Home
Domain Management
Traffic Health
Traffic Health ISP Trends
Traffic Health ISP Trends

SERIES:

Ultimate Guide To Traffic Health

Traffic Health ISP Trends

How to read the ISP Trends report in Traffic Health Premium, and what to do when an internet provider or mobile carrier appears to be blocking one of your tracking domains.

When a tracking domain stops working for people on one mobile carrier or one home internet provider, there is usually no error anywhere in Everflow. Clicks simply stop arriving from that provider while everything else looks normal. ISP Trends is the report that makes that pattern visible.

This article covers what the report shows, how to read a drop, and what to do when a provider does appear to be blocking one of your domains.

Traffic Health PremiumISP Trends is part of Traffic Health Premium, along with reputation flags, alerts and third-party domain monitoring. The Basic plan is free and monitors your Everflow tracking domains only. Premium is priced by how many domains the plan covers, starting at $350 per month. You choose the capacity in Control Center → Billing → Traffic Health. Tracking domains themselves are billed separately from Traffic Health.

Where To Find ISP Trends

Open Traffic Health and select the ISP Trends tab. The report covers the tracking domains configured on your account and the internet service providers that traffic to them is arriving from.

The Traffic Health ISP Trends tab selected, showing the Top ISPs with Declining Clicks summary card above the full trends table
Read it as a direction, not a verdictISP Trends is built from your own click and conversion data. It shows you where traffic is falling away, which is a strong first indicator. But a decline is not proof that a provider has blocked you, and the report is not a block check. Always confirm with the steps in Working through it below before acting on it.

Top ISPs With Declining Clicks

The card at the top of the page is the short version of the whole report. It ranks the providers where your domains have lost the most traffic, so you can see at a glance whether anything needs attention without reading the table underneath.

The Top ISPs with Declining Clicks card ranking five providers by the size of their traffic decline over the last thirty days

The card is limited to providers with meaningful volume behind them, so a domain that only ever saw a handful of clicks from a provider will not appear here. If nothing is trending downward, the card and the table are both empty. That is the healthy state, not a loading problem.

Reading The Table

Each row pairs one provider with one of your tracking domains, and shows how traffic on that pairing has moved. Three controls change what the table is telling you.

The three comparison periods

Every row is compared against three windows at once: seven, fourteen and thirty days ago, each with its own value and its own change against yesterday.

The ISP Trends table showing the seven, fourteen and thirty day comparison periods, each with its own value column and its own change column

Reading all three together is what separates a real problem from noise. A drop that shows up against seven days but not against thirty is usually a partner pausing or a weekday pattern. A drop that deepens as the window widens is the shape worth investigating.

Choosing what to measure

The table can be built on clicks, conversions or revenue, and the change can be shown as a percentage or as a raw count.

The metric toggle offering Clicks, Conversions and Revenue, beside the toggle that switches the change column between percentage and absolute number

Clicks is the right default here. A domain that is unreachable loses clicks before it loses anything else, so clicks move first and move most clearly.

The ISP Trends table with Conversions selected, showing conversion counts and percentage change for each comparison period

Conversions are worth a second pass, because they answer a different question. Clicks holding steady while conversions fall away on one provider points at something happening after the click, a script not loading for example, rather than the domain being unreachable.

Percentages or absolute numbers

The percentage view is the one to scan with, because it makes a collapse obvious regardless of how much volume the provider sends. The absolute view is the one to decide with.

The same table with the absolute number view selected, showing the change as a raw count of clicks rather than a percentage

A ninety per cent drop on a provider that sends twenty clicks a day is not worth an afternoon. The same percentage on a provider carrying a fifth of your volume is. Switch to absolute numbers before deciding what to act on.

Narrowing The View

Filtering by domain or ISP

Table Filters narrows the table to specific tracking domains or specific providers.

The Table Filters menu open with the Domain option expanded, listing the tracking domains available to filter the report by

Filtering by domain answers the most useful diagnostic question in the whole report: is this happening to one domain, or to all of them? A decline isolated to a single domain points at that domain. The same decline across every domain you run usually points at something else entirely: a change on your pages, or a shared piece of infrastructure sitting in front of them.

The Table Filters menu with the Internet Service Provider option expanded, listing the providers available to filter the report by

Filtering by provider is how you follow up a partner report. If a partner tells you their traffic died and names their carrier, filter to that carrier and see whether your own data agrees.

Choosing which columns to show

Table Actions → Columns Customization controls which columns appear and in what order.

The Table Actions menu open on Columns Customization, showing a toggle for each column and drag handles for reordering them

Turning off the comparison periods you are not using makes the table considerably easier to scan, particularly if you are checking it regularly.

How Big A Drop Matters

There is no threshold at which a decline becomes a confirmed block. These are the working ranges our team uses when reading the report.

Change against the comparison periodHow to read itUnder 50%Normal variation. Traffic moves for all sorts of reasons: day of week, a partner adjusting spend, a seasonal pattern.50% to 85%Worth noting, not worth acting on alone. Check whether it holds across all three comparison periods before spending time on it.Over 85%Worth investigating. Check whether the drop is isolated to one domain, and whether it affects every partner sending traffic on that provider.Over 95%Something has almost certainly changed. Traffic this close to zero rarely has an ordinary explanation.

The most informative check is not the size of the drop but its spread. If every partner sending traffic through a domain has lost that provider, the domain is the common factor. If one partner has lost it and the others have not, look at what changed for that partner. A campaign ending is far more likely than a block.

When A Provider Is Blocking Your Tracking Domain

Consumer internet providers and mobile carriers increasingly ship network-level security products, sold under names like Xfinity Advanced Security, Verizon Home Network Protection, AT&T ActiveArmor and Videotron Helix Safety. These block domains their providers associate with tracking or with poor reputation, and they do it for the whole household or the whole mobile connection rather than in one browser.

Networks in Canada see this with Videotron, Rogers and Bell; in the United States it comes up most often with Verizon, T-Mobile, Comcast and Xfinity, AT&T and Spectrum.

This is a real cause and it is worth knowing about. But it is not the only thing that produces these symptoms, and reaching for it first has sent people down the wrong path more than once. Work from the symptom instead. Select the one you are seeing:

This site can’t provide a secure connectionERR_SSL_PROTOCOL_ERROR
▼

What it means: The secure connection is being interrupted before it completes. This is not a problem with your certificate. The same link loads normally from a different network.

What to check: Ask the person seeing it which provider they are on and whether they were on wi-fi or mobile data, then re-test the same link from a different network. Check the domain in Traffic Health before assuming the provider is responsible.

Server’s IP address could not be foundName resolution failure
▼

What it means: The browser never resolved the tracking domain to an address, so nothing was ever requested. Reported as “can’t be reached”, “server can’t be found” or “it couldn’t be resolved”. This is the symptom we see most often.

What to check: Have the affected person switch their device to a public resolver such as Google or Cloudflare and try again. This has resolved cases outright, with no change on the Everflow side.

No error at all, clicks are simply downSilent
▼

What it means: Nothing breaks visibly. Clicks recorded in Everflow stay higher than the sessions landing on your own site, and the gap widens. Networks describe this as click discrepancy, click loss or fall-off, and it is how most people notice a problem first.

What to check: Compare Everflow clicks against sessions on your own analytics for the same window. A steady baseline that moves, three or four per cent becoming ten, is the signal. Then use ISP Trends to see whether the drop concentrates on particular providers.

Clicks land, but arrive with no transaction IDScript blocked
▼

What it means: The request completes and returns normally, but with an empty transaction ID. The click is lost without any error being raised anywhere.

What to check: Check which script path your pages load. The older /scripts/sdk/everflow.js path was added to public ad-blocking filter lists and is blocked by anything that consumes them. Move to /scripts/main.js, which is the path used throughout current documentation and in the platform itself.

It works for you, but not for your partnerNetwork-specific
▼

What it means: You test the link and it loads. The partner, or their traffic, cannot reach it. Whether a domain is reachable depends on the network and often the region the request comes from, so testing from your own connection proves very little on its own.

What to check: Collect the provider name, the region and whether wi-fi was off, then have someone on that same provider test the link. Turning wi-fi off is what separates a mobile carrier problem from a home router or a local network problem.

Working Through It

In order, cheapest first. Each of these has resolved a real case.

1Establish where it fails, and where it does notHave the person seeing the problem tell you their provider, their rough location, and whether they were on wi-fi or mobile data. Turning wi-fi off is the single most useful detail, because it separates a mobile carrier problem from a home router or local network problem. Then get someone else on the same provider to open the same link.
2Check the domain in Traffic Health firstBefore assuming a provider is responsible, look at what Traffic Health already knows. Several cases that were first put down to carrier-level blocking turned out to be ordinary reputation flags that Traffic Health reports, with a documented delisting route. If a vendor is named, start with that vendor’s false-positive appeal rather than moving the domain.
3Try a different DNS resolverIf the symptom is that the address cannot be found, have the affected person point their device at a public resolver such as Google or Cloudflare and try the link again. This has fixed cases outright, with nothing changed on the Everflow side, and it takes a minute to test.
4Check which script path your pages loadIf clicks arrive without a transaction ID, or conversions are falling while clicks hold, check the SDK path on your pages. The older /scripts/sdk/everflow.js path was added to public ad-blocking filter lists and is blocked by anything that consumes them. Current documentation and the platform itself use /scripts/main.js.
5Check anything sitting in front of your tracking domainIf your tracking domain runs behind a proxy or CDN, its security features can drop clicks silently, and nothing on the Everflow side will show a reason. Bot protection, elevated security levels, firewall rules and IP reputation controls are all worth reviewing. In at least one case clicks started arriving again once these were turned off.
6Contain it with a per-partner domainIf the problem follows one partner’s traffic, give that partner its own tracking domain. Their flags then stop affecting everyone else, and you avoid moving every partner on the account. This is a common arrangement for mailer and SMS traffic.
7Move the domain, lastIf a reputation flag is confirmed and an appeal has failed, switching domain is the remaining option. Additional domains are $40 per month each. Update your offers in bulk, then tell partners to pull fresh links, because links already in circulation keep pointing at the old domain. You can leave the old domain live alongside the new one while they migrate. Expect to plan for this rather than treat it as a quick fix.
Changing domain does not always fix itA new domain resolves the problem when the old domain’s reputation was genuinely the cause. It does nothing when the cause is elsewhere, and networks have moved to a brand-new domain that had never carried traffic and seen exactly the same behaviour return. Frequent rotation also has a cost of its own: cycling through similar domains is itself a pattern reputation systems key on. Work through the checks above before moving.

What Traffic Health Can And Cannot See

Traffic Health watches your domains and their IPs against reputation and blocklist sources (Google Threat Intelligence, HetrixTools and EasyList among them), and where one of them flags a domain, it names the source so you know where to appeal. In practice this catches more of these cases than people expect.

What it does not have is visibility into the private lists that consumer network-security products maintain. Those are not published and cannot be queried, so a domain can be blocked by one of them while Traffic Health shows nothing.

A clean Traffic Health result narrows the problem, it does not close it. It rules out the vendors we monitor, which is most of them, and leaves the private lists open.ISP Trends does not check for blocks. It measures your own traffic. A decline is a signal to investigate, not a confirmation.Each hostname is monitored exactly as configured. Monitoring track.example.com does not monitor example.com. A root domain has to be added separately as a third-party domain, which requires Premium.
Tell us when you see oneIf you confirm a provider blocking one of your domains, raise it with your account manager with the provider name, the region, the domain and the date. Several networks reporting the same provider in the same week is information we cannot get any other way, and it is how we spot the broader events.

Common Questions

Q
My tracking link works when I test it. Why is it blocked for my partner?
▼

Because reachability depends on the network the request comes from, and often on the region. A domain can be perfectly reachable on your connection and unreachable on a particular mobile carrier in a particular area. Testing from your own connection tells you almost nothing. You need someone on the same provider to test it.

Q
Traffic Health shows my domain as healthy. Does that rule out a block?
▼

No, but it is still the right first check, and it is right more often than people expect. Traffic Health monitors a wide set of reputation and blocklist vendors, and several cases that were first assumed to be provider-level blocking turned out to be ordinary flags that Traffic Health does report. What it does not have is visibility into the private lists that consumer network-security products maintain, so a clean Traffic Health result narrows the problem rather than closing it.

Q
Is ERR_SSL_PROTOCOL_ERROR a problem with my SSL certificate?
▼

No. The certificate on your tracking domain is valid, and the same link loads normally from another network. The error means the secure connection was interrupted before it finished being set up. Reinstalling or reissuing a certificate will not change it.

Q
I moved to a brand-new tracking domain and the problem came back. Now what?
▼

That happens, and when it does, domain reputation is not the explanation. A domain that has never carried traffic has no reputation to be flagged on. Work through the checks in Working through it above. In practice the causes that survive a domain change have been a blocked script path, security settings on a proxy in front of the tracking domain, or a resolution failure on the end user’s network.

Q
Are Everflow-hosted domains less likely to be flagged?
▼

No. A domain hosted by Everflow carries no inherent reputation advantage over one you bring yourself. What matters is the domain’s own history and the behaviour of the traffic running through it.

Q
Can Everflow get my domain unblocked?
▼

No. Consumer network-security products and reputation vendors are outside the platform, and they only accept appeals from the party responsible for the domain. Where a vendor is named in Traffic Health, the delisting route is that vendor’s own false-positive process. Networks that do this regularly report appeals usually coming back the same day.

Q
Should I rotate domains every time one gets flagged?
▼

Not automatically. Rotation used to be the standard answer and it is now producing worse results for high-volume networks. Frequent rotation across similar-looking domains is itself a pattern that reputation systems key on. Networks that used to rotate are increasingly appealing the flag first and only moving the domain when the appeal fails.

Q
Can I change the tracking domain for one partner only?
▼

Yes. Assigning a specific tracking domain to an individual partner is supported, and it is a common arrangement for partners whose traffic carries more risk. It also contains the damage: a flag picked up on that partner’s domain does not affect everyone else.

Q
If I switch tracking domain, do my partners have to pull new links?
▼

Yes. Changing the domain on your offers does not change links your partners are already using, so they need to take fresh links. You can update offers in bulk, and you can keep the previous domain live alongside the new one while partners migrate.

Q
What does an additional tracking domain cost, and how quickly can I get one?
▼

Your first domain is included with your Everflow account. Additional domains are $40 per month per domain, whether they are fully managed or co-managed, and this is billed separately from Traffic Health, so you do not need Premium to add domains. If you expect to need spares, it is worth having them in place before you need them rather than arranging one mid-incident. See Domain Management Options for what each management type covers.

Q
Do ISPs treat track.mydomain.com and mydomain.com as the same domain?
▼

Traffic Health does not roll them up. It monitors each hostname exactly as configured, so a root domain is only monitored if it is added separately as a third-party domain, which requires Traffic Health Premium. Whether an individual reputation vendor rolls a subdomain up to its root varies by vendor, and is not something we can answer for all of them.

Related Reading

Next in This Series