Tracking Audit: How to Tell That Your Marketing Decisions Rest on Wrong Numbers
Whether your tracking measures reliably shows in a single comparison: do the conversions reported in the ad account match the real orders in your backend? This guide shows where the measurement gap really comes from in 2026, the four classes of measurement error, and what a tracking audit actually checks.
In short: the one comparison that reveals broken tracking
Whether your tracking measures reliably, you recognize first by a single comparison: do the conversions reported in the ad account match the real orders in your shop backend or CRM? If they deviate systematically, you are distributing your advertising budget according to a picture that never existed, and steering it on the basis of wrong numbers. This comparison is worth doing before any technology comes into play.
A conversion is a desired action by a user, such as a purchase, an inquiry or a sign-up. The ad account, meaning Google Ads or Meta, reports how many such actions it has attributed to an ad. The backend is the internal system where the actual orders live, for example the shop system, an enterprise resource planning system (ERP) or a customer relationship management system (CRM). The real revenue is booked there, which is why it is the most reliable reference.
Advertising budget is steered on the basis of conversion numbers, by people as well as by the automated algorithms of the ad platforms. If these numbers are wrong, both optimize on a distorted picture.
It can be said plainly: in many accounts it is no longer the human who makes the most expensive decisions, but an algorithm that takes every reported value at face value and shifts the budget accordingly. A wrong number then does not remain without consequences, it is translated automatically and at scale into spending.
Remember: You can only steer what is measured reliably. That is why a tracking audit, the systematic check of your measurement, is first a business decision and only then a technical task.
Why numbers are missing today: not because of “dying cookies”, but because of Safari, iOS, consent and blockers
In 2026, the measurement gap does not arise from an end of cookies in Chrome, but from Safari’s browser protection, the app tracking prompt on the iPhone, declined consents and ad blockers.
A cookie is a small memory file that a website places in a visitor’s browser to recognize them on a later visit. Through such files, tracking assigns visits, clicks and purchases to the same user.
A widespread misconception says third-party cookies would die in 2024 or 2025, and everything would be different afterwards. A third-party cookie does not come from the site you are currently visiting, but from an embedded third party, such as an ad network.
For Chrome, however, this end never came: on April 22, 2025, Google officially decided not to abolish third-party cookies in Chrome; users continue to control them via the browser’s existing privacy settings. By October 2025, Google had discontinued or scaled back central building blocks of its “Privacy Sandbox”. The Privacy Sandbox was Google’s planned replacement for third-party cookies, a bundle of new technologies meant to enable advertising without these cookies; this replacement is now largely not happening.
The measurement gap persists nonetheless; it just arises elsewhere today. Four real sources feed it.
Safari’s browser protection: cookies capped at 7 days, at 24 hours for ad clicks
The first source is Safari’s browser protection. Intelligent Tracking Prevention (ITP) is Apple’s protection feature built into Safari that restricts cross-site tracking of users. Since ITP 2.1, all cookies set via JavaScript in the browser are capped at a maximum lifetime of seven days; “set via JavaScript” means created by the page’s code in the browser itself.
If a visitor arrives via an ad link with appended tracking parameters, such as a Google Ads or Meta parameter in the address, Safari cuts these cookies down to 24 hours. This shortening through appended link parameters, also called link decoration, hits paid traffic hardest of all, because clicks from ads almost always carry such parameters.
In addition, Safari has blocked third-party cookies completely by default since March 2020; Firefox also blocks third-party tracking cookies by default. For these browsers, the third-party cookie is long gone, regardless of the decision in Chrome.
The app tracking prompt on the iPhone: only around 25 to 35 percent agree
The second source is the app tracking prompt on the iPhone. App Tracking Transparency (ATT) is Apple’s consent dialog, mandatory since 2021: an app may only track a user across apps and websites if they actively agree in the dialog. The tracking identifier is the IDFA, an anonymous advertising ID on iPhones with which ad networks recognize a user across apps. Without an active “yes”, it remains hidden from the advertiser.
Reported consent rates are low, on average roughly 25 to 35 percent; these values vary widely depending on the measurement method and are to be understood as an order of magnitude, not an exact rate.
Declined consents: what the user clicks away is missing from the numbers
The third source is declined consents. “Consent” is a visitor’s permission for tracking; the consent banner is the window that asks for it when the page loads. Under the applicable data protection rules, non-essential tracking cookies may only be set after active consent. What a user declines may not be measured in the browser and is accordingly missing from the numbers.
Reported average consent rates are around 30 percent, with studies citing very wide ranges depending on banner design; in Germany and Austria, consent is declined more often than average. This rate is also panel- and design-dependent and is to be understood as an order of magnitude.
Ad blockers: where the measurement script does not load, the visitor is missing entirely
The fourth source is ad blockers. An ad blocker is a browser add-on that hides advertising and in doing so often also stops the small measurement scripts a website uses to count its visitors. If the analytics or pixel script does not load at all, the visitor is completely missing from the measurement.
Ad blockers are widespread: reported magnitudes are around 29 to 30 percent of internet users worldwide, around 40 percent in Europe and, at the top, around 49 percent in Germany; on desktop, the shares are higher. These adoption figures vary by panel and are to be understood as orders of magnitude.
Lost origin information: visits without an attributable source
Added to this is the loss of origin information. A “referrer” is the information about which page a visitor came from. It gets lost when links are shared via private channels such as messengers or email apps, when campaign links carry no origin parameters, when redirects are misconfigured and strip these parameters, and increasingly with clicks from AI assistants, which often arrive without a referrer. Without origin information, the analytics tool cannot assign a visit to any source.
The four error classes: not measured at all, too little, too much, or the wrong event
Mismeasurement takes four forms: an event is not measured at all, too little, too much, or the wrong event is captured. Each form distorts steering in its own way.
A tag is a small measurement code snippet on the page; “firing” means it triggers and reports an event. The four error classes differ in how this firing deviates from reality.
| Error class | Typical cause | Consequence for steering |
|---|---|---|
| Not measured at all | Safari cookie capping, app tracking prompt, declined consent, ad blockers, lost referrers | Channels and campaigns appear weaker than they are; budget flows past them. |
| Measured too little | Partial signal loss from the same sources; only part of the users is captured | The true contribution of a channel is underestimated; profitable campaigns are throttled too early. |
| Measured too much | Double counting through duplicated or incorrectly fired tags; additionally statistically estimated conversions | Campaigns appear more profitable than they are; budget is steered towards an overly positive picture. |
| Wrong event measured | Tags firing on the wrong trigger or capturing the wrong event | Steering optimizes for an action that is not the one actually desired. |
The class “measured too much” arises above all through double counting. The same conversion is captured twice, for example by a Google Ads tag and a simultaneous GA4 import, by tags firing both on a redirect and on the destination page, or by manually added tags that already exist in the tag manager.
Modeled conversions belong to the same class: these are conversions not measured directly but statistically estimated, with which the software extrapolates missing data, for example for users without consent. Modeling is not fundamentally wrong; but it increases uncertainty as soon as it remains unclear which share of the numbers is estimated. The class “wrong event”, finally, arises through incorrectly fired tags that report a different event than intended.
Google Ads and GA4 show different numbers: only above 15 to 20 percent is it a defect
A certain deviation between Google Ads and GA4 is normal, because both attribute and count differently; only differences above roughly 15 to 20 percent point to a configuration error. This threshold is a rule of thumb from practice, not an official limit from Google; it helps separate noise from a real defect.
GA4 stands for Google Analytics 4, Google’s free web analytics tool. GA4 and Google Ads count conversions differently because they use different attribution models and lookback windows. “Attribution” is the rule determining which channel a conversion is credited to.
A “lookback window” is the period in which an earlier click still counts for a later conversion; Google Ads often uses 30 days by default here, GA4 calculates differently. Meta, in turn, uses a 7-day click window by default. Because the two tools attribute according to different rules, different numbers inevitably result, entirely without errors.
Only when the difference exceeds the magnitude of the rule of thumb is a configuration error likely.
Another warning signal is a conspicuously high share of traffic listed in GA4 as “Direct” or “(none)”. “Direct / (none)” in the report means the tool could not determine the origin of a visit; it is not always a genuine direct entry of the address, but often just missing origin information, for example through blocked or deleted cookies, lost referrers, untagged links or faulty redirects. A certain direct share is normal; only a conspicuously high or suddenly rising share is suspicious.
What a tracking audit actually checks
A tracking audit checks whether the measurement tags fire correctly and without duplication, whether Consent Mode v2 is set up cleanly, whether the data layer delivers reliable values, and whether server-side routes such as the Meta Conversions API or Google Enhanced Conversions are connected correctly.
The individual checkpoints are:
- Google Tag Manager (GTM): GTM is the tool that centrally manages all measurement tags on a site. The audit checks correct installation and whether tags are duplicated or incorrectly fired, because exactly that creates double counting.
- GA4 configuration: The audit checks whether the GA4 tag fires on all pages and whether the important events are defined correctly.
- Standardization of origin parameters: The audit checks whether outgoing links carry origin parameters consistently, so channels are attributed cleanly in reporting.
- Consent Mode v2: The audit checks whether this mechanism is set up correctly (see below).
- Data layer: The data layer is an invisible data store on the page where important values such as product, price or order number are held ready so that measurement tags can read them reliably. The audit checks whether these values are clean and reliable.
- Deduplication: The audit checks that the same event is not counted twice when it is reported via multiple routes.
- Attribution model and lookback window: The audit checks whether these are chosen consistently across the tools.
- Server-side tagging: The audit checks whether server-side measurement is in place or needed.
Consent Mode v2: mandatory since March 2024 for advertising to EU users
A central checkpoint is Consent Mode v2. This is Google’s mechanism that passes a user’s consent status to the Google tags and throttles or releases them accordingly. Since March 2024, Google has required that websites serving ads to users in the EU or the European Economic Area, or measuring their behavior, set up Consent Mode v2 and pass the necessary consent signals. Without a correct Consent Mode, new users from this region can no longer be added to remarketing or audience lists.
There is a basic and an advanced variant; the advanced variant sends cookieless signals on refusal and allows more modeling. Consent Mode does not replace a legally compliant banner; it complements it.
Meta Conversions API and Google Enhanced Conversions: the server-side routes
The audit checks two server-side routes separately. The Meta Conversions API (CAPI) sends conversion events directly from your own server to Meta, not from the visitor’s browser where blockers and browser restrictions apply. If it runs in parallel with the browser pixel, deduplication prevents double counting: pixel and CAPI send the same event with an identical event identifier (event_id); if Meta detects two events with the same identifier, it keeps only one. Meta reports the quality of this matching as Event Match Quality on a scale from 0 to 10.
The second route is Google Enhanced Conversions. They enrich a measured conversion with hashed first-party customer data such as email address, name or phone number. “Hashing” means converting data with a one-way procedure (SHA-256) into a string from which the original cannot be computed back; the email address itself thus never leaves the company in plain text. Google matches this hash against the hashes of signed-in Google accounts and thereby gains a second attribution route to the ad click, even without a cookie. The prerequisite is that the first-party data is held cleanly in the data layer.
How broken is your data foundation? A self-assessment
Between us: hardly anyone runs this comparison voluntarily, because the dashboard in the ad account looks so tidy: clean curves, round totals, a picture you like to believe. The uncomfortable experience is that the second number from the backend is almost always off, the first time you hold it up next to it. That is no reason to panic, but the actual beginning of the check.
For the quick self-test, compare the conversions reported in the ad account with the real orders in your backend over a fixed period: up to about 10 percent deviation, the situation is usually uncritical; from around 20 percent, there is need for review. This tolerance too is a rule of thumb from experience, not an official limit.
You can calculate the deviation yourself. Take the number reported in the ad account and the actual number from the backend for the same period and form the percentage difference. A hypothetical calculation example: if the ad account reports 120 conversions and the backend holds 100 real orders, the deviation is 20 percent. The figures used here are freely chosen assumptions and not a measurement; the result is an orientation, not a fixed limit.
Even the direction of the deviation is a clue. If the ad account reports less than the backend, this points to signal loss, meaning events not measured at all or measured too little. If it reports more, this often speaks for double counting or wrong attribution. As an additional check signal, use the level of direct traffic in GA4: a conspicuously high share suggests that many visits can no longer be assigned to any origin. This way, you can classify your own data foundation in stages, instead of viewing it only as “works” or “broken”.
What an audit realistically delivers, and what it does not
An audit makes the measurement gap visible and partially closable, but it never restores 100 percent of the lost data; and a serious audit may well conclude that everything is fine.
The typical procedure is an inventory of which tags fire where, a comparison between ad account and backend, a review of consent, tag manager, GA4 configuration and data layer, and a verdict at the end. Part of the lost conversions can be recovered via server-side routes and Enhanced Conversions or the Conversions API, but not completeness.
And therein lies the actually good news: as soon as you know where and how much your measurement is off, the number in the ad account loses its power to mislead you. A data foundation you had to trust blindly becomes one whose limits you know and can factor in. Privacy-compliant measurement and maximum data volume are in conflict; an audit finds the feasible optimum in between.
On recovery effects, percentages circulate in the trade literature, for example on restoring part of the conversions via server-side measurement. These values vary strongly with the starting position (traffic mix, iPhone and Safari share, blocker rate) and are not guaranteed, universally valid figures. That the effect exists and in which direction it works is proven; a fixed percentage as a promise is not.
At Dometrics, the entry point is a paid data check with a clear yes/no decision; if the check finds no lever, there is an honest no and the fee back.
When browser measurement reaches its limit: server-side as the next step
Part of the conversions lost in the browser can be recovered via server-side measurement. Server-side tracking moves the measurement from the visitor’s browser to your own server, where ad blockers and the cookie capping of the browser protection do not apply; it is carried by the same building blocks as the Conversions API, Enhanced Conversions and first-party cookies. What exactly that means, what it costs and when it pays off is covered in a dedicated guide.
Keep reading: Server-side tracking in detail
Next step: the tracking audit
Whoever wants to know whether their own data foundation holds has it checked in a tracking audit, and receives a clear yes/no decision as the result. At Dometrics, this entry point is a paid data check; if no lever is found, there is a no and the fee back. Dometrics is certified as a Google Partner and Meta Business Partner. Tracking forms the foundation there on which the other services are built.
To the tracking audit: Tracking & Analytics at Dometrics
Look up terms: Tracking pixel · Third-party cookie and ITP · Consent Mode · Conversion · Attribution · Lookback window · GA4 · Google Tag Manager · First-party data · Server-side tracking · all terms in the glossary
Frequently asked questions
How do I know my conversion tracking is broken?
Most clearly by the fact that the conversions reported in the ad account systematically deviate from the real orders or inquiries in your backend, ERP or CRM. If the ad account permanently deviates upwards or downwards from the actual „till", at least one side is measuring incorrectly.
Why do Google Ads and GA4 differ from each other?
Because both tools count conversions according to different attribution models and lookback windows. A certain deviation is therefore normal; only differences above roughly 15 to 20 percent, understood as a rule of thumb from experience, point to a configuration error.
Why do I have so much direct traffic in GA4?
Because „Direct / (none)" is the catch-all for visits whose origin GA4 could not determine. Causes are blocked or deleted cookies, lost referrers, untagged links, faulty redirects and, increasingly, clicks from AI assistants without origin information. A conspicuously high or suddenly rising share is a warning signal.
Are third-party cookies dying now or not?
Not in Chrome. On April 22, 2025, Google decided not to abolish third-party cookies in Chrome and had wound down central building blocks of its Privacy Sandbox by October 2025. In Safari and Firefox, however, third-party cookies are already blocked by default. The measurement gap therefore persists, but it arises via Safari, iOS, consent and blockers, not via a cookie end in Chrome.
What does a tracking audit check?
Among other things, it checks Google Tag Manager for duplicated or incorrectly fired tags, the GA4 configuration, the standardization of origin parameters, Consent Mode v2, the cleanliness of the data layer, deduplication, the attribution model with lookback window, and the server-side connections via the Meta Conversions API and Google Enhanced Conversions.
Do I need Consent Mode v2?
If you serve ads to users in the EU or the European Economic Area or measure their behavior, Google has required Consent Mode v2 since March 2024. Without it, new users from this region can no longer be added to remarketing or audience lists. It does not replace a legally compliant consent banner, it complements it.