Home › Marketing Analytics › UTM Parameters
MARKETING ANALYTICS · TRACKING

UTM Parameters: Best Practices and a Naming Convention

Most "direct" traffic in an Indian GA4 property is not direct. It is WhatsApp broadcasts, Instagram bios and QR codes that nobody tagged. Here is the five-parameter system, what GA4 actually does with each value, and a naming convention you can paste into a sheet today.

By the Digital Hangover team · Updated September 2026 · 11 min read
Quick answer: UTM parameters are five tags added to the end of a URL — utm_source, utm_medium, utm_campaign, utm_content and utm_term — that tell Google Analytics 4 where a click came from. GA4 uses source and medium to sort sessions into channels like Paid Social or Email, so the values you type decide what your reports say. Write them lowercase, from a fixed vocabulary, and never on internal links.
ANATOMY OF A TAGGED LINK Five parameters, and what GA4 does with each yourbrand.in/offer? utm_source=instagram &utm_medium=social &utm_campaign=2026-10-diwali &utm_content=reel-3 &utm_term=(ads only) utm_source where the click came from instagram · newsletter → Session source utm_medium the channel type social · email · cpc → Default channel group utm_campaign the campaign or push 2026-10-diwali → Session campaign utm_content which creative or placement reel-3 · bio-link → Manual ad content utm_term the keyword or audience (paid) running-shoes → Manual term Lowercase, hyphens, one fixed vocabulary for source and medium — 'Facebook', 'facebook' and 'fb' become three sources. Never tag internal links: it restarts the session and erases the real source.

A tagged link, taken apart: the five parameters and the GA4 dimension each one becomes.

Tracking is the bottom layer of the stack we map in our marketing analytics guide. If this layer is wrong, every dashboard and attribution model built on top of it is wrong too. UTMs are the cheapest part of it to fix: no code, no developer, just discipline.

One thing this page does not do: build links for you. Our free UTM builder does that. This page is the rulebook you hand to whoever uses the builder.

What are the five UTM parameters?

FreeNo codeCase-sensitive

A UTM parameter is a short key=value pair appended to a URL after a ?, separated by &. GA4 reads them on the landing page and records them against the session.

Google's own reference (Collect campaign data with custom URLs) lists the parameters and says three are required whenever you tag at all: utm_source, utm_medium and utm_campaign.

  • utm_source (required) — the referrer. Where the link lived: instagram, whatsapp, newsletter, packaging.
  • utm_medium (required) — the marketing medium. How it got to them: social, paid-social, email, qr, cpc.
  • utm_campaign (required) — the specific push: 2026-10-diwali-sale.
  • utm_content (optional) — which creative or placement, so two links in the same email or two ad variants can be told apart.
  • utm_term (optional) — Google's doc calls it the "paid keyword". In practice, the audience or keyword the click was bought against.

The same page documents a sixth, utm_id, an optional campaign ID for matching against cost data, and warns that values are case-sensitive: utm_source=google and utm_source=Google are two different sources in your reports. Two newer parameters, utm_creative_format and utm_marketing_tactic, are listed but marked as not currently reported in GA4, so leave them out.

What does GA4 do with each parameter?

GA4 maps each parameter to a dimension, then uses source and medium together to assign every session to a default channel group. That grouping is the first thing every acquisition report shows, so the rules matter.

From Google's default channel group definitions (verified September 2026), the rules that matter for manually tagged links are:

  • Paid Social: source matches Google's list of social sites and medium matches ^(.*cp.*|ppc|retargeting|paid.*)$. So instagram / paid-social and facebook / cpc both land here.
  • Organic Social: source matches the social-sites list or medium is one of social, social-network, social-media, sm, social network, social media.
  • Email: source or medium is email, e-mail, e_mail or e mail.
  • Paid Search: source matches a list of search sites and medium matches the same paid regex as above.
  • Display: medium is display, banner, expandable, interstitial or cpm. Referral: medium is referral, app or link. SMS: source or medium is exactly sms.
  • Direct: source is (direct) and medium is (not set) or (none) — no referrer and no UTMs.
  • Unassigned: nothing above matched. This is where utm_medium=qr or utm_medium=whatsapp ends up.

Google notes the channel definitions are not case-sensitive, but the underlying values still are — Instagram and instagram share a channel and then split into two rows the moment you view the report by source / medium.

Two consequences. First, the medium does the sorting. Use social for anything organic on a social platform and paid-social for anything you paid for, and the channel comes out right whether or not Google's source list recognises the platform. We could not verify whether WhatsApp is on that list, which is exactly why we do not rely on it. Second, "Unassigned" is not a bug — it is GA4 saying the medium you invented matches no rule.

The other three parameters are stored, not sorted. Per Google's dimensions reference, utm_campaign populates "Manual campaign name", utm_content populates "Manual ad content", utm_term populates "Manual term" and utm_id populates "Manual campaign ID". You reach them as secondary dimensions.

utm_source vs utm_medium: the distinction people get wrong

Source is the place. Medium is the type of traffic. A useful test: one medium should hold many sources, and one source should be able to carry more than one medium.

  • instagram / social — an organic Story or bio link.
  • instagram / paid-social — a boosted Reel or a Meta ad that appeared on Instagram.
  • whatsapp / social — a broadcast list. Same medium as the bio link, different source.

The mistake we see most is stuffing the channel into the source: utm_source=facebook-ads, utm_medium=facebook. Now "facebook" is both a source and a medium, it never matches the Paid Social regex, and you have a row of Unassigned traffic that cost real money.

The naming convention: one table your whole team follows

Lowercase onlyHyphens, not spacesFixed vocabulary

A convention only works if it removes decisions. The rules below leave one free-text field, the campaign name, and even that has a shape.

ParameterRuleGood exampleBad example
utm_sourceLowercase. One word from a fixed list: instagram, facebook, linkedin, youtube, whatsapp, newsletter, packaging, google, partner-name. Never the medium, never a campaign.whatsappWhatsApp_Broadcast_Oct
utm_mediumLowercase. Only these: social, paid-social, email, cpc, display, referral, qr, sms. New medium = a decision, not a typo.paid-socialPaid Social (space, mixed case)
utm_campaignYYYY-MM-name. Year and month first so campaigns sort by date; then a 1–3 word slug. No brand name (it is your own site).2026-10-diwali-saleDiwaliSale2026_Final_v2
utm_contentThe creative or placement: reel-a, carousel-b, hero-button, footer-link, bio. What you would A/B test.carousel-bimage1 final
utm_termAudience or keyword: lookalike-buyers, retargeting-30d, or the search term for manual search ads. Leave empty when there is no audience to name.retargeting-30dWomen 25-34 Mumbai

Three rules underneath the table. Hyphens, not spaces — a space becomes %20 and breaks when pasted into WhatsApp. Lowercase, always. And no personal data: never put a phone number or customer name in a UTM, because it lands in your analytics as plain text.

Five Indian examples, fully tagged

Assume a D2C brand at yourbrand.in running a Diwali sale in October 2026. Every link below follows the table above; build the real ones with the UTM builder rather than typing them by hand.

  • WhatsApp broadcast to existing customers
    yourbrand.in/diwali/?utm_source=whatsapp&utm_medium=social&utm_campaign=2026-10-diwali-sale&utm_content=broadcast-1
    Medium social so it sorts into Organic Social. Change broadcast-1 to broadcast-2 for the reminder message and you can see which one people acted on.
  • Instagram bio link
    yourbrand.in/?utm_source=instagram&utm_medium=social&utm_campaign=bio&utm_content=bio-link
    The bio is permanent, so the campaign is bio, not a dated name. Swap the destination page, keep the tag.
  • QR code on packaging
    yourbrand.in/reorder/?utm_source=packaging&utm_medium=qr&utm_campaign=2026-10-reorder-insert&utm_content=box-insert
    This will show as Unassigned in the channel view — that is fine. Read it as source / medium. Print a short redirect (yourbrand.in/qr1) that forwards to the tagged URL, so the QR itself stays scannable.
  • Email newsletter
    yourbrand.in/diwali/?utm_source=newsletter&utm_medium=email&utm_campaign=2026-10-diwali-sale&utm_content=hero-button
    Medium email matches the Email channel rule. Tag the hero button and the footer link with different utm_content values.
  • Meta ad landing on your site
    yourbrand.in/diwali/?utm_source=facebook&utm_medium=paid-social&utm_campaign=2026-10-diwali-sale&utm_content=carousel-b&utm_term=retargeting-30d
    Meta does not auto-tag for GA4 the way Google Ads does, so this goes in the ad's URL parameters field. paid-social matches the paid.* regex, so it lands in Paid Social.

For a coaching institute the campaign becomes 2026-11-jee-batch and the broadcast goes to parents who enquired last month. For a clinic, the QR sits on the prescription pad. Inside our performance marketing engagements this sheet is one of the first documents we set up, because it decides whether month-two reporting is possible at all.

Google Ads: auto-tagging, not UTMs

Do not manually tag Google Ads final URLs when auto-tagging is on. Google's GA4 guidance on tagging Google Ads final URLs says auto-tagging "is the recommended approach and ensures that you get the most detailed Google Ads data", and that manual tagging "will only allow you to see a subset of Google Ads data". Auto-tagging appends a gclid to the click, and the linked GA4 property pulls campaign, ad group, keyword and cost from that ID.

If you add UTMs on top, the gclid still wins unless you flip the property setting "Allow manual tagging (UTM values) to override auto-tagging (GCLID values)". Google's Google Ads help page warns that when you do, impressions, clicks and cost "will be reported as 0 for the manual UTM values". The override buys a tidy source / medium row and costs you the numbers you wanted.

The one legitimate case for manual tags on Google Ads is a landing page that rejects unknown URL parameters. If that is you, fix the landing page first.

The mistakes that quietly break the data

  • UTMs on internal links. A tagged button from your homepage to your pricing page starts a new session attribution with the new campaign and overwrites the source that actually brought the visitor. UTMs go on links into your site, never within it.
  • Mixed case and near-duplicates. Instagram, instagram, IG and insta are four sources. Fix the vocabulary, not the report.
  • Tagging Google Ads clicks with auto-tagging on. Covered above. It either does nothing or zeroes your cost data.
  • A medium that matches no rule. utm_medium=instagram or utm_medium=whatsapp lands in Unassigned. Use social or paid-social.
  • Campaign names without dates. diwali-sale is fine in year one. By year three you have three campaigns with the same name.
  • Tagging links to a site you do not own. UTMs only work if the destination runs your GA4 tag. A tagged link to your Amazon listing tells you nothing.

How to set up the convention and the governance sheet

One afternoonGoogle SheetsOwner required

A convention that lives in one person's head is not a convention. It needs a sheet, an owner and a habit.

  1. Write the vocabulary tab. Two columns: allowed utm_source values and allowed utm_medium values, copied from the table above and trimmed to the channels you use. Adding a value here is the only way a new source or medium is born.
  2. Create the link register tab. Columns: date, created by, destination URL, source, medium, campaign, content, term, full tagged URL, where it was used, short link. Every tagged link gets a row, including the ones made at 11 pm.
  3. Build links with the tool, paste them into the register. Use the UTM builder so the encoding is right, then record the result and any short link, so the QR on a box can be traced back.
  4. Add data validation. Restrict the source and medium columns to the vocabulary tab with a dropdown. Typos stop being possible in the sheet, which is where they start.
  5. Name an owner and a review cadence. One person approves new vocabulary. Once a month they open GA4's source / medium view and hunt for values not in the sheet. Each gets fixed in the register and, if it was an ad, in the ad platform.
  6. Check that GA4 is receiving it. Open a tagged link in an incognito window and watch Realtime for the source and campaign. If nothing shows, the usual culprit is a redirect stripping parameters — the GA4 setup checklist covers the property side.

How to read the results in GA4's Traffic acquisition report

Go to Reports › Acquisition › Traffic acquisition. Google's documentation for the report confirms it defaults to "Session default channel grouping" and covers both new and returning users, which is what you want for campaign reading (User acquisition only shows the first touch that created a new user).

Read it in three passes.

  • Pass one — channels. Leave the default dimension. Are Paid Social, Organic Social and Email roughly where you expect? A fat Unassigned row means a medium outside the rules. A fat Direct row means untagged links.
  • Pass two — source / medium. Change the primary dimension to "Session source / medium". Now you see whatsapp / social next to instagram / social. Any value not in your vocabulary tab is a governance failure, not a GA4 one.
  • Pass three — campaign and creative. Switch the primary dimension to "Session campaign", then add a secondary dimension for the manual ad content or manual term. This is where carousel-b beats carousel-a, and where the second WhatsApp broadcast turns out to have driven more orders than the first.

Sort by the key event you care about — a WhatsApp click, a form submit, a purchase — not by sessions. A source with 40 sessions and 6 enquiries beats one with 400 sessions and 2.

Once the rows are clean, you can push this view into a Looker Studio report the founder actually opens, and start asking which touch deserves the credit — the job of marketing attribution, and only answerable when the source data is right.

Where to go from here

UTMs fix what GA4 can see, not what it counts. If key events are missing or the property is double-tagged, a perfect convention still reports into a broken bucket. Our GA4 guide covers the property itself.

The honest scope of a UTM: it tells you which link someone clicked. It does not tell you whether the Reel they watched three days earlier made them click. Keep both facts in mind and the reports stay useful.

Key takeaways: Five parameters, three required. Source is the place, medium is the traffic type, and medium is what GA4 uses to sort sessions into channels — so pick mediums that match Google's rules. Write a vocabulary, put it in a sheet with dropdowns, give it an owner, and build every link with a tool rather than by hand. Never tag internal links or auto-tagged Google Ads clicks.

Frequently asked questions

What are UTM parameters used for?

UTM parameters tell Google Analytics 4 where a click came from. Without them, links you share on WhatsApp, in an Instagram bio, in an email or on a printed QR code usually show up as "direct" traffic. With them, GA4 records the source, medium, campaign, creative and audience against the session, and sorts it into a channel like Organic Social, Paid Social or Email.

What is the difference between utm_source and utm_medium?

utm_source is the place the link lived — instagram, whatsapp, newsletter, packaging. utm_medium is the type of traffic — social, paid-social, email, cpc, qr. GA4 uses the medium (together with the source) to assign the default channel group, so a wrong medium such as "instagram" or "whatsapp" lands the session in Unassigned even if the source is correct.

Are UTM parameters case-sensitive?

Yes. Google's documentation states that utm_source=google and utm_source=Google are treated as different values. GA4's channel-group rules themselves are not case-sensitive, so both would still sort into the same channel, but they split into two rows as soon as you view the report by source / medium. Writing every value in lowercase removes the problem entirely.

Should I add UTM parameters to Google Ads URLs?

Not when auto-tagging is on, which is Google's recommended setup. Auto-tagging adds a gclid to each click and gives GA4 the full campaign, keyword and cost data. If manual UTMs are allowed to override it, Google's help pages state that impressions, clicks and cost report as 0 for those manual values. Use UTMs for platforms that do not auto-tag into GA4, such as Meta, LinkedIn, email and WhatsApp.

Where do I see UTM data in GA4?

In Reports › Acquisition › Traffic acquisition. The report defaults to Session default channel grouping; switch the primary dimension to Session source / medium to see your tagged values directly, and to Session campaign to compare campaigns. utm_content and utm_term appear as the manual ad content and manual term dimensions, which you can add as a secondary dimension.

Tracking that survives month two

Campaigns you can actually read

Every performance marketing engagement we run starts with the tracking layer — UTM convention, GA4 key events and ad-platform tags — before a rupee of ad spend goes live.

Explore performance marketing →

Get our posts in Google

Make Digital Hangover a preferred source

One tap tells Google to show more of our SEO and marketing coverage in your Top Stories.