Quick Answer
Turning off URL expansion in Performance Max does not lock traffic to the pages you built. PMax can still pull Final URLs from sitelinks, footer links, your sitemap, and auto-applied assets, then spend on /login, /privacy-policy, and /terms pages that cannot convert. Fix it with account-level page exclusions, a page feed of approved URLs, and a weekly Landing Page report check.
URL expansion off is not a whitelist
You spent real time on landing pages that convert. You flipped URL expansion to Off because you wanted PMax to stop inventing destinations. Then you open the Landing Page report for that campaign and feel sick.
Ten to fifteen percent of spend is sitting on legal pages and the login screen. Those URLs cannot take a lead. They cannot take a purchase. Google still treated them as relevant enough to bid on.
Off does not mean "only serve the URLs I picked." It mostly means "do not expand from my asset group Final URL into every crawlable page on the site." PMax still reads sitelinks and footer links. It still sees indexed pages. If a page looks relevant to the query, paid clicks can land there even when the page is commercially useless.
Why junk URLs look relevant to PMax
Privacy pages, terms pages, and login pages score well on soft relevance. They mention your brand. They live on the same domain and show up in the sitemap. To the system they are valid pages on a valid site.
A privacy policy cannot book a demo. A login page sends existing users into the product instead of new buyers into a form. That spend buys activity on pages that were never part of the offer.
Auto-applied assets make the hole bigger. Google can invent sitelinks and other extensions that point at pages you never put in the asset group. Google Merchant Center product links plus leftover site extensions open more doors. You flipped one switch. The account still had several other ways to wander.
Campaign-level URL rules help. Account-level exclusions catch more. If you only blocked junk at the wrong level, PMax can still walk around the fence.
How to stop the bleed
Step 1: Pull the Landing Page report and sort by cost
Open the Landing Page report. Filter to your Performance Max campaigns. Sort by cost, not by conversions. Look for /login, /privacy, /terms, /support, /careers, and any thin utility page. Write down every URL that cannot convert. That list is your exclusion starter kit.
Do this even if URL expansion is already Off. The report is where the leak shows up clearly.
Step 2: Add account-level page exclusions for every non-converting URL
Exclude those URLs at the account level, not only inside one campaign. Account-level page exclusions (the same idea people call account level negative URLs) follow the traffic wherever PMax tries to send it. Campaign-only rules miss spend that routes through another door.
Include common variants. Trailing slashes, localized paths, and old CMS slugs all count. If a page cannot convert, it does not belong in paid traffic.
Step 3: Feed PMax a page feed of approved URLs only
A page feed is a whitelist. You upload the URLs that are allowed to receive traffic, then attach that feed to the campaign. Pair it with the exclusions from Step 2. Exclusions block the junk. The page feed tells PMax where the real offers live.
Yes, feeds need upkeep when you launch a new landing page. That upkeep costs less than silent spend on /terms. If you ship pages weekly, put the feed update on the same checklist as the deploy.
Step 4: Strip sitelinks and turn off auto-applied assets that invent destinations
Audit sitelinks and other site extensions. Remove any link that points at a utility or legal page. Turn off automated assets at the account level when you need tight Final URL control. Leave AI Mode style expansion features off while you are cleaning this up. Those features chase inventory. You are trying to protect the pages that can convert.
Step 5: Recheck the Landing Page report every week
Run the same cost-sorted Landing Page report once a week for 30 days after the fix. New pages get indexed. New sitelinks appear. Auto-applied assets sneak back on. A five minute check beats another quiet month of bleed.
If Maximize Conversions or another Smart Bidding goal is running on dirty destinations, you are also teaching the model that those pages count. Clean the URLs first. Then let bidding learn from pages that can actually convert.
If you want the full PMax lead gen setup in one place, including the URL controls most accounts skip, grab the PMax Lead Gen Setup Checklist. It walks the exclusions, feeds, and asset settings in order so you are not patching this after the money is gone.
Keep PMax, lock the destinations
Controlled PMax with a clean URL map can still work. PMax with URL expansion Off and no exclusions is hope with a budget attached.
Search campaigns give you tighter keyword control. That is a different lever. If you run PMax, treat destination control like budget and conversion tracking... something you set before you scale spend, not after a surprise Landing Page report.
FAQ
Does turning off URL expansion stop PMax from using my privacy policy?
No. Off reduces free-range crawling from your asset group Final URL. PMax can still reach indexed pages through sitelinks, footer links, sitemaps, Google Merchant Center product links, and automated assets. You still need account-level exclusions and, ideally, a page feed.
Are campaign-level URL exclusions enough?
Often no. People who stopped the bleed moved the same non-converting pages to account-level exclusions. Campaign rules miss paths that enter through another campaign setting or asset. Put the permanent block at the account level.
Will a page feed alone fix it?
A page feed helps because it whitelists approved destinations. Combine it with account-level exclusions and a sitelink cleanup. Feeds alone still leave gaps if extensions and auto-applied assets keep offering junk URLs.
How fast should I see the leak stop?
Exclusions can cut the obvious /login and /terms spend within a day or two of serving. Keep watching the Landing Page report for a few weeks. New indexed pages and re-enabled automated assets are how the leak comes back.