An Tran Solutions
An Tran Solutions
Back to Blog

Google Analytics Just Got Dashboards, but the More Important Update Is the One Nobody Mentions

September 23, 20267 min readby An Tran
On this page

There's a widespread belief among business owners: "Google Analytics is hard to use because its reports are a mess." You open it and face a forest of menus, every number in a different place, no idea where to look. So when Google launched Dashboards (drag and drop, tidy, every KPI on one page), the natural reaction was: finally.

I have to say something that isn't easy to hear: the reporting interface was never your problem. The numbers inside it are.

And this very September, Google shipped two updates twelve days apart. The one the whole marketing world wrote about is the one that looks nice. The second one barely got a mention, but it's the one that can actually change the numbers on your screen.

What happened, and when

Two milestones, straight from Google's official release notes (What's new in Google Analytics):

  • September 9, 2026: Dashboards. In Google's words: "Dashboards are now available in Google Analytics. Dashboards are a highly flexible way to help businesses view their KPIs on a single report."
  • September 21, 2026: Hostname filters. Google writes: "Google Analytics now supports Include data filters for hostnames, allowing you to create an allowlist of approved domains authorized to send event data to your property."

One feature for viewing numbers. One feature for deciding which numbers are allowed in. Guess which one got ten times the coverage.

What the new Dashboards can do, and what they can't

To be fair: it's a useful addition, and I'll use it.

You get six chart types: scorecard, table, line, bar, donut, and funnel. Drag, rearrange, and resize with the mouse right inside Google Analytics, with no second product to open. The limits: up to 15 cards per dashboard on a standard property, 30 on a paid Analytics 360 property. You need Editor or Administrator access to create and publish; anyone with access to the property can view a published dashboard (PPC Land).

And here's the part few people read closely. According to the same source, Google stated at launch that API support, segments, and card-level comparisons are not yet supported, with no timeline for any of the three. GA4 Optimizer adds to the list of gaps: no text or description blocks, no display style customization, no calculated metrics, no regex filtering (GA4 Optimizer).

For comparison: Looker Studio has 36 chart types and more than 600 data connectors.

Read it correctly: Dashboards don't replace Looker Studio. They shorten the path to answering a question that three charts can handle. That's a real convenience, but a convenience of presentation, not of reliability.

So if you've been waiting for Dashboards to "finally understand your data," I'm afraid you'll be disappointed. A prettier dashboard doesn't make the data more accurate. It just helps you reach a wrong decision faster, and with more confidence.

The September 21 update is what changes your numbers

This is where I want you to slow down the most.

Before September 21, 2026, hostname filtering in Google Analytics only worked one way: Exclude. You had to know the junk domain in advance, then add it to a blocklist. Every time a new source appeared, you added another line. Forever.

Google admitted that problem plainly in the announcement: "Previously, filtering was limited to Exclude filters, which required ongoing manual updates to keep up with new sources of spam. By allowing you to define a list of approved hostnames, this feature simplifies configuration and helps ensure the integrity of your analytics data with minimal maintenance." (Search Engine Journal)

From September 21, you can do the opposite: declare a list of allowed domains. Any event carrying a different hostname gets filtered out (PPC Land).

It sounds like a minor change to a configuration screen. It isn't minor. It's an admission that until a few days ago, your Google Analytics property accepted data from any domain on the internet by default.

Why that's possible: your measurement ID is public

Plenty of business owners think the measurement ID (the G-XXXXXXXXXX string) is some kind of technical secret. It isn't.

It's a public string sitting in the source code of every page you serve. Anyone can press Ctrl+U and read it. Once they have it, a spammer doesn't need to touch your website at all: they point a script straight at Google's collection endpoint, attach your ID, and claim whatever hostname they like. Your server never logs a single visit, because no visit ever happened (MetricsWatch).

MetricsWatch describes its own incident to show the scale of the distortion: Google Analytics reported 510 users, while the cross-check tool (PostHog) recorded only 16. A gap of more than 30x. The tell: the fake traffic showed up under the bare domain without www, while their real site runs on www.

This isn't only about spam. The same gap creates three very ordinary problems I run into constantly when auditing client websites:

  1. A staging or dev site still carries the real measurement tag. The team tests 200 times, and your conversion rate gets diluted 200 times over.
  2. A cloned or scraped copy of your site keeps your measurement tag intact, so strangers' data gets mixed into your customer data.
  3. Old domains and forgotten subdomains are still sending data, and no one knows.

And every one of those numbers is, as of today, sitting in the dashboard you just finished building.

But don't switch it on yet: this filter is one-way

I won't end on "turn it on now." This feature has a sharp edge you need to see before you touch it.

Google is explicit in its data filters documentation: data excluded by a filter is never processed, "the excluded data is never processed and will never be available in Google Analytics or BigQuery", and filters don't apply to historical data; they're only evaluated "from the point of creation forward" (Google Analytics Help).

Read that again. Not hidden. Not filtered at report time. Gone. Even from your BigQuery export.

The practical consequence: a misconfigured Exclude filter only lets junk in, and you can still separate it out during analysis. But an incomplete Include filter deletes real data, with no way to get it back. Forget a subdomain, forget the second domain in a cross-domain setup, forget your checkout domain, and that slice of data is gone for good.

Three more details to know before configuring, per PPC Land and Search Engine Journal:

  • Each property gets a maximum of 10 data filters, and hostname filters share that quota with internal-traffic and developer-traffic filters.
  • Events sent via the Measurement Protocol aren't subject to Include filters. If you push data server-side, that path stays open.
  • Events without a hostname are blocked automatically, and filters take about 24–36 hours to take effect.

One more technical point worth making: an allowlist stops anyone claiming an unfamiliar hostname. If a spammer claims your actual domain, it still gets through. It's a good layer of defense, not a lock.

Fortunately, Google left a way back: the Testing state. In this state, Analytics tags events that match the filter with a dimension called Test data filter name, so you can preview exactly what would be deleted before you activate it. Don't skip this step. It's the difference between a week of data cleanup and a quarter of lost data.

The right order: trustworthy data first, dashboards second

Here's my thesis in one sentence: Google shipped the tool for viewing KPIs before the tool for ensuring those KPIs are real, and most businesses are rolling them out in exactly that wrong order.

I understand why. A dashboard is visible. It looks good in a meeting; it proves work was done. Nobody praises a hostname filter. It does one thing: make some numbers go down. That's the kind of work nobody wants credit for, but it's the kind that decides whether you spend your ad budget well or badly.

Think about the real business consequences. If 20% of the traffic in your reports isn't human, then your conversion rate gets diluted, your cost per customer is distorted, your "best-performing" channel might just be the most spammed one, and you pour more budget into exactly where the leak is. No dashboard fixes that. A dashboard just presents it more neatly.

So what should you do this week?

Very concretely, in this order:

  1. Open a report and check hostnames before building any dashboard. Add the Hostname dimension to a report (or a table card in the new Dashboards). You should see exactly one or two domains. If you see more, you have work to do.
  2. Cross-check against a source that counts real visits. Server logs, your CDN dashboard, or any tool that only records requests that actually happened. If the two numbers differ by tens of percent, trust the one that actually touches your infrastructure.
  3. Write down every legitimate domain. Your main domain with and without www, subdomains, checkout pages, ad landing pages, old domains that still redirect. Miss one line here and you lose data in the next step.
  4. Create the Include filter in Testing state, and leave it there for at least a week. Check the Test data filter name dimension for any real data getting caught. Only activate it when you're sure.
  5. Ask your engineering team or web agency exactly three questions: Is staging using the production measurement ID? How many domains are sending data to this property? If an Include filter is activated incorrectly, what do we lose?

If the answer to the first question is "let me check," you've just found the reason your numbers never add up.


Dashboards are a good feature, and I encourage you to use them. But use them in the right order: clean the water supply first, then buy the nice glass.

The September 21 update came with no glossy screenshots and no one writing odes to it. It just quietly closed a gap that has been distorting the reports of a great many businesses for years. That's the kind of news most worth reading, and always the least read.

Need someone to audit your entire measurement setup before you make budget decisions based on it? Get in touch, or see how I approach SEO and performance.

Sources

Related articles