Skip to content

How to trace a direct traffic spike in GA4, step by step

Pin down the day the spike started, then check three things in GA4: whether it bought anything, where it landed and which devices it used. Rule out bots in Shopify and your own team, then match what is left to your sends and mentions.

By , Founder & CEOUpdated 8 min read

Run the numbers for your store: the free UTM coverage calculator.

To trace a direct traffic spike, pin down the day it started. Then check in GA4 whether it bought anything, where it landed and which devices it used. Rule out bots and your own team, and match what is left to your sends. A deep landing page usually means an untagged link.

Step by step

Adding annotations needs the Analyst role or above in GA4, and defining internal traffic needs Editor. Keep the spike day and an ordinary day of the same weekday side by side throughout.

  1. Pin the day it started. In GA4, open Reports, then Acquisition, then Traffic acquisition. Set the dates to cover the spike and a few weeks either side, and find the Direct row of Session default channel grouping. Note the first day of the jump, and whether the line came back down or stayed up. Menu path: Reports > Acquisition > Traffic acquisition.
  2. Mark it, and look for Google's own note. Right-click the spike day on the report's line graph, click Add annotation and give it a title. Google's help says it may add its own annotation when a significant data-impacting event occurs. If one sits on your spike day, read it before you blame anything else. Menu path: any report's line graph > right-click > Add annotation; the full list sits under Admin > Data display > Annotations.
  3. Check whether the spike bought anything. Read the Direct row's Engaged sessions, Engagement rate and Key events for the spike day, then for the ordinary day. GA4 counts a session as engaged if it lasted 10 seconds or longer, had a key event or had 2 or more page views. A crowd with almost no engaged sessions and no key events was not shopping. Menu path: Reports > Acquisition > Traffic acquisition, Direct row.
  4. See where it landed. Switch the table's dimension to Session source / medium, then click the plus icon and add Landing page + query string as a secondary dimension. Search the table for (direct) / (none). Many sessions on one deep product URL point to a link that lost its tags, while home page visits point to people typing your name. Menu path: Reports > Acquisition > Traffic acquisition > dimension drop-down > Session source / medium, then plus icon > Landing page + query string.
  5. Look at the devices. Open Tech details and compare Browser, Operating system and Screen resolution for the spike day and the ordinary day. A bump that sits in one browser or one screen size, with almost no engagement, looks like a bot. GA4 drops known bots by itself, but its help says you cannot see how much it dropped. Menu path: Reports > Tech > Tech details.
  6. Ask Shopify which sessions were bots. In your Shopify admin, go to Analytics > Reports, filter the Category to Acquisition and open Sessions over time for the same dates. If the configuration panel is hidden, click Controls. Where the report shows a Human or bot session row under Filters, set it to Bot. Shopify only classifies sessions from 7 October 2025 onward. Menu path: Shopify admin > Analytics > Reports > Category: Acquisition > Sessions over time > Controls > Filters > Human or bot session.
  7. Take your own team out. Launch days bring staff and agencies to the site, so mark their visits as internal traffic. In GA4 Admin, under Data collection and modification, click Data streams, pick your web stream, then Configure tag settings, Show more and Define internal traffic. The full setup, data filter included, is in how to reduce direct traffic in GA4. Menu path: Admin > Data collection and modification > Data streams > web stream > Configure tag settings > Show more > Define internal traffic.

A worked example

For illustration, say Direct usually brings about 300 sessions a day, and one Thursday it shows 1,500. In this worked example, Google added no annotation that day, so the extra 1,200 sessions need a story of their own. Key events rise a little and engagement rate falls a lot, so most of the crowd was not shopping.

Say the landing page check splits those 1,200 sessions three ways. Suppose 700 land on one gift set page, 400 on old blog posts and 100 on the home page. The gift set visits carry the discount code from that morning's text message in their query string. That text went out through a link shortener with no UTM tags, so every click arrived without a source.

The blog visits look odder. Tech details puts nearly all of them on one browser and one screen resolution, with almost no engaged sessions. Shopify's Human or bot session filter marks a matching batch as Bot. That is a crawler GA4 did not know.

The home page visits came from people who heard the owner on a podcast that week and typed the address. That slice is real demand, and the only part that needs patience.

So one spike held three stories: a mislabelled text, a bot and a small bump of interest. The fix for the text is to tag the next one with utm_medium=sms, which GA4's channel rules file under SMS. The bot needs no fix in revenue terms, because it never buys.

Now the money side, from one store's real export. On its Journeys sheet, journeys with 1 touch hold 79.5% of revenue, with 0.5 days to buy. Untagged clicks that buy the same day join exactly that row: one touch, no source, a sale within hours.

In that one store, a text that loses its tags hands its sales to Direct. That row already holds 57.7% of revenue on the Channels sheet. No model can split a 1-touch journey after the fact, so the only real fix is the tag on the next send.

What should you check when the trace finds nothing?

  • The jump never came back down. That is a step, not a spike. Look for a change made that day: a new redirect, a link shortener, a checkout or domain move. Google's help warns that redirects and URL shorteners can strip the tags on the way in.
  • Shopify's sessions moved around 21 to 23 September 2026. That is Shopify's session measurement rollout, not your buyers. Its help says to treat comparisons across those days as a measurement change.
  • GA4 shows the spike and Shopify does not. Shopify now filters identified bot sessions out of its session reports by default, while GA4 removes only the bots it knows. A crawler can show up in one and vanish from the other.
  • The spike is spread across pages and devices. That pattern fits real people, often after a mention. Check Organic Search on the same days, because people who search your name arrive there instead.

What to do this week

  1. Set an alarm for the next spike. On the GA4 Home page, scroll to Insights, click View all insights, then Create, and under Start from scratch click Create new. Pick Daily, click Change to narrow the segment to Direct, choose Sessions with the condition Has anomaly and add your email. Pass: the insight is listed under Manage with email on. Fail: you cannot create it, so ask someone with the Editor role.
  2. Measure last month's bots in Shopify. Open Sessions over time for last month and add Human or bot session as a dimension from the Dimensions menu in the configuration panel. Pass: bot sessions are a small, steady share. Fail: they arrive in bursts on the days Direct jumped, so judge those days with bots filtered out.
  3. Tag the next text before it goes out. Give every link utm_source and utm_medium=sms, skip the link shortener, and tap one on your phone. Pass: the send day shows under SMS in Traffic acquisition. Fail: Direct jumps again, so a redirect is still stripping the tags.

Check the homework. Your GA4 Attribution paths export already holds the evidence. Causality Engine reads that one file and shows what each channel caused next to what last-click gave it, in 1 to 2 minutes, for €99 once (excluding VAT), refundable within 30 days. Check the homework

Sources, 1 October 2026: Traffic acquisition report (Google); About annotations (Google); Landing page report (Google); Tech details report (Google); Known bot-traffic exclusion (Google); Bot filtering in Shopify analytics and reports (Shopify); Acquisition reports (Shopify); Filter out internal traffic (Google); Analytics Insights (Google); Default channel group (Google); Understand (direct) / (none) traffic (Google)

Frequently asked questions

  • Why does a direct spike show in GA4 but not in Shopify?
    Often because it was bots. Since Shopify's session measurement rollout of 21 to 23 September 2026, identified bot sessions are filtered out of its session reports by default. GA4 removes only the bots it knows. So a crawler can lift GA4's Direct and leave Shopify's sessions flat.
  • Can GA4 email me when direct traffic spikes?
    Yes, with a custom insight. Under View all insights, click Create, narrow the segment to Direct, pick Sessions with the condition Has anomaly and add email addresses. Hourly checks are available for web data. You need the Editor or Administrator role to create one.
  • What does a direct spike on one product page usually mean?
    Usually a link that lost its tags. A send, a post or a printed code pointed at that page without UTM parameters, or a redirect stripped them. GA4 then filed the clicks under Direct. Check Landing page + query string for that day, then tag the link.

Go deeper: Causal attribution, explained.

Sixty-second versions of these ideas: Causality Engine on YouTube Shorts.

Keep reading

Terms in this article

Browse the full glossary

Your platforms guess.
We run the math.

Upload a GA4 export and see what each channel caused, next to last-click, in 1–2 minutes. The read is yours to keep.

Free, in your browser: your file is not uploaded. The full read is €99, refundable within 30 days. Prices exclude VAT.
Or book a 30-min call.