Bot traffic in Google Analytics is one of those problems people try to solve twice. They read an old Universal Analytics guide, go looking for the “exclude all hits from known bots and spiders” checkbox, and cannot find it. That is because GA4 does the job without asking you.
What GA4 does not do is catch everything. The bots that reach your reports are the ones nobody has listed yet, and they are the ones that distort engagement rates, inflate channels and make a quiet month look like a breakout. This guide separates the two and works from Google’s own help page, without bot-share percentages it cannot support.
What is bot traffic, and what GA4 removes for you
Bot traffic is any hit generated by software rather than a person: search crawlers, uptime monitors, scrapers, AI crawlers, and the spam scripts that fake visits to get a referrer into your reports. Some of it is useful to you, such as the crawlers covered in our guide to the Googlebot user agent. None of it belongs in a report about readers.
Google’s Analytics Help page on known bot-traffic exclusion is short and unambiguous. In GA4, “traffic from known bots and spiders is automatically excluded.” Known bots are identified using “a combination of Google research and the International Spiders and Bots List”, which is maintained by the Interactive Advertising Bureau (IAB). The IAB Tech Lab’s page for that list describes it as a paid subscription, updated monthly, built to help companies keep “nonhuman traffic” out of their analytics and billable counts.
Two further sentences matter more than the first. You “cannot disable known bot traffic exclusion”, and you also cannot “see how much known bot traffic was excluded.” The filter is permanent and invisible. There is no counter, no report and no setting.

What GA4 filters and what it misses
The table sets out what Google states against what follows from it. The left column is Google’s wording; the right is the practical consequence.
| What Google states | What it means for your reports |
|---|---|
| Known bots and spiders are automatically excluded | No setup needed for listed crawlers; there is nothing to switch on |
| Known bots are identified from Google research and the IAB International Spiders and Bots List | A bot that is on neither source is not filtered |
| You cannot disable known bot traffic exclusion | You cannot compare figures with and without the filter |
| You cannot see how much known bot traffic was excluded | Any bot you can see in a report is an unknown bot |
The last row is the useful one. Because the excluded share is hidden, you have no baseline. But it also simplifies the diagnosis: anything bot-like that survives into your reports got there because it was not on the list. New scrapers, headless browsers run from cloud servers and referral spam scripts are the usual suspects.
A stated limitation: none of this tells you what proportion of your sessions are bots. Google gives no figure, and studies that quote one measure other people’s sites with other methods. Treat any percentage you read elsewhere as irrelevant to your property.

How to identify bot traffic in Google Analytics 4
Unknown bots rarely announce themselves, but they behave unlike people. These are the patterns worth checking. They are judgement, not Google rules, so look for several at once before acting on any one.
- Sudden spikes from one place. A jump in sessions concentrated in a single city or a single source, with no publication, campaign or link to explain it.
- Near-zero engagement time. Sessions that land and do nothing. Real readers scroll, click and stay; scripts often fire one event and leave.
- Odd hostnames. Hits recorded against a hostname that is not your site, which usually means someone is sending data to your measurement ID directly.
- Referral spam sources. Unfamiliar domains in the referral list sending many sessions and no engagement. Our guide to referral traffic covers how that channel gets polluted.
- Growth in Unassigned or Direct. Traffic that matches no channel rule, or arrives with no source at all, is where scripts often land. See what direct traffic hides.

The quickest way to test a suspicion is a comparison or segment in Explorations. Isolate the suspect city, source or hostname and compare it with the rest of the property on engagement time, pages per session and conversions. A human audience and a script rarely look alike once they sit side by side.
Cross-checking outside GA4 helps too. Organic sessions that rise while clicks in Search Console stay flat deserve a closer look, which is one practical use of the comparison in Search Console vs Google Analytics.
Timing is another tell. People arrive in patterns that follow their working day and their time zone. A source that sends sessions at a flat rate around the clock, or in bursts at the same minute each hour, is far more likely to be a scheduled script than an audience. Plot the suspect segment by hour before deciding.

How to exclude bot traffic from Google Analytics
Once you have found the pattern, there are two layers to work on: what GA4 records, and what reaches your site at all.
Inside GA4
GA4 offers a small set of general controls. Use the unwanted referral settings to stop known spam or self-referring domains from claiming sessions as referrals. Use data filters to keep internal traffic, such as your own team and testing tools, out of reporting. For bots you cannot filter at collection, build comparisons or segments in Explorations that exclude the suspect source, city or hostname, and report from those.
Be honest about what that achieves. A segment hides the noise from a view; it does not remove the hits from the property. Standard reports will still include them, so note the exclusion wherever you share numbers.

Outside GA4
Blocking bots at the server or CDN is outside Google Analytics, and it is the only layer that stops a script before it fires a tag. Firewall rules, rate limits and bot management at your CDN all work here. If the visitors are AI crawlers, our guide to blocking AI crawlers covers the options.
Take care with anything that blocks broadly. Rules that catch scrapers can also catch legitimate search crawlers, which costs you far more than a noisy report. And if your site runs ads, unexplained bot sessions are a revenue risk as well as a reporting one, as our guide to AdSense invalid traffic explains.
Finally, keep a short log. Record the date you noticed a pattern, what you excluded and how. When traffic shifts months later, that log is what lets you tell a real change in readership from a change in your own filters. For the bigger picture of where visits come from, see our overview of website traffic sources.

Frequently asked questions
Does GA4 filter bot traffic automatically?
Yes, for known bots. Google states that traffic from known bots and spiders is automatically excluded, using Google research and the IAB International Spiders and Bots List.
Can I see how much bot traffic GA4 removed?
No. Google states that you cannot see how much known bot traffic was excluded, and you cannot disable the exclusion either.
How do I know if traffic in my reports is from bots?
Look for spikes from one city or source, near-zero engagement time, unfamiliar hostnames and referral spam domains, then compare the suspect traffic with the rest in Explorations.
Can GA4 block bots from visiting my site?
No. GA4 only controls what it reports. Stopping bots from reaching the site happens at the server or CDN, outside Google Analytics.
The takeaway GA4 removes known bots for you and will not say how many. Whatever bot-like traffic remains is unknown, so find it by behaviour, keep it out of the views you report from, and block it at the server when it matters.

