iframe tracking is the work of measuring what visitors do inside an iframe, a window that displays another web page within yours, such as an embedded booking widget, enquiry form, video or payment box. Your analytics tags cannot normally see inside these windows, so bookings and enquiries made there go unrecorded unless you plan for them.
How iframe tracking works
An iframe is a separate document with its own address. If it comes from another domain, browsers deliberately keep your page’s scripts out of it for security. Your Google Tag Manager container sees that the iframe loaded, but not the button clicks or form submissions inside it.
There are four main ways around this, depending on who controls the embedded page:
- Native integrations. Many booking and form tools offer their own GA4 connection or Tag Manager option in their settings. Check this first.
- Messages to the parent page. Some tools announce actions to the page that hosts them using a browser feature called postMessage. Calendly, for example, sends a message when a meeting is booked. A listener on your page catches the message and turns it into a dataLayer.push, which Tag Manager can treat like any other event.
- Tags inside the iframe. If the embedded page is on your own domain, or the provider lets you add a container, you can tag it directly. The visit then needs connecting to the parent page, or GA4 counts it as a separate visitor.
- A thank-you page. If the tool can redirect the whole browser window to a confirmation page on your site after completion, you can track that page load instead.
Why it matters
Plenty of UK service businesses take their most valuable actions through embedded third-party tools: salons and clinics with an online booking widget, restaurants with a table reservation box, consultants with a calendar embed, and many firms with a HubSpot or Typeform enquiry form. If none of these send data to GA4, your analytics shows visitors arriving and apparently doing nothing.
The cost goes beyond reporting. Google Ads and Meta cannot optimise towards bookings they never hear about, so they fall back on weaker signals such as page views. Campaigns that genuinely produce bookings look like they fail, and you may switch off the ones that work.
There is also a consent point. Embedded tools often set their own cookies. Under PECR the non-essential ones need consent just as your own do, and your cookie policy should name them.
Common mistakes
- Assuming Tag Manager sees everything on the page, then wondering why bookings never appear.
- Installing GA4 inside the iframe without linking the visit, which splits one person into two users, often with the embedded tool’s domain showing up as a referral source. Cross-domain tracking settings or passing the client ID are needed.
- Relying on cookies inside a third-party iframe. Safari and Firefox block or partition third-party cookies, so tracking inside the frame loses the visitor.
- Counting the iframe loading, or a click on it, as a conversion.
- Listening to every message without checking which domain sent it, which lets unrelated scripts trigger false conversions.
How to act on it
List every embedded tool on the site and note what visitors do in each. Then work through the options above in order: native integration, postMessage listener, a tag in the frame, redirect to a thank-you page. Choose the simplest one that reports the completed action, not just the start.
Test with real bookings in Tag Manager’s preview mode and GA4 DebugView, and confirm that the conversion carries the original source, not the booking tool’s domain.
Embedded forms and booking widgets are among the commonest gaps I find when setting up tracking for performance marketing campaigns.
