Where duplicates come from
URL parameters after filters and sorting, versions with and without a slash, http and https, www and non-www, pagination pages, UTM tags in newsletter links. For a human it is one page, for a robot – different URLs with identical content.
What this means in practice
Without a canonical page, signals are diluted across copies, and the crawl budget is spent on crawling junk URLs instead of new materials. In Yandex.Webmaster reports, these pages can be found via "Duplicate meta tags".
Common mistakes
Canonical to a non-existent URL or one blocked in robots.txt, canonical chains pointing to each other, canonical to the homepage from all site pages. Each of these breaks indexing worse than the complete absence of the tag.