Skip to content
FLOWPILOTS

GUIDE

How to audit a website's conversion tracking

- Brad Raimer, founder

Conversion tracking fails in layers. A tag can be missing from the page, blocked before it runs, cut off from the ad click, or counting the same sale twice. This audit checks them from the page outward, so each step rules out a cause before the next one depends on it. Each platform has its own guide for the detail.

List what the page loads

Start with the pages that matter: the landing pages your ads point at and the page that confirms a conversion, such as the thank-you page after a form. For each, write down which tags it is supposed to carry. Google lists a move to a new domain or a new thank-you page among the causes of a missing tag, so check every page in the path, not just the home page.

Check consent before you call it broken

A site that asks visitors before tracking will hold its tags back until they answer. In the basic form of Google's consent mode, Google tags do not load and send nothing before the visitor interacts with the banner. Run every test below twice: once after allowing, to prove the tags work, and once after declining, to prove they stay quiet.

Check the security policy allows each tag

A Content Security Policy controls which scripts a page may load, and the browser blocks a script from any source the policy does not allow ("Content Security Policy"). Every ad platform's tag loads from its own hosts, so each one has to be in the policy; Google publishes its list in a guide to tags under a CSP.

Make sure the click ID reaches the page

Google Ads ties a conversion back to an ad through the GCLID that auto-tagging adds to the landing address, and Google names two ways it is lost: a site that rejects unknown URL parameters, and a redirect that drops the parameter before the final page. After any redirect, the final address should still carry it.

Read each platform's own status

Each platform reports whether it is hearing from your site. Google Ads gives every conversion action a status, and Tag Assistant tests it live. Meta's Ads Data Advisor marks a pixel Active, Warning, or Inactive. LinkedIn shows the Insight Tag's source status. TikTok offers three verification checks. The detail for each is in its own guide:

Make sure each conversion counts once

A count that runs high misleads too. Google drops a repeat conversion that carries the same transaction ID, which covers a visitor who reloads a thank-you page. Meta pairs a pixel event with the same event sent from your server only when the pixel's eventID matches the server's event_id, the event names match, and both arrive within 48 hours ("Handling Duplicate").

Audit again after every site change

A redesign, a new tag manager setup, a new consent banner, or a tighter security policy can each undo a working setup. Run the audit again after any of them. The free scan below covers the first three for one public page at a time.

To check a page from outside, the FlowPilots free scan reads one public page the way a browser does: which analytics and ad tags it is set up to load, and whether its own headers let them run. It needs no account and nothing installed on the site, and what it cannot observe is named rather than guessed.

Works cited

All posts