Skip to content
DMarketer Tayeeb – Digital Marketing Expert in Bangalore | SEO, SEM & SMM Expert
Contact

UTM Parameters: A Complete GA4 Campaign Tracking and QA Guide

UTM parameters label an incoming link with the source, medium and campaign you chose. To trust the resulting GA4 row, carry those values through the redirect, confirm the landing page sent them with its first measurement event, and read the session-scoped report after processing. This guide follows that whole path, including Google Ads auto-tagging, consent behavior and the common Direct, Unassigned and (not set) cases.

UTM means Urchin Tracking Module; people also call these UTM tags, codes or campaign parameters.

A UTM is a campaign label, not a tracking tag by itself. GA4 still needs to load on the landing page and collect the event. A correct-looking URL cannot prove that the tag fired or that the visit became a session in the intended property. Google’s campaign URL guidance and manual and automatic tagging reference define the fields below.

Choose fields that answer a reporting question

For a manually tagged external link, use utm_source, utm_medium and utm_campaign. Google recommends including all relevant fields when you set any UTM, especially those three plus utm_id and utm_source_platform. Treat those five as a complete naming set for a campaign register; utm_content and utm_term add detail when you will use it. These are recommendations for consistent reporting, not custom dimensions you must create.

The following mapping combines Google’s manual-tagging field table with the Data API dimension definitions.

Manual UTM fields and their GA4 manual traffic-source dimensions
URL parameterUse it forGA4 session dimensionFirst-user dimensionDecision
utm_sourceThe publisher or source sending the visit, such as newsletter or linkedin.Session manual sourceFirst user manual sourceUse on every manually tagged campaign link.
utm_mediumThe acquisition method, such as email, paid_social or referral.Session manual mediumFirst user manual mediumUse one controlled value for each channel type.
utm_campaignThe shared initiative or promotion, such as 2026q4_autumn_webinar.Session manual campaign nameFirst user manual campaign nameUse one stable name across the campaign’s channels.
utm_idA stable campaign identifier that can join campaign data across systems.Session manual campaign IDFirst user manual campaign IDRecommended when the campaign has a durable internal ID.
utm_source_platformThe platform responsible for directing traffic to the property, such as an email or buying platform.Session manual source platformFirst user manual source platformRecommended when that platform distinction is useful.
utm_contentThe placement or creative variation, such as header_cta or carousel_a.Session manual ad contentFirst user manual ad contentOptional; use it only when you will compare those placements or creatives.
utm_termA manually supplied paid-search term or another defined term value.Session manual termFirst user manual termOptional; use it only when the source provides a meaningful value.

The campaign-name and campaign-ID labels have been easy to confuse. Use utm_campaign for the campaign name and utm_id for its ID: Google’s Data API schema says sessionManualCampaignName is populated by utm_campaign, while sessionManualCampaignId is populated by utm_id. The same mapping is given for first-user dimensions. The API schema describes available report dimensions; a listed dimension does not prove that a particular property collected a value.

Google’s manual-tagging page also lists utm_creative_format and utm_marketing_tactic, while saying those parameters are not currently reported in Analytics properties. The Data API schema includes dimension entries for them, but that does not establish that a property will populate them. Do not build a launch report around either field until current Google documentation and a property-level check confirm the data you need.

Pick one answer for each field and put the allowed values in a shared campaign register. Keep source, medium and campaign separate: linkedin is a source; paid_social is a medium; 2026q4_autumn_webinar is the initiative. Use lowercase and a single separator, and make the campaign ID stable if you plan to join reporting to another system. UTM values are case-sensitive, so Email and email can become different dimension values even where a channel rule matches both.

Illustrative register only. Replace the event name and ID with real campaign details before use.
Touchpointutm_sourceutm_mediumutm_campaignutm_idutm_source_platformutm_contentutm_term
Newsletternewsletteremail2026q4_autumn_webinaraw26_01email_platformissue_42_header—
Paid sociallinkedinpaid_social2026q4_autumn_webinaraw26_01linkedin_campaign_managercarousel_a—
Partner referralindustry_partnerreferral2026q4_autumn_webinaraw26_01partner_sitenewsletter_banner—
Printed QRconference_badgeqr2026q4_autumn_webinaraw26_01offline_printregistration_desk_card—

Use one campaign name and ID across the four touchpoints so you can compare them, then distinguish the link placement in utm_content. The medium also affects channel grouping. GA4’s current default rules map email to Email and referral to Referral; Paid Social requires a recognized social source with a paid medium. A custom value such as qr may be Unassigned under the default rules. If you need a named QR bucket, check the current default channel definitions and configure an appropriate custom or primary channel group. The source, medium and campaign dimensions can still be useful even when a medium has no matching default channel.

Build the URL without breaking its query or fragment

The first query parameter follows ?; later parameters follow &. If the destination already has a query, add UTMs with &, not another question mark. Keep a page fragment such as #agenda after the query string. In a URL like https://events.example/register#agenda?utm_source=newsletter, the apparent UTM text is inside the fragment, not the query sent with the page request. See the WHATWG URL Standard for URL components.

For example, this partner URL keeps the existing lang=en query and places the fragment last:

https://events.example/register?lang=en&utm_source=industry_partner&utm_medium=referral&utm_campaign=2026q4_autumn_webinar&utm_id=aw26_01&utm_source_platform=partner_site&utm_content=newsletter_banner#agenda

When code builds links, pass plain values and let the URL API encode them. URLSearchParams percent-encodes reserved characters and Unicode when it serializes a query; a space may appear as +. Do not pre-encode the values, because encoding a percent sign a second time changes the data. For example, a content value of slot A+B & café is safely serialized as slot+A%2BB+%26+caf%C3%A9. The URLSearchParams reference and WHATWG URL Standard define this behavior.

function buildCampaignUrl(destination, campaign) {
  const url = new URL(destination);
  if (url.protocol !== "http:" && url.protocol !== "https:") {
    throw new TypeError("destination must use http or https");
  }
  const fields = {
    utm_source: campaign.source,
    utm_medium: campaign.medium,
    utm_campaign: campaign.campaign,
    utm_id: campaign.id,
    utm_source_platform: campaign.sourcePlatform,
    utm_content: campaign.content,
    utm_term: campaign.term,
  };

  for (const key of ["utm_source", "utm_medium", "utm_campaign"]) {
    if (typeof fields[key] !== "string" || fields[key].trim() === "") {
      throw new TypeError(`${key} is required`);
    }
  }

  for (const [key, value] of Object.entries(fields)) {
    if (value == null || String(value).trim() === "") {
      url.searchParams.delete(key);
    } else {
      url.searchParams.set(key, String(value).trim());
    }
  }

  return url.toString();
}

For example, call the function with one row from the register:

const partnerUrl = buildCampaignUrl("https://events.example/register?lang=en#agenda", {
  source: "industry_partner",
  medium: "referral",
  campaign: "2026q4_autumn_webinar",
  id: "aw26_01",
  sourcePlatform: "partner_site",
  content: "newsletter_banner",
});
console.log(partnerUrl);

The expected serialized output is:

https://events.example/register?lang=en&utm_source=industry_partner&utm_medium=referral&utm_campaign=2026q4_autumn_webinar&utm_id=aw26_01&utm_source_platform=partner_site&utm_content=newsletter_banner#agenda

Here are copyable URLs for all four illustrative touchpoints. They use the reserved events.example domain; replace the destination and event name before launch.

Newsletter:
https://events.example/register?utm_source=newsletter&utm_medium=email&utm_campaign=2026q4_autumn_webinar&utm_id=aw26_01&utm_source_platform=email_platform&utm_content=issue_42_header

Paid social:
https://events.example/register?utm_source=linkedin&utm_medium=paid_social&utm_campaign=2026q4_autumn_webinar&utm_id=aw26_01&utm_source_platform=linkedin_campaign_manager&utm_content=carousel_a

Partner referral:
https://events.example/register?lang=en&utm_source=industry_partner&utm_medium=referral&utm_campaign=2026q4_autumn_webinar&utm_id=aw26_01&utm_source_platform=partner_site&utm_content=newsletter_banner#agenda

Printed QR:
https://events.example/register?utm_source=conference_badge&utm_medium=qr&utm_campaign=2026q4_autumn_webinar&utm_id=aw26_01&utm_source_platform=offline_print&utm_content=registration_desk_card

The function requires an absolute HTTP or HTTPS destination and nonblank source, medium and campaign values. It preserves unrelated query parameters and the fragment, replaces duplicate UTM keys with the new value, and removes old optional UTM fields omitted from the current register. It passed local static checks under Node v24.19.0 for reserved-character and Unicode round-trips, duplicate and stale-field handling, missing core values, invalid URLs and non-web schemes. Those checks tested URL construction only; they did not send a campaign click or verify a live redirect, site tag or GA4 report.

  1. Freeze the register. Confirm the destination, source, medium, campaign name and ID, platform and any content or term values. Check that the final URL is HTTPS and that no value contains a person’s name, email, phone number, CRM record ID or other user-level identifier.
  2. Follow each exact link. Use every distinct destination and redirect path that will actually be placed in an ad, email, partner page or QR code. For session-scoped acceptance, use a fresh test browser profile with the site’s permitted consent state or wait until the prior GA4 session has ended. Opening a second campaign URL inside an active session does not start a new session. Inspect the final address after every redirect and confirm that the target page is correct, each intended UTM is present once, required query parameters survived, and the fragment follows the query. Google documents the mid-session behavior in its campaign and traffic-source reference.
  3. Check the first measurement event. Use Tag Assistant or your tag manager’s preview to confirm the intended GA4 property and a landing-page event such as page_view. Inspect its page_location value while the UTM query is still present. Google documents that UTMs are omitted from the Landing page + query string and Page path + query string dimensions and are instead included in Page location, so those page dimensions are not the right place to look for the full tagged URL; see its URL builder and reporting guidance.
  4. Use DebugView and Realtime as collection checks. Enable debug mode for your own device through Tag Assistant, then confirm that the expected page event appears in DebugView. Realtime is a quick collection check, while both views provide limited attribution for this diagnosis. Use them to confirm that activity arrived, not as the final campaign-report acceptance test; see Google’s Realtime description and DebugView guidance.
  5. Check the processed session report. In GA4, open Reports → Acquisition → Traffic acquisition. Inspect session-scoped dimensions such as Session source / medium and Session campaign; use Session manual ad content or Session manual term in an Exploration when those values matter. For the first source that acquired a person, use User acquisition and its First user dimensions. Google explains the scope difference in its Traffic acquisition report guide and User versus Traffic acquisition comparison.
  6. Record what passed. Save the final destination URL, the observed redirect chain, the GA property/tag checked, consent state used for the test, the page event and page_location observed, the GA4 report dimension and date range, and the date checked. Mark the campaign complete only when the session values match the register in the processed report.

Do not treat a fixed delay as a failure rule. Google says processing may take 24–48 hours and reports can change during that time, while typical freshness intervals differ by property and report. Realtime may be quick; processed acquisition data is the later acceptance point. See Google’s data freshness guidance. If a row is still absent after processing, use the diagnostic order below instead of assuming that consent, attribution or the URL alone caused it.

Consent changes what the test can show. In basic consent mode, Google tags are blocked until the visitor interacts with the banner, and no data is sent before consent. In advanced consent mode, tags can send cookieless pings while consent is denied. However, Google says DebugView does not show events when client-side privacy controls apply or when Analytics cookie consent has not been granted. Run a test in a consent-permitted state under your site’s rules; do not infer that a denied-consent visit was fully tracked or bypass a visitor’s choice. See Google’s consent mode description and DebugView guidance.

Diagnose Direct, Unassigned and (not set) separately

Start with the first observable failure and test one layer at a time
What you seeCheck firstWhat it can meanNext step
UTMs disappear from the final browser URLEach redirect target, shortener, click tracker, final URL and fragment placement.A redirect or URL rule may have rebuilt the destination without the query; a malformed URL may have placed parameters after #.Test the exact campaign destination and preserve the full query at every redirect hop.
Final URL is correct, but no landing event is visibleTag Assistant, property ID, stream, firing conditions, browser blocking and effective consent state.The tag may not have loaded or fired on that page, or the test may not be allowed to send Analytics events.Fix the tag or consent implementation first. Confirm the first event’s page_location before diagnosing report attribution.
Realtime has activity but the campaign report does notDate range, property, report dimension, processing freshness and whether you chose session or first-user scope.Realtime gives a quick activity check with limited attribution; the processed report may lag or the chosen scope may answer a different question.Wait for the property’s normal processing interval, then check Traffic acquisition with Session dimensions. Use User acquisition only for first-user acquisition.
Traffic appears as (direct) / (none)Whether GA4 received referral or campaign information on the session’s first measurement event; inspect final URL and page_location.Google processes a session as direct when referral-source information is unavailable. A missing or stripped UTM is one possible cause, not the only cause.Check the redirect and tag path, then verify source/medium in the processed session report. Do not equate every Direct session with a person typing the URL.
Channel group is UnassignedSession source and medium values against the exact default or custom channel rules in use.Unassigned means no rule in the selected channel group matched the event data. A custom medium such as qr may not match a default rule.Correct the medium if it was mislabeled, or define and use an appropriate custom or primary channel group for a deliberate new category.
A dimension shows (not set)The exact dimension and scope; for Session source / medium, check the session_start event, tag ordering, and whether all relevant UTM values were sent.(not set) is GA4’s placeholder when it has no value for that dimension. Causes vary; missing campaign fields and missing session-start data are documented cases.Inspect collection and event timing, then retest with complete source, medium and campaign values. Don’t diagnose from the placeholder alone.
UTMs show in Page location but not Landing page + query stringThe dimension you selected.GA4 documents that its landing-page and page-path query-string dimensions omit UTM values; Page location carries the full URL.Use Page location for the captured query or Traffic acquisition’s native session campaign dimensions for campaign analysis.
Google Ads values are missing or unexpectedAuto-tagging, the linked Google Ads account, the final click identifier, the relevant Google Ads dimensions and any manual fallback values.Unlinked accounts, unavailable click identifiers, incomplete UTMs or privacy-related identifiers can produce gaps or different dimensions.Keep auto-tagging and the account link healthy. Add manual content or term only for their manual dimensions; if relying on UTMs as fallback, provide a complete consistent set.

Use the placeholder at the dimension level. If Session source / medium is (not set), GA4 says that traffic is shown as Unassigned in the default channel group because there is no matching channel rule. That does not make the two labels synonyms: one is a missing dimension value, the other is a channel classification. Google’s (not set) guide and tagging best practices list distinct causes, including incomplete manual tags, a missing session_start, tag ordering and session identity configuration.

For linked Google Ads traffic, keep auto-tagging enabled so GA4 can use the click identifier and platform-specific dimensions. When manual UTMs and auto-tagging are both present and the click identifier works as intended, Google says the auto-tagged values supply source, medium and other traffic-classification dimensions. You can still add utm_content and utm_term when you need the native Manual Ad Content or Manual Term dimensions.

There is an important fallback case. If GCLID or DCLID cannot be used as intended and at least one UTM is present, Google says it derives all cross-channel traffic-source values from the UTMs alone. Missing values can then produce (not set). Do not copy a blanket rule that manual utm_content or utm_term is forbidden with auto-tagging; also do not assume a manual tag will repair an unlinked account or a broken landing-page tag. Check the exact auto-tagging precedence and the Google Ads dimension troubleshooting steps.

Keep acquisition UTMs on links that bring visitors onto the site. Google’s campaign and traffic-source documentation says a new campaign or source encountered mid-session does not start a new session: those values are associated with the events collected at that point and can be used for event-based attribution, but they are not assigned to the existing session. That makes internal UTMs a poor way to label on-site placements. Track internal clicks with an event or content measurement plan instead of relabeling the campaign that acquired the visit. This recommendation follows from the documented session behavior; it is not a claim that an internal UTM always overwrites session attribution.

Never put names, personal email addresses, phone numbers or person-level CRM identifiers in UTM values. GA4 collects the page URL and Google requires both URL paths and parameters sent to Analytics to be free of personal identifying information; Google’s PII guidance describes redaction as a best-effort control, not permission to place identifiers in campaign links. Use campaign-level labels that describe the channel, initiative or placement.

Use campaign attribution for the question it can answer

UTMs let you inspect which labels were attached to incoming traffic and compare sessions or attributed key events under GA4’s reporting settings. They do not show how many visits or conversions would have happened without the campaign, and they do not prove that a reported key event became a qualified lead or recognized revenue in a CRM. For those decisions, reconcile campaign data with the relevant CRM outcome and use an incrementality design when the question is causal. The separate guide on separating attribution from incrementality covers that measurement distinction.

A link passes QA only when the final URL, the first collected page event and the processed session dimensions agree with the campaign register. Verify every distinct deployed destination, redirect path and creative link before marking the campaign accepted. Keep those three pieces of evidence together so a future report discrepancy can be traced to the URL, collection or reporting layer.

Share this article

Published by

Tayeeb Khan

Tayeeb Khan is the founder of DMarketer Tayeeb, covering digital marketing, SEO and AI. Articles may draw on professional experience, source-based research and AI-assisted or automated production. Firsthand tests are identified in the relevant article; a byline does not imply personal testing or human review of every claim.

Leave a Comment

Your email address will not be published. Required fields are marked *

Stay ahead of the curve

Get actionable digital marketing, SEO, and AI insights delivered to your inbox. No fluff, just value.

No spam. Unsubscribe anytime.