Click the “Add Filter” button.

    add analytics filter

  3. Select the “Create new Filter” radio button.
  4. Give the filter a name.
  5. Select “Custom” under “Filter Type.”

    analytics custom filter

  6. Select the “Include” radio button.
  7. Choose “Hostname” in the “Filter Field” drop-down.
  8. Enter your hostname regular expression in the “Filter Pattern” field.

    hostname filter

  9. Click “Verify this filter” to ensure that you’ve entered the filter pattern correctly. Note that if you have only a small amount of traffic, you may get an error. Double-check the filter pattern to ensure accuracy. If correct, ignore the error.

    verify analytics filteranalytics filter error

  10. Click “Save” to apply the filter.

This will filter out a lot of the spam, and it provides the added bonus of potentially filtering out some dev traffic you may be sending.

Create Referral Spam Exclusion Filters

You may also want to create filters to exclude specific patterns of spam that are tarnishing reports. To create referrer exclusion filters:

  1. Click the “Admin” tab, make sure your new filtered view is selected in the “View” dropdown, and select “Filters.”

    google analytics filters

  2. Click the “Add Filter” button.

    how to add analytics filter

  3. Select the “Create new Filter” radio button.
  4. Give the filter a name.
  5. Select “Custom” under “Filter Type.”

    custom analytics filter

  6. Select “Referral” under “Filter Field.”

    analytics referral filter

  7. Next, you need to enter the filter pattern you want to block. You can do this by entering the exact text that appears in Analytics reports for the spam referrer, or you can block referral spam with one or two mighty referral exclusions using regular expressions. Creating a more inclusive referral exclusion filter makes blocking spam more manageable by eliminating the need to add a new filter for every new spam referrer, but you’ll likely need to enlist the help of a technical team member to write the regular expressions.

    analytics filter pattern

  8. Click “Verify this filter” to ensure that you’ve entered the filter pattern correctly.
  9. Click “Save” to apply the filter.
  10. If you decided to filter by referrer instead of using regular expressions, you’ll have to repeat each of these steps for every referrer you want to block.

Language and keyword spam can also be blocked with exclusion filters using the same process. Just substitute the “Filter Field” selection (step six) with “Language Settings” for language spam, or “Search Term” for keyword spam.

After setting up these filters, you can expect to see changes in historical reports. The significance of the changes will depend on what percentage of your existing traffic was from spam referrals. You may see a decrease in referral numbers, organic traffic numbers, and keywords that are driving users to your site, but at least now you’re seeing accurate data.

Will This Stop All Google Analytics Spam?

While going through these steps will prevent known spambot referrals from appearing in reports, spammers are always finding new ways to circumvent filters. As such, identifying and preventing Google Analytics spam is an ongoing process that needs to be executed before running any incremental analytics reports.

In general, Google Analytics spam is problematic if it represents more than 2% of overall traffic, or 3% of traffic for any channel—and it’s important to check both. Even if only 1% of overall traffic is spam, that 1% could be 10% of organic search traffic, which would distort segmented analysis on organic traffic reports.

A simple first step is enabling spam auto-filtering in Google Analytics. While it won’t remove all fake traffic, it will eradicate many known offenders. After that, set up filters for other spammers that are impacting your reports.

If you need help, a good SEO partner can conduct an audit of your Analytics traffic and establish the necessary filters for you. This will help ensure that your historical data—as well as all future reporting—accurately reflects actual visits to your site by real users.

Nate Dame
CEO and Founder
Nate is the founder and CEO of Profound Strategy, a results-oriented SEO consultancy trusted by forward-thinking companies, including a few of the world's largest B2B and technology brands. Profound Strategy builds holistic SEO strategies, supports internal teams, and offers full-service execution to create an organic search presence that generates significant revenue.

What's Next?

Profound Strategy is on a mission to help growth-minded marketers turn SEO back into a source of predictable, reliable, scalable business results.

Start winning in organic search and turn SEO into your most efficient marketing channel. Subscribe to updates and join the 6,000+ marketing executives and founders that are changing the way they do SEO:

And dig deeper with some of our best content, such as The CMO’s Guide to Modern SEO, Technical SEO: A Decision Maker’s Guide, and A Modern Framework for SEO Work that Matters.