Skip to content

What causes direct traffic spikes?

Usually something GA4 could not label. An email or text went out with untagged links, a mention sent people to type your address, or bots and your own team piled in. A jump that never falls back points to a tracking change instead.

By , Founder & CEOUpdated 7 min read

Run the numbers for your store: the free UTM coverage calculator.

A direct traffic spike usually means GA4 met a crowd it could not label. Often an email or text went out with untagged links. Sometimes a podcast or press mention sent people to type your address, or bots Google does not know paid a visit. If the jump never falls back, suspect a tracking change.

What one store's data shows

The usual answer lists the suspects: untagged links, bots, people typing your address. It rarely says which spikes are worth anything. One store's export helps with that part, because it shows how fast revenue follows a visit.

One store's anonymised GA4 export, 1 January 2024 to 21 August 2026. It holds shares of revenue only: no ad spend, no order counts.

What the export showsShare of revenueSource cell
Direct, in last click, first click and touched views57.7%Channels sheet, Direct row
Journeys with 1 touch (0.5 days to buy)79.5%Journeys sheet, 1 touch row
Journeys with 2 to 3 touches (12.5 days to buy)12.2%Journeys sheet, 2 to 3 touches row
Journeys with 4 to 9 touches (16.9 days to buy)5.4%Journeys sheet, 4 to 9 touches row

First, the export cannot show a spike. It holds shares for the whole range, with no daily figures, so no single Tuesday stands out. It shows where the money landed once the dust settled.

On the Channels sheet, Direct holds 57.7% of revenue, whether you credit the last click, the first click or every touch. In that one store, an untagged send would pour its sales into the row that already holds most of the money. A mislabel there hides in plain sight.

On the Journeys sheet, journeys with 1 touch hold 79.5% of revenue, with 0.5 days to buy. That is the shape a same-day spike leaves behind. A typed visit after a podcast and a click on a naked email link both arrive as one touch that buys within hours.

The slower rows tell the rest. Journeys of 2 to 3 touches held 12.2% of revenue on the Journeys sheet and took 12.5 days to buy. Journeys of 4 to 9 touches held 5.4% and took 16.9 days, by the same Journeys sheet.

So a mislabel and real demand leave different footprints. A send with naked links lands in full on the day, then stops. Demand that needs a second visit arrives over the following weeks, as it did in that one store. Much of it comes back under other names, such as brand search or email.

What the export cannot tell you is which visits were which. A typed address and an untagged click both arrive with no source, so the export files them together. Bots that never buy leave no trace in revenue at all. That is one more reason to judge a spike by sales, not by sessions.

Why is typing your address the wrong first guess?

Because typing is the one cause you cannot check, and the others arrive in bursts. GA4 only knows that a visit came with no source. Google's help puts typed addresses, untagged links, stripped redirects and ad blockers in the same (direct) / (none) bucket.

Sends. One email or text reaches your whole list in a single go. If its links carry no UTM tags, or lose them on a redirect, every click lands in Direct at once. It is also the easiest spike to trace, because you know the send time.

Bots. Google's help says GA4 automatically excludes traffic from known bots and spiders. You cannot switch that off or see how much it removed. A crawler missing from that list can be counted like anyone else, and with no referrer it lands in Direct.

Shopify watches for the same thing from its side. Its help suggests the Human or bot session filter for investigating sudden spikes in traffic. Since its session measurement rollout of 21 to 23 September 2026, identified bot sessions are filtered out of Shopify's session reports by default.

Your own team. Launch days fill a site with staff, agencies and friends checking the new page. GA4 can mark visits from your office IP addresses as internal traffic. Shopify counts your own visits as sessions too, unless you open the store with View store from the desktop admin.

Lost referrers. Some visits lose their referrer before they arrive. Shopify's help names browsers with Do Not Track switched on, proxies or firewalls that block referrer data, and shortened URLs.

Mentions. A podcast, a TV slot or a printed code can send people to type your name. That spike is real demand, but GA4 cannot confirm it. Rule out the four causes above first.

What can a spike in Direct not tell you?

It cannot tell you what the visits were worth. Sessions count bots, staff and window shoppers the same as buyers. Before you call it demand, check key events and revenue for the same days.

It cannot show the people who came back later. Someone who heard your name on Monday and searched for it on Friday arrives through Organic Search, not Direct. Their sale never touches the spike, so the spike looks smaller than its effect.

And it cannot tell you what caused the jump. A podcast and an untagged email draw the same line on a chart. To learn what a mention or a channel adds, compare sales where it ran with sales where it did not, as a holdout test does.

What to do this week

  1. Put the spike on the calendar. In GA4, open Reports > Acquisition > Traffic acquisition and set the dates around the spike. Right-click the spike on the line graph, click Add annotation and name what happened that day. Pass: the jump starts on the day of a send, mention or release. Fail: nothing happened that day, so treat it as bots or a tracking change until you know more.
  2. Check whether the spike bought anything. In the same report, compare the Direct row's key events and engagement rate on the spike day with an ordinary day. Google counts a session as engaged when it lasts 10 seconds or longer, has a key event, or has 2 or more page views. Pass: key events rose with sessions. Fail: sessions jumped while key events stayed flat and engagement fell, so look for bots or your own team.
  3. Read the weeks after, not the day. Set Traffic acquisition to the weeks after the spike, then to the same span before it, and note Direct, Organic Search and Email. Pass: they stay above their usual level, so the spike was demand that is still arriving. Fail: everything drops back the next day, so it was a one-off: a send, a bot run or your own team.

Check the homework. Your GA4 Attribution paths export already holds the evidence. Causality Engine reads that one file and shows what each channel caused next to what last-click gave it, in 1 to 2 minutes, for €99 once (excluding VAT), refundable within 30 days. Check the homework

Sources, 1 October 2026: Understand (direct) / (none) traffic (Google); Known bot-traffic exclusion (Google); Filter out internal traffic (Google); About annotations (Google); Traffic acquisition report (Google); Default channel group (Google); Bot filtering in Shopify analytics and reports (Shopify); Acquisition reports (Shopify); Marketing reports (Shopify)

Frequently asked questions

  • Can bots cause a spike in direct traffic?
    Yes, when GA4 does not recognise them. Google's help says GA4 automatically excludes known bots and spiders, and you cannot see how many it removed. A crawler missing from that list can be counted like any visitor, and with no referrer it lands in Direct.
  • Does a podcast or TV mention show up as direct traffic?
    Partly. People who type your address after hearing it arrive with no referrer, so GA4 files them under Direct. People who search your name instead arrive from search results and land in Organic Search. Check both lines on the day of the mention and in the weeks after.
  • Why did direct traffic spike but sales did not?
    Usually because the extra visits were not shoppers. Bots GA4 does not recognise, your own team checking a launch, or a crowd that left after one page can all lift sessions without sales. Compare key events and engagement rate for the spike day before you call it demand.

Go deeper: Causal attribution, explained.

Sixty-second versions of these ideas: Causality Engine on YouTube Shorts.

Keep reading

Terms in this article

Browse the full glossary

Your platforms guess.
We run the math.

Upload a GA4 export and see what each channel caused, next to last-click, in 1–2 minutes. The read is yours to keep.

Free, in your browser: your file is not uploaded. The full read is €99, refundable within 30 days. Prices exclude VAT.
Or book a 30-min call.