
Always include utm_source, utm_medium, and utm_campaign together on every external link, and enforce lowercase plus GA4-compatible medium values from day one. Partial tags do more damage in GA4 than no tags at all, because GA4 stops inferring source or medium from the referrer once it detects any UTM parameter. The rest of this guide covers the six parameters, naming rules, builders, common mistakes, and the governance habits that keep your data clean past week one.
TL;DR:
- Ensure utm_source, utm_medium, and utm_campaign are present on every external link, with all values in lowercase to prevent fragmented data.
- Use only designated medium values recognized by GA4, such as cpc, email, social, referral, display, or affiliate, and avoid mixing separators or case variations.
- Avoid tagging internal links or navigation; track internal behavior with on-site events instead to preserve accurate acquisition data.
- Test UTM tags in GA4 Realtime before launching campaigns to confirm correct attribution and prevent “(not set)” entries.
- Automate link creation using builders and establish a governance system with a shared naming convention and regular audits to maintain consistent, clean data.
UTM parameters are the small pieces of text appended to a URL after a question mark, and analytics platforms read them to figure out where a visitor actually came from. Without them, a click from a paid Instagram Story and a click from an organic Instagram post can land in the same murky bucket labelled “social,” and you lose the ability to tell which one is worth another dollar.
They matter more in 2026 than they did five years ago, not less. Browser privacy changes have chipped away at third-party cookies and made click IDs from ad platforms less reliable across sessions. UTMs live in the URL itself, so they survive cookie deletion, ad blockers, and cross-device jumps in a way that platform-specific tracking pixels often cannot. That is why UTMs remain one of the most durable, platform-agnostic sources of truth an analytics setup can rely on.
There is one rule that saves a surprising number of small marketing teams from a self-inflicted mess: only tag external links. Tagging internal navigation, like a banner on your own homepage that links to a landing page on the same site, overwrites the visitor’s original source and can create a brand-new session out of thin air. That corrupts the very acquisition data you were trying to protect, according to the University of Minnesota’s UMC tracking guidelines.
A quick way to remember when UTMs belong and when they don’t:
GA4 recognizes six standard parameters, but only three of them carry the weight for basic reporting. Get those three wrong and everything downstream, from channel grouping to campaign ROI, gets shaky.
utm_source identifies the platform or publisher sending the traffic, such as google, newsletter, or facebook. utm_medium describes the marketing channel type, like cpc, email, or social, and this is the field GA4 leans on hardest for its default channel grouping. utm_campaign names the specific initiative, for example spring-sale-2026 or q1-webinar-series.
The other three add precision but aren’t strictly required for GA4 to function:
Google itself recommends setting source, medium, and campaign together every time to keep GA4 from filling its reports with “(not set)” entries. A paid search link might look like ?utm_source=google&utm_medium=cpc&utm_campaign=spring-sale-2026, while an organic social post might use ?utm_source=facebook&utm_medium=social&utm_campaign=spring-sale-2026. Same campaign, different medium, and that distinction is exactly what your reports need to separate paid performance from organic reach.
GA4 treats Spring-Sale and spring-sale as two completely different campaigns. That single quirk is responsible for more fractured reporting than almost any other UTM mistake, and it’s entirely preventable with one rule: lowercase, always. Practitioner estimates suggest enforcing lowercase alone removes roughly 30% of the taxonomy drift that shows up in acquisition reports over time, because case inconsistency is the single most common way the same campaign ends up split across multiple rows.
Pick one separator and never mix it with another. A hyphen (spring-sale-2026) or an underscore (spring_sale_2026) both work fine; the problem starts when your team uses hyphens in some campaigns and underscores in others, because GA4 reads them as unrelated strings. Stick to letters, numbers, and your chosen separator. Avoid spaces (they get URL-encoded into %20 and look messy in reports), and avoid special characters like &, #, or ? inside parameter values, since those characters already have meaning in a URL.
Here’s a simple sequence to lock in a naming convention this week:
cpc, email, social, organic, referral, affiliate, display. Stick to strings GA4 already recognizes for channel grouping rather than inventing your own.{season}-{initiative}-{year}, so every campaign name follows the same shape.Pro Tip: Keep a “banned values” list right next to your naming convention, listing medium strings your team has accidentally used before, like “Email” or “Paid-Social” with a capital letter. Seeing the mistake written down stops it from happening a second time.
A campaign called spring-sale-2026 tagged consistently across email, paid social, and affiliate partners will roll up into one clean line in GA4. The same campaign split across Spring_Sale, spring-sale, and SPRING2026 becomes three unrelated rows that nobody notices until someone asks why the numbers don’t add up.
GA4 behaves differently from older analytics tools in one important way: once it detects any UTM parameter on a landing page, it stops falling back to the referrer to guess where the traffic came from. That means a half-finished tag isn’t a minor omission, it’s often worse than no tag at all, because GA4 will report exactly what you gave it, blank fields included, rather than trying to infer the gap.
Omit utm_source or utm_medium and GA4 typically drops that session into “Unassigned” in the Traffic Acquisition report, or fills the specific dimension with “(not set).” Neither is useful for a monthly performance review, and both tend to snowball once a campaign scales across multiple channels.
GA4’s default channel grouping leans heavily on utm_medium, matching against a known set of strings. A mismatch sends otherwise good traffic into the wrong bucket, or no bucket at all, according to Minily’s breakdown of UTM parameter behaviour in GA4.
Standard medium values that map cleanly to GA4’s default channels include:
cpc or ppc for paid searchemail for newsletter and lifecycle campaignssocial for organic social posts (paired with cpc or paid-social for ads)referral for partner or affiliate linksdisplay for banner and programmatic adsaffiliate for partner-driven commission trafficOne formatting habit removes most of this risk before it starts: enforcing lowercase and a locked medium list at the moment a link is created, rather than trying to clean it up in a spreadsheet three months later.
Testing a tag takes less than two minutes and should happen before any campaign goes live. Click the tagged link yourself, then open GA4’s Realtime report and confirm the session shows the source, medium, and campaign you expected within a minute or two. If the Realtime report shows “(not set)” or an unfamiliar channel, fix the link before it goes anywhere near a live campaign, not after the budget’s already spent.
Manual tagging works fine for the occasional email link, but it falls apart the moment your team is running more than a handful of campaigns a month. That’s where builders and dynamic tagging earn their keep.
For one-off links, Google’s own Campaign URL Builder is the simplest place to start. Enter your website URL and each UTM value into the form, and it assembles a correctly formatted link with no risk of a stray character breaking the string. Google explicitly recommends this tool as the standard way to generate tagged URLs by hand.
Paid platforms scale much faster, and that’s where dynamic parameters take over. Instead of typing a static campaign name into every ad, platforms like Google Ads let you drop in macros such as {campaignid} or {keyword}, which auto-populate at click time. Dynamic tagging reduces manual errors and scales cleanly across hundreds of ad groups where hand-typing every URL simply isn’t realistic. This is the same logic behind ValueTrack parameters in Google Ads, which insert campaign, ad group, and keyword data automatically.
A few practical notes for building links that hold up:
Most broken attribution traces back to a small handful of repeat offenders. Tagging internal links tops the list, followed closely by mixed case in campaign names, medium values GA4 doesn’t recognize, and links missing one of the three required fields entirely.
A five-minute checklist before any tagged link goes live catches nearly all of them:
Pro Tip: Run this checklist as a shared document link, not a mental note. The moment it lives only in someone’s head, it stops happening the week that person is on vacation.
Taxonomy drift, where the same campaign splits into multiple inconsistent rows, shows up first in the acquisition report as a campaign name you don’t recognize sitting next to one you do, with suspiciously similar traffic patterns. Catching it monthly, rather than quarterly, keeps the cleanup small enough to fix in an afternoon instead of a full day.
A naming convention only works if it survives contact with a Friday afternoon and a rushed campaign launch. That’s what governance is for, and it doesn’t need to be complicated to be effective.
Start with a central UTM registry, even if it’s just a shared spreadsheet with columns for source, medium, campaign, content, and the final URL. A short master spreadsheet or a CMS-enforced template is genuinely the lowest-friction governance a small team can roll out this week, and it beats a complicated tool nobody remembers to open.
From there, automation removes the human error entirely. A few ways teams operationalize this:
Pro Tip: Set a recurring calendar reminder for the first Monday of every month to pull the Unassigned traffic percentage. If it creeps up two months in a row, someone on the team has gone off-script with a link.
This is exactly the kind of setup work Tech Business Development handles for small marketing teams that don’t have a dedicated analytics hire: building the GA4 property correctly, setting up GTM server-side tagging where it’s warranted, and putting a link-governance template in place so tagging discipline doesn’t depend on any one person remembering the rules.
UTMs and cookies solve different problems, and confusing the two is a common source of frustration. A UTM parameter identifies where a click came from; a cookie or pixel identifies the same visitor across multiple visits. You need both working together, not one instead of the other.
When someone clicks a tagged link, GA4 reads the UTM values on that landing page and stores them in a first-party cookie for the duration of the session (and often longer, depending on your lookback window settings). If that visitor comes back three days later through a bookmark with no UTM at all, GA4 may still attribute the new session to the original campaign if the attribution window hasn’t expired, but that depends on your model settings, not the UTM itself.
Ad platform click IDs, like Google’s gclid or Meta’s fbclid, work alongside UTMs rather than replacing them. A click ID helps the ad platform’s own pixel confirm a conversion; the UTM helps your analytics platform categorize the traffic source in a way that’s readable across every channel, not just that one platform. Losing either one weakens the picture, but losing the UTM is often worse for reporting, because click IDs are proprietary to each platform and don’t roll up cleanly into a single cross-channel view the way a consistent UTM taxonomy does.
The practical takeaway: don’t strip UTMs from a link because “the pixel already tracks it.” The pixel and the UTM are answering different questions, and you need both answers to know whether a campaign actually worked.
UTM parameters are visible in the URL bar, sit in browser history, and often get logged by server access logs long after the campaign ends. That visibility means one rule matters more than almost any other: never put personal data in a UTM value.
Email addresses, names, phone numbers, or internal customer IDs should never appear in a utm_content or utm_term field, even if it feels like a convenient way to track individual recipients. A URL containing someone’s email address can end up cached by a browser, shared accidentally in a screenshot, or logged by a third-party analytics tool that has nothing to do with your intended tracking. That’s a straightforward privacy exposure that’s entirely avoidable.

Instead, use anonymous, campaign-level identifiers. If you need to distinguish individual recipients in an email send, a hashed or randomly generated ID tied back to your email platform’s own system is far safer than a raw identifier sitting in plain text in the URL.
Regional privacy rules, including GDPR in the EU and various state-level laws in the US, generally treat UTM parameters as non-personal campaign metadata as long as they don’t contain identifiable information themselves. Keep it that way, and UTM tagging stays a low-risk part of your analytics stack rather than a compliance liability.
Different channels call for slightly different tagging habits, even though the underlying rules stay the same.
Email campaigns typically use utm_medium=email with utm_content distinguishing between CTA buttons or template variants, for example ?utm_source=newsletter&utm_medium=email&utm_campaign=spring-sale-2026&utm_content=header-cta.
Organic social posts use utm_medium=social paired with the specific platform as the source, such as utm_source=instagram. Paid social ads should use a distinct medium, like utm_medium=paid-social or cpc, so GA4 doesn’t lump paid spend in with organic reach in the same channel bucket.
Paid search through Google Ads often relies on dynamic ValueTrack parameters rather than static values, automatically inserting the campaign ID, ad group, and keyword at click time rather than requiring a manually built link for every ad variation.
Affiliate links generally use utm_medium=affiliate with utm_source identifying the specific partner, for example utm_source=partnername, which lets you compare performance across multiple affiliates inside the same report without them blending together.
The pattern across all four: source names the specific place the click happened, medium names the channel type consistently, and campaign ties every channel’s traffic back to the same initiative for a single, unified report.
GA4 isn’t the only place UTM data ends up, and it’s worth understanding how other tools read the same parameters differently. Marketing automation platforms, CRM systems, and ad platform dashboards often import UTM data through their own connectors, and each one can interpret medium values, casing, or missing fields with its own logic rather than GA4’s.
The most common pitfall when analyzing UTM performance outside GA4 is assuming every tool defines a “channel” the same way. A CRM might group all social traffic together regardless of paid or organic status, while GA4 separates them by medium. Cross-referencing numbers between tools without accounting for that difference leads to reports that appear contradictory when they’re actually just measuring differently.
Another pitfall worth watching: as AI-driven search tools and chat assistants send more referral traffic, some of that traffic arrives with no UTM at all and gets logged under unfamiliar referrer domains rather than a clean channel. Tracking how these newer referral sources show up in GA4 is becoming its own small discipline, and it’s worth checking that traffic isn’t quietly landing in “Unassigned” alongside your own tagging mistakes.
When performance numbers across tools genuinely disagree even after accounting for those differences, triangulating multiple measurement approaches rather than trusting a single dashboard tends to surface which number is actually closer to reality.
If you’re staring at a campaign that’s already live with broken tags, don’t wait for a full overhaul. In the next 48 hours, go through your active campaigns and patch any link missing utm_source, utm_medium, or utm_campaign. That alone stops the bleeding.
Over the next 30 days, write down your naming convention, set up a shared registry, and start routing new links through a builder instead of hand-typing them. This is the point where most of the recurring mistakes disappear for good.
Past 90 days, automate what you can. Dynamic parameters for paid platforms, a locked medium dropdown for anyone creating links, and a monthly audit of your Unassigned rate. I’d rather see a small team nail the 48-hour fix properly than half-implement a complicated 90-day system they abandon by March. Clean data compounds; sloppy data compounds faster in the wrong direction.
— Shayan Shirvani
Spreadsheets and style guides work, right up until someone forgets to open them. Tech Business Development sets up the GA4 property, the naming conventions, and the link-creation templates once, then automates the parts that usually fall apart under deadline pressure, so your team isn’t relying on memory to keep campaign data clean.

An engagement typically covers GA4 and GTM configuration aligned to your actual channel mix, a locked UTM template your team can’t accidentally break, and validation built into the process so every link gets checked in Realtime before a campaign launches rather than after the budget’s spent. The goal is straightforward: your acquisition reports reflect what actually happened, not a patchwork of inconsistent tags nobody had time to catch. If your Unassigned traffic has been creeping up and nobody’s sure why, visit the Tech Business Development services page and request a consultation to get GA4 and your tagging system rebuilt properly.
For the technical reference behind everything in this guide, Google’s own campaign tagging documentation covers required parameters and how GA4 processes them, while the Campaign URL Builder remains the simplest way to generate a correctly formatted link by hand. For deeper GA4-specific channel-grouping behaviour, Minily’s UTM parameter guide is worth bookmarking, and UTM Generator’s best-practices article covers short links and governance in more detail than fits in a single guide.
Use a builder like Google’s Campaign URL Builder to append utm_source, utm_medium, and utm_campaign to every external link, keep all values lowercase, and confirm the tag in GA4 Realtime before the campaign goes live.
The biggest offenders are tagging internal links, mixing uppercase and lowercase in the same campaign name, using a medium value GA4 doesn’t recognize, and leaving out one of the three required fields entirely.
Enter your destination URL and parameter values into Google’s Campaign URL Builder or a similar tool, or use dynamic platform macros for paid ads so the values populate automatically at click time.
Always include the three required ones, utm_source, utm_medium, and utm_campaign, and add utm_content or utm_id only when you need creative-level detail or cost-data import into GA4.
Yes. Tech Business Development configures GA4 and GTM alongside a locked UTM naming template and link governance, so tagging stays consistent without relying on manual spreadsheet upkeep.