Website traffic is the number of visits a site receives over a period of time, broken down by the channel they come from.
Before reading any chart you need to know one thing: "visits" is not a unit of measurement. Google Analytics 4 uses three, users, sessions and views, and to the question "how much traffic did we get in September" they give three different answers. Deciding which of the three is your number, and never changing it again, matters more than any optimisation done afterwards.
Two different things are called traffic
Hosting companies call traffic the volume of data the server exchanges with visitors' devices, measured in gigabytes per month: it is the number that triggers a plan's bandwidth limits. In a control panel such as cPanel it shows up as bandwidth, next to the visitor statistics. Marketers call traffic the visits. The two readings almost never match: a site with heavy images and autoplay videos uses up bandwidth even with very few visitors.
To tell which of the two someone means, look at the unit. Gigabytes: bandwidth. Sessions, users, clicks: people. From here on, this article is about the second.
Users, sessions and views count different things
| Metric | What it counts | When the counter goes up | Where to find it in GA4 |
|---|---|---|---|
| Active users | Distinct identifiers, not people | On that identifier's first visit in the selected period | Acquisition overview |
| Sessions | Periods of interaction with the site | On the first event after 30 minutes of inactivity | Engagement reports |
| Views | page_view events | On every page load, reloads included | Pages and screens |
The session is the most delicate of the three. By default it times out after 30 minutes of inactivity, and the threshold can be changed in the tag settings of the web data stream. Someone who opens a tab, goes out for lunch and comes back to the same page an hour later has produced one user and two sessions. Same person, same content, two different numbers depending on the metric you look at.
The channels, and the new one hardly anyone mentions
GA4's default channel groups are rules written by Google and cannot be edited (you can create a custom group alongside them, though). They are worth reading once, because two of the rules change how reports should be read today.
The first: clicks from Google's AI Overviews and AI Mode stay inside "Organic Search". There is no separate row in the report, so the traffic that survives Google's generated answers only shows up as organic going up or down, mixed in with everything else. What you cannot see at all is the share of searches that end without any click.
The second: for a few months now there has been an "AI Assistant" channel. It collects visits with the medium ai-assistant, which GA4 assigns when the referrer matches a list of assistants maintained by Google, and the documentation names ChatGPT, Gemini, DeepSeek, Copilot and Grok. It is the only place where that traffic is shown separately, and it is also the first reason to reread the channel definitions rather than trusting how they were two years ago.
| GA4 channel | Rule | What actually ends up in it |
|---|---|---|
| Organic Search | Non-ad links in search results | Clicks from AI Overviews and AI Mode too |
| AI Assistant | Medium equals ai-assistant | ChatGPT, Gemini, DeepSeek, Copilot, Grok |
| Direct | Source "(direct)" and medium "(not set)" or "(none)" | Typed URLs, bookmarks and anything that arrives without a referrer |
| Referral | Medium equals referral, app or link | Blogs, news sites, directories, links from other sites |
| Paid Search | Google Search Network or Google Partners, Search campaigns | Google Ads, plus engines managed through Search Ads 360 |
| Organic Social | Source on the social list or medium social | LinkedIn, Facebook, Instagram without paid promotion |
Direct traffic is the most misunderstood entry
The rule says: source exactly "(direct)" and medium "(not set)" or "(none)". It does not say "people who typed the address". Direct collects everything that arrives without a readable referrer: links shared in chats, emails without tracking parameters, PDFs, desktop apps, badly set up QR codes.
At the same time the channel loses visits that really are direct. Session attribution uses the last non-direct click, with a default window of 90 days, and the example is in the documentation: on day 1 the user arrives from an organic Google link and the session is google/organic; on day 68 the same user comes back by typing the address, and the session is still attributed to google/organic. A direct return within 90 days does not show up as direct.
So the direct channel contains visits that are not direct and loses others that are. You can read it as a brand awareness indicator, but knowing that it is the dirtiest of the six.
The number you read is an estimate
Since October 2021 Google Analytics has counted active users and sessions with an approximate counting algorithm, HyperLogLog++, in standard and custom reports, in explorations and in Looker Studio. The BigQuery export does not apply it and counts exactly. Google spells out the comparison: 1,463 sessions in the reports against 1,501 in BigQuery for the same week, 1,828 against 1,876 for the following one. The absolute value moves by a few points; the change between the two weeks is identical in both cases (+25%).
In practice: a trend reading holds up, an absolute number taken to a meeting with three significant figures does not. If the figure has to go into a contract or a bonus, take it from BigQuery and write it down.
Then there is the cookie banner. When someone refuses consent, GA4 does not have their data and can only estimate it through behavioural modelling, which however only switches on at specific thresholds: consent mode in advanced implementation on every page, at least 1,000 events a day with analytics_storage='denied' for at least 7 days, and at least 1,000 daily users with consent on 7 of the previous 28 days.
Below those thresholds there is no estimate: people who refuse do not appear. For a UK small business site with a few hundred sessions a day, traffic means the visits of people who accepted cookies, and nothing else. A year-on-year comparison holds as long as the banner stays the same; the day someone changes its layout or the order of the buttons, the drop you see may just be a different consent rate. It is the first hypothesis to rule out, before looking at rankings.
Estimates of other people's traffic are a separate matter, because there nobody measures the numbers: a tool models them. We have written about it in how to check a website's traffic.
How the UK goes online
In 2025, 95% of UK adults aged 16 and over had internet access at home, and the average adult spent 4 hours 30 minutes a day online in May 2025 (Ofcom, Online Nation 2025, from the Technology Tracker and Ipsos iris data). The figure you need most often, though, is the device split: smartphones account for 75% of men's online time and 79% of women's, computers for 15% and 8%, tablets for 10% and 14%.
These are the numbers to compare your site's device breakdown against. An e-commerce site with 40% of sessions from desktop does not have a tracking problem: it has an audience that behaves differently from the UK average. A B2B site with 70% from desktop is getting visits from the office, and that figure tells you when to publish and when to send emails, not whether the site is mobile friendly.
In our SEO consultancy projects the first week almost always ends up here: not looking at rankings, but deciding which number the business calls traffic and working out where it comes from.
Put it in writing once: which metric, from which tool, over which period, with which filters, and then never change it. In most businesses almost every argument about traffic is an argument between two different definitions, held by people convinced they are talking about the same number: one comes from Search Console, the other from GA4, and neither is wrong. It is the same reasoning that separates a KPI from a metric, and it is the part you cannot hand over to the tool.
Website traffic FAQs
Organic traffic comes from non-ad links in search engine results. Direct traffic is what GA4 cannot attribute to any source: typed URLs and bookmarks, but also links shared in chats or emails without tracking parameters. The two categories are defined in opposite ways: the first by what it contains, the second by what is missing.
They count different things. Search Console counts clicks on Google search results before the page opens; Google Analytics counts sessions after the tracking code has fired, and only for people who accepted cookies. The two figures are not meant to match, and the gap between them is a data point in itself: how Search Console works.
No, not directly. In Google's documentation on debugging drops in search traffic the causes listed are algorithm updates, ranking losses, technical issues, security issues, spam, seasonality and site moves: the volume of visits appears neither among the causes nor among the remedies. Traffic is an effect of rankings, not an ingredient.
Yes, in the default AI Assistant channel, which GA4 assigns when the referrer matches a list of assistants that includes ChatGPT, Gemini, DeepSeek, Copilot and Grok. Clicks from Google's AI Overviews and AI Mode, on the other hand, stay inside Organic Search and have no row of their own in the report.
There is no threshold that applies to everyone, and comparing with the sector average is of little use. A B2B company with 400 sessions a month and eight quote requests is doing better than a portal with 20,000 sessions and no enquiries. The useful question is how many sessions per channel produce a key event, not how many sessions there are in total.