UTM Parameters: The Complete Guide (2026)
What each UTM parameter means, a naming convention you can copy, real examples for every channel, and the mistakes that quietly split your campaign data in two.
UTM parameters are five optional tags you add to the end of a link — utm_source, utm_medium, utm_campaign, utm_term and utm_content — so your analytics can tell exactly where a visit came from, even when the browser sends no referrer. You need three of them on every link you control (source, medium, campaign), all lowercase, with values drawn from a short written list. That one discipline fixes most broken campaign reports.
Key takeaways
- utm_source is who sent the visit, utm_medium is the type of channel, utm_campaign is why; those three are the minimum on every tagged link.
- UTM values are case-sensitive in most analytics tools, so “Newsletter” and “newsletter” become two separate rows that never merge.
- Never put UTM parameters on links inside your own site; they overwrite the visitor's real source.
- Write your allowed source and medium values down in one shared doc and generate links with a builder instead of typing them.
- UTMs matter most where referrers vanish: email, messaging apps, PDFs, QR codes, podcasts and mobile apps.
What are UTM parameters?
UTM stands for Urchin Tracking Module, after Urchin Software, the web analytics company Google bought in 2005 and turned into Google Analytics. The parameter format outlived the product: today almost every analytics tool reads it, from GA4 to Plausible, Fathom, PostHog and VisitTrack. A tagged link looks like this:
https://example.com/pricing?utm_source=indiehackers&utm_medium=community&utm_campaign=2026-10-launchWhen someone clicks that link, the analytics script on the landing page reads the query string and records the visit under source “indiehackers”, medium “community” and campaign “2026-10-launch” — regardless of what the HTTP referrer says. That matters more every year. Referrers get stripped by email clients, messaging apps, native mobile apps and strict referrer policies; SparkToro's 2023 test found that 100% of visits from TikTok, Slack, Discord, Mastodon and WhatsApp arrived with no referrer at all and were reported as direct (SparkToro). A UTM tag survives all of that because it is part of the URL. See the UTM parameters glossary entry for the short definition.
What does each UTM parameter mean?
| Parameter | Answers | Required? | Good values | Bad values |
|---|---|---|---|---|
| utm_source | Who sent the click | Yes | google, newsletter-name, x, reddit, partner-acme | Google, www.reddit.com, email1 |
| utm_medium | What kind of channel | Yes | email, social, paid-social, cpc, sponsorship, referral, affiliate | Email Blast, post, link |
| utm_campaign | Why, which push | Yes | 2026-10-launch, black-friday-2026, onboarding-drip | campaign1, Test, final_FINAL |
| utm_term | Which keyword or audience | Optional | analytics-for-saas, lookalike-1pct | Anything with a person's name or email |
| utm_content | Which link or creative | Optional | hero-cta, footer-link, video-a | Long free-text descriptions |
The most common confusion is source versus medium. Source is the specific sender: one newsletter, one website, one social network. Medium is the category that source belongs to. A useful test: if you could swap the value for a competitor of the same kind and the meaning still fits, it is a medium. “Newsletter” is a medium; “lennys-newsletter” is a source. “Social” is a medium; “linkedin” is a source.
Campaign is the reason the link exists. It should let you group every link from one push — the launch email, the X thread, the partner blog post — into a single row. Dates in campaign names (2026-10-launch rather than launch) save you a lot of confusion a year later, when you run a second launch.
What is a good UTM naming convention?
A naming convention is less about elegance and more about making the same thing always come out the same way. These rules have held up across every team we have seen get UTMs right.
- 1.Lowercase everything. GA4 and most other tools treat “LinkedIn”, “linkedin” and “Linkedin” as three sources, and no report filter can merge them retroactively.
- 2.Use hyphens between words, never spaces. A space becomes %20 or a plus sign depending on who encoded the link, which creates yet another variant.
- 3.Pick one name per platform and write it down: x, not twitter on Monday and x on Tuesday. Keep a short allowed list for utm_medium (eight to twelve values is plenty).
- 4.Make campaign names readable without context: year-month or event, plus a short descriptor (2026-10-launch, 2026-q4-webinar-series).
- 5.Keep personal data out. Emails, names and user ids in UTMs end up in third-party analytics, server logs and screenshots — and Google's own terms forbid sending PII to Google Analytics.
- 6.Generate links with a tool, not by hand. A UTM builder with your allowed values filled in removes most typos; a UTM parser is the quickest way to check a link someone else built.
- 7.Review the source list once a month. Any new value you did not create on purpose is either a typo to fix in the original link or a channel you did not know about.
| utm_medium value | Use it for | Typical sources |
|---|---|---|
| Your own newsletter and lifecycle emails | newsletter, onboarding, product-updates | |
| sponsorship | Paid placements in someone else's newsletter or podcast | the publication's name |
| social | Organic posts on social networks | x, linkedin, reddit, bluesky, threads |
| paid-social | Ads on social networks | x, linkedin, meta, reddit |
| cpc | Search ads | google, bing |
| community | Posts in forums and communities you participate in | indiehackers, hackernews, discord-servername |
| referral | Links from partners, guest posts and directories | the partner's domain-name |
| affiliate | Links from affiliates who earn a commission | the affiliate's handle |
| qr | Printed material and slides | conference-name, flyer-name |
| in-app | Links from your product to your marketing site | app |
What do UTM links look like for each channel?
Concrete examples are the fastest way to internalize a convention. All of these follow the rules above.
Own newsletter, October issue, main button:
?utm_source=newsletter&utm_medium=email&utm_campaign=2026-10-issue&utm_content=main-cta
Paid sponsorship in another newsletter:
?utm_source=saas-weekly&utm_medium=sponsorship&utm_campaign=2026-10-launch
Organic X thread announcing a feature:
?utm_source=x&utm_medium=social&utm_campaign=2026-10-revenue-launch
X ads, one creative out of three:
?utm_source=x&utm_medium=paid-social&utm_campaign=2026-q4-prospecting&utm_content=video-b
Product Hunt launch page link:
?utm_source=producthunt&utm_medium=community&utm_campaign=2026-10-launch
QR code on a conference booth:
?utm_source=saasconf-2026&utm_medium=qr&utm_campaign=2026-saasconfNotice what is not there: no utm_term on organic posts (there is no keyword), no spaces, no capital letters, and the same campaign value reused across every channel that belongs to one push. When the launch ends, filtering by utm_campaign=2026-10-launch shows you every channel that contributed, side by side.
What are the most common UTM mistakes?
Most UTM problems are not exotic. They are the same eight mistakes, in roughly this order of frequency.
| Mistake | What happens | Fix |
|---|---|---|
| UTMs on internal links (a homepage banner tagged utm_source=homepage) | The visitor's real source — Google, a newsletter — is overwritten by your own site | Use custom events or content ids for internal promos, never UTMs |
| Mixed case | One channel splits across several rows that never merge | Lowercase everything; fix links at the source |
| Redirects that drop the query string | The landing page loads with no UTMs and the visit is counted as direct | Test every short link and redirect end to end; preserve query strings in redirect rules |
| A second question mark (?utm_source=x?ref=y) | Everything after the second ? is parsed as part of a value | Use ? once, then & between parameters |
| UTMs after a # fragment | The browser never sends them; most scripts don't read them | Put the query string before the # |
| Tagging organic search or direct links | Search results and bookmarks don't need UTMs; tagging them breaks channel detection | Only tag links you place yourself |
| Personal data in values | Emails and names leak into analytics and logs | Use opaque ids, or nothing |
| No campaign value | You know it was email, but not which email | Make utm_campaign mandatory in your builder |
The internal-link mistake deserves a longer explanation, because it is invisible until you go looking. Most analytics tools treat a new set of UTM parameters as a new campaign touch. If a visitor arrives from Google, clicks a banner on your homepage tagged utm_source=homepage-banner, and then signs up, the signup is credited to “homepage-banner” — a source that is literally your own website. Multiply that across a site and your best channel looks like your own navigation. If you want to know which internal banner works, track the click as a custom event instead.
Do UTM parameters affect SEO?
Not if you only use them on links you place off-site, and not if your pages declare a canonical URL. Google treats ?utm_source=… variants as the same page when a rel=canonical tag points at the clean URL, which every modern framework emits by default. The risk is the opposite situation: tagged internal links that get crawled and indexed as duplicate URLs. That is one more reason to keep UTMs off your own navigation.
Which links don't need UTM parameters?
- Organic search results. Google and Bing send a referrer, and analytics tools classify them as search automatically.
- Search ads with auto-tagging. Google Ads appends gclid, Microsoft Ads appends msclkid; many tools map those click ids to the right source without UTMs.
- Links others post about you without asking. You can't tag them, and the referrer usually tells you enough.
- Links between pages of your own site. Covered above — never.
On the click-id point: VisitTrack's tracker recognizes gclid, gbraid and wbraid (Google), fbclid (Meta), msclkid (Microsoft), ttclid (TikTok), twclid (X) and li_fat_id (LinkedIn), and fills in the source with medium “paid” when no utm_source is present. Explicit UTMs still win when both exist, so your naming convention stays in charge. We cover the X case in depth in how to track X ads conversions without a pixel.
How do UTM parameters connect to revenue?
A UTM tag only tells you where the visit came from. To learn whether that campaign produced money, the analytics side has to remember the visitor's UTMs and match them to a payment later. That is what revenue attribution does: the first UTM source, medium and campaign a visitor arrived with are stored, and when a Stripe, Polar, Paddle, Lemon Squeezy or Razorpay payment comes in for that visitor, it is credited to that campaign. The step-by-step setup is in how to track revenue by traffic source.
Two practical notes if you are wiring this up. First, attribution models disagree about which UTM gets the credit when a visitor arrives through several campaigns; read first-touch vs last-touch attribution before you compare campaigns. Second, VisitTrack reads utm_source, utm_medium and utm_campaign (plus the click ids above); as of October 2026 utm_term and utm_content are not broken out as separate report dimensions, so if creative-level comparison matters, encode the variant in the campaign name (2026-q4-prospecting-video-b) or send it as a custom event property.
How do you audit existing UTM data?
If you are inheriting a messy setup, a one-hour audit gets you most of the way to clean data.
- 1.Export the last 90 days of sources and mediums with session counts (most tools have a CSV export).
- 2.Lowercase and trim every value in a spreadsheet, then group. Every group with more than one original spelling is a duplicate to fix.
- 3.For each duplicate, find the live link that produces the wrong spelling — usually a bio link, an email template or an old ad — and correct it.
- 4.List every medium value and map it to your allowed list. Anything that doesn't map is either a new channel to add on purpose or a mistake.
- 5.Search your own site for “utm_” in the HTML. Every hit on an internal link gets removed.
- 6.Publish the allowed list and the builder link somewhere the whole team sees it, and make it the only way links get created.
A quick sanity check for any tagged link
Paste the final URL into a private browser window, let it load, and look at the address bar. If the utm_ parameters are gone, a redirect stripped them and your analytics will count the visit as direct. This takes ten seconds and catches the most expensive UTM bug there is.
What are the 5 UTM parameters?
utm_source (who sent the visit), utm_medium (what type of channel), utm_campaign (which campaign or push), utm_term (which keyword or audience) and utm_content (which specific link or creative). The first three should be on every tagged link; the last two are optional.
Are UTM parameters case-sensitive?
Yes, in GA4 and most other analytics tools. utm_source=Newsletter and utm_source=newsletter are recorded as two different sources and cannot be merged after the fact, which is why the standard convention is to use lowercase for every value.
Should I use UTM parameters on internal links?
No. A UTM on an internal link overwrites the visitor's real source with a label for your own site, so conversions get credited to your homepage banner instead of the channel that brought the visitor. Use custom events to measure internal promotions.
What is the difference between utm_source and utm_medium?
utm_source names the specific sender, such as linkedin or a newsletter's name. utm_medium names the category of channel that sender belongs to, such as social, email or sponsorship. Many sources share one medium.
Do UTM parameters hurt SEO?
No, as long as your pages have a canonical tag pointing at the clean URL and you only use UTMs on links placed outside your site. Google consolidates the tagged variants under the canonical page.
Do I need UTM parameters for Google Ads?
Not if auto-tagging is on, because Google Ads appends a gclid click id that Google Analytics and several other tools recognize. Adding UTMs as well is harmless and helps tools that don't read gclid.
Can UTM parameters track conversions on their own?
No. UTMs only label the visit. To see conversions or revenue per campaign, your analytics must remember the visitor's UTMs and connect them to a later signup event or payment.