Referral traffic in GA4: find it, and why some of it shows as direct
Find referral traffic in GA4 under Acquisition, Traffic acquisition, medium referral. Why apps, chats and lost referrers show as direct, and how to fix it.
LLaunchScaler·Published ·8 min read
In GA4, referral traffic is in Reports, Acquisition, Traffic acquisition: set the dimension to Session source / medium and read the rows whose medium is referral, where the source is the referring site. Some of your referrals never appear there, because visits from apps, chats and links that drop the referrer arrive with no source and GA4 files them as (direct) / (none).
That gap is why a launch or a mention can feel bigger than your referral numbers say. Below is where to find referrals, the specific reasons some show as direct, what the linking site's Referrer-Policy does to them, and how UTM tags and a separate AI channel get the missing sources back.
Where do you find referral traffic in GA4?
Open Reports, then Acquisition, then Traffic acquisition. The default dimension is Session default channel group, where referrals appear as the Referral row. Switch the dimension to Session source / medium to see each referring site, such as news.ycombinator.com / referral, with its sessions, engagement and key events.
Step by step:
Open Reports, Acquisition, Traffic acquisition.
Click the dimension dropdown above the table and choose Session source / medium.
Type referral in the search box above the table and press Enter to keep only referral rows.
Sort by Sessions, or by Key events if you track signups, to see which sites send visitors who act.
GA4 defines the Referral channel as visits "via non-ad links on other sites/apps (e.g., blogs, news sites)." A visit lands there when its medium is referral, app or link, which is what GA4 assigns automatically when a visit arrives with a referrer and no tags. If you tag links yourself, the medium you choose decides the channel; the naming scheme is in UTM parameters: a naming convention.
Questions, answered
What people ask about this
01
Where is referral traffic in GA4?
Open Reports, Acquisition, Traffic acquisition, and change the dimension to Session source / medium. Rows ending in / referral are referrals, with the referring site as the source; the Session default channel group dimension groups them under Referral.
GA4 learns a visit's source from UTM parameters in the URL or from the browser's Referer header. When a click carries neither, GA4 has nothing to go on and records (direct) / (none). Apps, messengers, email clients, PDFs, noreferrer links, redirects and some privacy settings all produce clicks like that.
MDN describes the header simply: "When you click a link, the Referer contains the address of the page that includes the link." Each cause below removes that page or hides it:
Cause
Why the source is lost
What GA4 shows
A link tapped in a native app or chat messenger
There is no web page containing the link, so there is no page to report
(direct) / (none)
A link in a PDF or Word document
Google says traffic from "links from offline documents such as PDFs and Word documents" is direct
(direct) / (none)
A link with rel="noreferrer"
MDN: the browser will "omit the Referer header and otherwise leak no referrer information"
(direct) / (none)
The linking site sends Referrer-Policy: no-referrer
The header is omitted on every request from that site
(direct) / (none)
An HTTPS page linking to an HTTP page
The default policy doesn't send the Referer to less secure destinations
(direct) / (none)
A redirect or URL shortener in front of your link
Google says redirects "can strip UTM parameters" and shorteners "strip away referral details"
(direct) / (none)
An ad blocker on the visitor's browser
Google says ad blockers can interfere with identifying the traffic origin
(direct) / (none)
Two facts limit the damage. GA4 won't let a later direct visit overwrite a known source: "A direct-traffic visit that follows a referred visit will never override an existing referrer." And typed URLs and bookmarks are genuinely direct. The problem is only the shares whose origin you can't see, which people call dark social.
What is the difference between direct and organic search in GA4?
Direct is GA4's label for a visit with no known source: the source is exactly (direct) and the medium is (none) or (not set). Organic Search is a visit from a non-ad search result, including Google's AI Overviews and AI Mode. The two only get confused when a search visit loses its referrer.
GA4's published channel rules make the split exact:
Channel
GA4's rule
Typical visits
Direct
Source exactly matches (direct) and medium is (not set) or (none)
Typed URLs, bookmarks, and links whose referrer and tags were lost
Organic Search
Source is on Google's list of search sites, or medium exactly matches organic
Google, Bing and other search results, including AI Overviews and AI Mode
Referral
Medium is referral, app or link
Links on other websites
AI Assistant
Medium exactly matches ai-assistant, set when the referrer is on GA4's list of AI assistants
ChatGPT, Gemini, DeepSeek, Copilot, Grok
How do you spot referrals hiding in direct?
Look at where direct visits land. People rarely type a long article URL from memory, so direct sessions that start on deep pages right after a launch or a mention are more likely shared links whose referrer was lost. Compare them against the dates you were mentioned.
In Traffic acquisition, add Landing page + query string as a secondary dimension.
Filter to the Direct row of Session default channel group.
Sort by sessions and read the landing pages. The homepage is expected; a specific blog post or pricing page with a jump in direct sessions points to a link shared somewhere you can't see.
Line the jump up with your launch dates, newsletter sends and mentions. If one matches, tag the next link you give that audience.
How does the linking site's Referrer-Policy change what you see?
The linking site's Referrer-Policy header decides how much of its address your analytics receives. The browser default, strict-origin-when-cross-origin, sends only the origin to other sites over HTTPS, so GA4 still sees the referring domain but not the exact page. Only a few policies remove the referrer entirely.
MDN lists what each policy sends to a different site:
Policy on the linking site
What your site receives
Result in GA4
strict-origin-when-cross-origin (the default)
The origin, such as https://example.com/, over HTTPS; nothing to HTTP
Referral from example.com
origin or strict-origin
The origin only
Referral from the domain
origin-when-cross-origin
The origin only, for cross-origin requests
Referral from the domain
no-referrer-when-downgrade or unsafe-url
The full URL, including path and query string
Referral, and the exact referring page
same-origin
Nothing for cross-origin requests
(direct) / (none)
no-referrer
Nothing
(direct) / (none)
MDN notes that strict-origin-when-cross-origin "is the default policy if no policy is specified," and that before a November 2020 spec revision the default was no-referrer-when-downgrade. So on most sites today you'll see which domain sent the visit, and you'll need UTM tags or the site's own analytics to know which page.
Your own site's policy affects the sites you link to in the same way. strict-origin-when-cross-origin keeps your paths private and still tells them the visit came from your domain; no-referrer hides you completely.
How do UTM tags recover what referrers lose?
UTM parameters travel in the URL, not in a header, so they survive apps, chats, PDFs, noreferrer links and privacy policies. Tag every link you hand to someone else: listings, newsletters, social bios, email signatures, slide decks and documents. GA4 reads the tags on arrival and files the visit under your source and medium.
The caveat is redirects. Google says they "can strip UTM parameters from the URL," so give each platform your final URL, not a shortened or redirecting one, then click the live link yourself and confirm the tags are still in the address bar.
Tags also let you measure outcomes per source. With a signup key event in place, each tagged row shows how many visitors signed up; the setup is in GA4 key events: track signups by source.
Why do AI referrals need their own channel group?
Because they behave like neither search nor ordinary referrals. GA4's default channel group now includes an AI Assistant channel for visits "from sources like ChatGPT, Gemini, Deepseek, Copilot, or Grok," and it excludes Google's AI Overviews and AI Mode, which count as Organic Search. For exact control over which AI sources count, build a custom channel group.
Google's help walks through the custom version:
In Admin, open Channel groups and create a new custom channel group, or edit an existing one.
Add a channel named "AI assistants" with a Source condition that matches a regex of AI assistant domains.
Move "AI assistants" above Referral in the channel list, so those visits aren't claimed by the Referral rule first.
Save, then pick the new channel group as the dimension in Traffic acquisition or User acquisition.
Google's example regex is deliberately broad, with alternatives such as .*gpt.* and .*copilot.* that match any source containing those letters. Write a tighter pattern that names the exact domains you care about, such as:
Custom channel groups apply to your reports retroactively, and a standard property can have 2 of them alongside the default. Update the regex when the assistants you care about change. The full method for ChatGPT and Perplexity visits is in how to track ChatGPT and Perplexity traffic in GA4.
Check that your own pages keep sources intact
Two things on your own site decide whether tagged and referred visits arrive whole: redirects in front of your landing pages, and the Referrer-Policy you send to the sites you link to. LaunchScaler's free scan checks both, among 156 checks across 6 of its 7 categories. It flags multi-hop redirect chains, warning above 3 hops, checks that plain HTTP goes straight to HTTPS on the same host in one hop, and reads your Referrer-Policy header, passing a private value such as strict-origin-when-cross-origin. It needs no account, only your URL. Run the free scan.
GA4 needs either UTM parameters or a Referer header to know where a visit came from. Links opened from apps, chat messengers, PDFs and emails without tags, links marked rel="noreferrer", and redirects that strip parameters all arrive with neither, so GA4 files them as (direct) / (none).
03
What is the difference between direct traffic and organic search?
Organic search is a visit from a non-ad search result, including Google's AI Overviews and AI Mode. Direct means GA4 found no source at all: a typed URL, a bookmark, or a link whose referrer and tags were lost on the way.
04
What is dark social?
Dark social is the name people use for shares whose source analytics can't see, typically links sent in messaging apps, texts and email. The visits are real, but they arrive without a referrer and land in direct.
05
Does GA4 track traffic from ChatGPT as referral?
GA4's default channel group now has an AI Assistant channel for sources like ChatGPT, Gemini, DeepSeek, Copilot and Grok, while Google's AI Overviews and AI Mode count as Organic Search. For control over exactly which AI sources count, build a custom channel group.
Put rel=sponsored on paid links, rel=ugc on links your users write and rel=nofollow on links you won't vouch for. A rule per link type, with the markup.
Since September 2019 Google shows no review stars for Organization or LocalBusiness reviews a business hosts about itself. Where product stars come from.