Google Analytics 4 now lets you allowlist the hostnames that may send data to a property, adds Dashboards for single-page KPI views, and lets you set custom lookback windows for conversions. Alongside those sit two audits, a campaign data import validation report and a diagnostic for missing aggregate identifiers, plus a new currency requirement on cost imports. Most of it is housekeeping that improves data trust, but a few items change numbers you already report on.
Key takeaways
- Hostname Include filters let you allowlist approved domains, but they also block events with empty hostnames and they do not apply to Measurement Protocol events.
- Custom conversion windows (1 to 30 days for engaged-view, 1 to 90 days for click-through) will move your conversion counts, so annotate the change date.
- Dashboards are a presentation layer. Build them after you trust the data, not instead of fixing it.
- Run the campaign data import validation report and read the aggregate parameter diagnostic this week; both are low-effort checks.
- Campaign data imports that include cost now need a currency field, so update upload templates before the next run.
- App conversion reporting for Google Ads customers is rolling out unevenly, so confirm your property's eligibility before planning around it.
What did Google change in GA4 this summer?
Seven entries matter, spread from late July to the end of September 2026. Some touch data collection, some touch attribution, and one is purely about how you look at reports. Sorting them by what they affect makes it easier to decide who in your team owns each.
| Change | Date | Who it affects | What to do |
|---|---|---|---|
| Improved app conversion management and reporting for Google Ads customers | September 29, 2026 | Teams with app conversions and linked Google Ads | Check property eligibility with Google support; review attribution settings for app conversions |
| Hostname filters (Include) | September 21, 2026 | Anyone fighting spam or stray domains in reports | Inventory your real hostnames, then test an allowlist |
| Dashboards | September 9, 2026 | Analysts and stakeholders who want one KPI view | Pick five to eight KPIs and build one pilot dashboard |
| Updated conversion window configuration | August 11, 2026 | Paid media and analytics leads | Decide whether defaults fit your sales cycle; log the change |
| Campaign data import validation report | August 10, 2026 | Teams importing non-Google campaign data | Review campaigns lacking cost, clicks or impressions |
| Diagnostic for aggregate parameter issues | July 30, 2026 | Properties where GBRAID and gad_ are missing from URLs | Open the diagnostic, fix the listed URLs |
| Campaign data import currency update | July 28, 2026 | Anyone uploading cost data | Add a currency field to upload files |
The order of effort is not the order of the dates. The hostname filter and conversion windows deserve the most care, because both can quietly change what your reports say. The diagnostics and validation report are read-only checks, so they can wait for a free afternoon but should not wait for a quarter.
How do hostname Include filters work in GA4?
Until this release, hostname filtering was Exclude-only. You spotted a junk domain in your hostname report, added an Exclude filter, and waited for the next one. That is a maintenance treadmill, and most teams stopped keeping up with it.
Include filters flip the model. You list the domains that are authorised to send event data to the property, and everything else is blocked. For a company with a marketing site, a booking subdomain and a checkout on a third-party domain, that is a short list and a one-time job.
Two behaviours from Google's notes deserve attention before you switch anything on:
- Measurement Protocol is exempt. Hostname Include filters are not applied to events sent through the Measurement Protocol, so that data remains unblocked. If you rely on server-side events, they pass through whether or not a hostname is on your list. It also means the filter is not a defence against someone sending junk through that route.
- Empty hostnames are blocked. An Include filter automatically blocks events with no hostname, and Google cites gtag.js traffic as an example of what that catches, on the reasoning that a missing hostname usually points to spam or abnormal traffic.
The second point is the one that bites. If any legitimate source of events in your stack arrives without a hostname, an Include filter will drop it, and you will not get an error. You will get a quiet dip in a report.
My position: use Include filters, but treat the rollout like a firewall rule, not a report setting. Do not enable it on your only production property on a Friday afternoon.
How should you roll out a hostname allowlist safely?
Start by listing every hostname that should legitimately send data. Pull the hostname dimension for a long enough window to cover seasonal domains, such as a campaign microsite that only runs in Q4 or a payment page hosted elsewhere. Then compare the list against what your developers and marketing operations people say exists. The gaps between those two lists are the finding.
A sensible sequence:
- Export the hostnames seen over the last several months and sort by event volume.
- Mark each as approved, unknown or spam. Chase the unknowns with the owners of subdomains and vendor-hosted pages.
- Apply the allowlist first on a secondary or test property that receives a copy of your data, if you have one.
- Compare event counts, key events and revenue against your main property for a week or two.
- Apply it to production, and write down the date in your change log.
- Re-check the hostname list whenever someone launches a new domain, a new checkout provider or a new regional site.
Step 6 is the one teams skip. An allowlist is only as good as the process that updates it. If your launch checklist for a new microsite does not include 'add hostname to GA4', you will eventually launch a site that collects nothing.
What not to do: do not build the list from a single week of data, and do not assume the old Exclude filters can be deleted the moment the allowlist is live. Leave them until you have confirmed the allowlist behaves as expected.
What do the new conversion windows change for attribution?
GA4 conversions now accept custom integer lookback windows. Engaged-view conversion (EVC) windows can be set to any integer from 1 to 30 days; before, they were fixed at 3 days. Click-through conversion (CTC) windows can be set to any integer from 1 to 90 days, where before you chose from presets of 1, 7, 14, 30, 60 or 90.
The settings live in Google Analytics under Advertising, then Conversion management, then the more options icon and Settings. The same configuration is available in the linked Google Ads conversion management interface.
The practical reason to care is sales cycle. A software vendor with a 45-day evaluation period was stuck choosing between 30 and 60 days, and either one misrepresented the journey. A retailer selling low-cost items may find that a 90-day click window credits ads for purchases that would have happened anyway. Now both can pick a number that matches how their customers really behave.
There is a catch. Changing a window changes how credit is assigned from that point, and your before-and-after comparisons will not be like for like. Treat it the way you would treat a tracking change: annotate the date, tell the paid media team, and do not read a jump in conversions as a campaign win without checking the window first.
A reasonable approach is to base the new value on evidence from your own data, not on a round number. Look at the time between first ad interaction and conversion for your main conversion types, and set the window to cover most of that range without stretching far beyond it. Change one conversion type at a time so you can see what moved.
What about app conversions and Google Ads reporting?
The September 29 release extends cross-channel reporting and conversion management to app conversions for Google Ads customers. App conversions are now supported in conversion reports, including performance, attribution analysis and attribution models. Attribution settings can also be adjusted independently for app conversions, so you can treat them differently from web conversions when assigning credit across channels.
Two limits come straight from Google's notes. The feature may not be available to your property, and the team is working to expand it to more properties. And cross-channel budgeting currently supports web conversions only.
So the action is narrow. If you run app conversions alongside Google Ads, ask your Google support contact whether your property is eligible, and do not build a budget process around app data in cross-channel budgeting. If you have no app conversions or no linked Google Ads account, you can ignore this entry entirely.
This is also a case where an agency promising 'full app attribution' next month should be asked for specifics. Eligibility is Google's call, not the implementer's.
Are Dashboards worth building now?
Dashboards are available in Google Analytics as a flexible way to view KPIs on a single report. The launch includes drag-and-drop layout, a simpler way to create visualisations and new report visualisations.
For most teams, the value is communication. The head of marketing wants one page with six numbers, not a trip through the Reports menu. A dashboard gives the analyst a way to hand that over without exporting to a spreadsheet each Monday.
Still, a dashboard shows whatever your data says. If hostname spam inflates sessions or your conversion windows have been changed without notice, a tidy chart makes a wrong number look authoritative. Sequence matters: clean up collection and attribution first, then build the view.
A pilot that works:
- Choose one audience, such as the marketing leadership team, and ask what three decisions they make from GA4 each month.
- Pick five to eight KPIs that inform those decisions, and define each one in writing, including which conversion and which window it uses.
- Build one dashboard, share it, and ask for feedback after a month.
- Retire any tile nobody looked at.
Do not rebuild every existing report as a dashboard. The point is a smaller set of views people actually open, not a larger set that nobody maintains.
How do the data import checks and diagnostics help?
Three smaller items concern campaign data quality, and together they form a short audit.
Campaign data import validation report (August 10). This report helps you assess non-Google campaign data and imported campaign data. It points out campaigns lacking useful performance data such as cost, clicks and impressions, and lets you review data you imported earlier. If you import spend from social or affiliate platforms, open it and see how many campaigns are effectively empty. Campaigns with a name but no cost make return-on-spend comparisons misleading.
Currency requirement (July 28). Campaign data import now requires a currency field whenever you upload cost data. Any scheduled or manual upload built before this change may need a new column. Check your templates and the people or scripts that produce them.
Aggregate parameter diagnostic (July 30). Properties where the aggregate identifiers GBRAID and gad_ are missing from the URL now see a diagnostic that lists the problematic URLs and ways to resolve the issue. Google says these identifiers matter for campaign data accuracy. The usual culprits for stripped URL parameters are redirects, link shorteners and landing page code that rewrites the address, so give the URL list to whoever owns your redirect and tag management setup. Read Google's linked documentation on aggregate identifiers for the exact fix steps.
These are the easiest wins in the batch. None changes your data; they tell you where it is thin.
Where do you need an implementation partner and where can you go solo?
Most of this is in-house work. Running the validation report, reading the diagnostic, updating import templates, building a first dashboard and choosing conversion windows all sit within a competent analyst's reach, provided someone owns the change log.
A partner earns their fee in three places:
- Hostname allowlists across complex estates. If you have dozens of domains, franchise sites, regional microsites or third-party checkouts, mapping them and testing the filter against a copy property is real work. A mistake costs you data you cannot get back.
- Attribution redesign. Moving to custom windows while also reconciling Google Ads and other channels is a measurement design question, not a settings change.
- Fixing URL parameter loss. When the diagnostic points at redirects and tag logic spread across several teams, someone has to trace it end to end.
If you do go looking, start with the GA4 partners directory and write a clear scope. Our GA4 RFP template gives you a brief to adapt, and find-partners lets you narrow by need. Ask each candidate how they would test a hostname allowlist before enabling it. A good answer mentions a parallel property and a comparison period, not just 'we will set it up'.
How do you measure whether any of this worked?
Pick a few checks and run them on a schedule, not once.
- Hostname report: after an allowlist goes live, the report should show only approved domains. Event volume from approved hostnames should stay in line with the pre-change level.
- Key event totals: compare daily key events before and after, and investigate any step change that isn't tied to a campaign or release.
- Conversion windows: record the date of each window change. When reviewing performance, compare periods that use the same setting.
- Import quality: the validation report should show fewer campaigns missing cost, clicks or impressions over time.
- Diagnostic status: the aggregate parameter diagnostic should clear once the listed URLs are fixed.
- Dashboard usage: ask stakeholders after a month whether they use the dashboard, and what they still pull manually.
Keep a plain change log with the date, the setting and the person responsible. It is the cheapest tool in this list and the one most teams lack.
What should you ignore or avoid?
Ignore the app conversion entry if you have no app conversions or no linked Google Ads account. Ignore dashboards if your stakeholders already get what they need from existing reports.
Avoid turning on a hostname Include filter without an inventory, since empty hostnames are blocked automatically. Avoid changing conversion windows and campaign structures in the same week. Avoid assuming the filter protects Measurement Protocol traffic, because it does not. And avoid treating any of these as a substitute for an audit of your tagging.
If you want a broader view of what else is moving in GA4 and the wider Google stack, the MarTech Partners blog tracks releases like these as they land. For anything affecting attribution, confirm current behaviour in Google's own documentation before you change production settings.
Sources
- Google Analytics Help: What's new in Google Analytics — Release notes for September 29, September 21, September 9, August 11, August 10, July 30 and July 28, 2026
Frequently Asked Questions
What does a GA4 hostname Include filter do?
It lets you list the hostnames that are approved to send event data to a property. Events from hostnames that are not on the list are blocked. Until now GA4 only offered Exclude filters for hostnames, which meant chasing spam sources one at a time.
Do hostname Include filters affect Measurement Protocol events?
No. Google states that Hostname Include filters are not applied to events sent from the Measurement Protocol, so that data stays unblocked. Server-side events sent that way will not be caught by the allowlist.
What are the new GA4 conversion window limits?
Engaged-view conversion windows can be set to any integer from 1 to 30 days, where they were previously fixed at 3 days. Click-through conversion windows can be set to any integer from 1 to 90 days, instead of only the presets of 1, 7, 14, 30, 60 or 90. You change them under Advertising, Conversion management, then Settings.
Why is GA4 asking for a currency field in campaign data import?
Campaign data import now requires a currency field whenever you upload cost data. If your upload template only carries a cost column, add the currency before your next scheduled import or the upload will not meet the requirement.
Are app conversions available in every GA4 property?
No. Google says the improved app conversion management and reporting may not be available to your property, and the team is working to expand it. Ask your Google support contact about eligibility, and note that cross-channel budgeting currently supports web conversions only.
