iOS 26 Killed the fbclid: What It Does to Meta Tracking
Since September 15, 2025, Safari strips Meta's click ID on every browse — not just private mode. No fbclid means no _fbc cookie, weaker match quality, and thinner retargeting on a quarter of typical B2C traffic. UTMs survive, and that asymmetry is the whole playbook.

Since September 15, 2025, Safari strips fbclid from every ad click — so the _fbc cookie never sets, match quality thins, and retargeting pools shrink on roughly a third of B2C traffic. UTMs survive untouched. The fix isn’t recovering the parameter; it’s match-key depth — hashed email and phone via CAPI don’t care what Safari strips.
SEPT 15, 2025 FBCLID STRIPPED EVERYWHERE UTMs SURVIVE FIX = MATCH-KEY DEPTH
What Apple changed (and what it didn't)
Link Tracking Protection shipped in 2023 stripping known ad click identifiers — Meta's fbclid, Google's gclid — from URLs in Mail, Messages and private Safari browsing. With Safari 26 / iOS 26 (September 15, 2025), Apple extended it to all Safari browsing by default. Practically: an iPhone user taps your Meta ad, and the ?fbclid=... suffix is removed before your page ever loads. What Apple deliberately did NOT strip: UTM parameters — they describe the campaign, not the individual, and they still arrive intact. That asymmetry defines everything below.

The chain from one stripped parameter to three measurement losses — and the UTM exception that becomes your workaround.
The damage, itemized
Apple targets identifiers that follow a specific user (click IDs); campaign-level parameters (UTMs) pass. That asymmetry is the whole playbook.
The mechanism worth understanding is the _fbc cookie: Meta's pixel reads fbclid from the landing URL and stores it as _fbc, which then rides along on every subsequent event — it's one of the strongest match keys the Conversions API accepts. No fbclid, no _fbc, and every event from that Safari visitor arrives at Meta with one less way to prove "this conversion belongs to that click." On accounts with heavy iOS traffic, the fall-2025 signature was unmistakable: Event Match Quality sliding, attributed conversions thinning, retargeting pools growing slower — all while Chrome-desktop-heavy accounts felt nothing. Run the tree above before blaming creative.

Date of onset + device mix + fbc coverage in Events Manager — three checks separate Safari damage from ordinary tracking rot.
The countermeasure stack (in priority order)
1. Match-key depth in CAPI. The click ID proved identity; customer information parameters replace it. Hashed email and phone at every capture point — checkout obviously, but also email signups, quiz steps, account creation — restore matching that no browser policy can strip, because they travel server-side. This is the single highest-leverage move, and it's most of why pixel-only setups fell so far behind in 2025-26. 2. Lean on UTMs harder. Since campaign-level parameters survive, disciplined dynamic UTMs keep your GA4/warehouse view of Meta traffic honest even where Meta's own attribution thins — set them once per campaign and audit quarterly. 3. Rebuild retargeting around what still fills: engagement custom audiences (video viewers, page engagers, form-openers) are collected on-platform and don't care what Safari strips; weight them up as website-visitor pools thin. 4. Report with the yardstick caveat: like the January and March 2026 reporting changes, this is measurement erosion, not delivery erosion — your Safari-using buyers didn't stop converting; some just stopped being counted. Blended truth (total revenue over total spend) remains immune to all of it.
The 15-minute self-assessment
Step one: device/browser mix — Shopify or GA4 will give your Safari+iOS share; under ~15%, this whole story is a footnote for you. Step two: Events Manager → your dataset → event details — check what share of recent events carry fbc; compare against spring 2025 if you have records. Step three: EMQ trend on Purchase and Lead since September. Step four: if all three point at Safari, prioritize the match-key work this week — every checkout and form that isn't feeding hashed email/phone into CAPI is leaving recoverable signal on the table. Accounts with dense first-party signal barely noticed iOS 26; accounts riding pixel-only setups wrote panicked forum posts. The difference was infrastructure, not luck.

Apple strips what identifies the user; feed Meta identity you legitimately own — email and phone through CAPI — and the yardstick steadies.
Frequently asked questions
What exactly does Safari's Link Tracking Protection strip?+
Does iOS 26 strip UTM parameters?+
What is the _fbc cookie and why does it matter?+
How much of my traffic does this actually affect?+
My EMQ dropped in fall 2025 — was this the cause?+
Can I recover the lost attribution?+
Does this affect retargeting audiences?+
Do Chrome and Android users have the same problem?+
Is Meta doing anything about it on their side?+
Should I stop using fbclid or strip it myself?+
How does this interact with the 2026 attribution changes?+
What's the single highest-leverage fix?+
Signal-poor era, signal-rich accounts
Whitelisted infrastructure — dense history and headroom, so browser-policy shocks move your yardstick, not your business.