Tutorials

A Practical Guide to Utm Tags

Taras Shynkarenko
Taras Shynkarenko
•Updated: •7 min read
A Practical Guide to utm tagsA Practical Guide to utm tags

TL;DR, Quick Answer

7 min read

Browsers now send only the domain (not full URL) as referrer for cross-origin requests, and strip referrers entirely for HTTPS-to-HTTP. Compensate by tagging every link you control with UTM parameters.

Direct traffic keeps growing and nobody changed a campaign, which is the browser referrer policies analytics impact in one line: modern browsers now pass the domain rather than the full URL.

Referrer data used to feel simple: someone clicked a link, the destination site received the previous page URL, and analytics reported where the visit came from. Modern browsers are more careful. That is good for privacy, but it changes attribution.

If your analytics reports show more "direct" traffic than expected, fewer full referral URLs, or missing campaign detail, referrer policy may be one reason.

What the Referrer Header Does

The HTTP Referer header, misspelling included, tells a destination page where the request came from. Analytics tools use it to classify traffic as search, referral, social, or direct.

Without any extra campaign tagging, a visit from:

https://partner.example/reviews/best-analytics-tools

might historically arrive with the full referring URL. That allowed the analytics tool to show not just partner.example, but the exact article.

Today, browsers commonly send less. MDN documents strict-origin-when-cross-origin as the default referrer policy in modern browsers, and Chrome announced the same default beginning with Chrome 85. Under that policy:

  • same-origin requests can send the full URL
  • cross-origin HTTPS-to-HTTPS requests send only the origin, such as https://partner.example
  • HTTPS-to-HTTP requests send no referrer

That means your analytics tool may know the domain, but not the exact page.

Referrer Detail Lost by Request Type
1
Same-origin request. The full URL reaches the destination page.
2
Cross-origin HTTPS to HTTPS. Only the origin, such as https://partner.example, gets sent.
3
HTTPS to HTTP. No referrer gets sent at all.
Under strict-origin-when-cross-origin, the same click carries less detail as it crosses origins and protocols.

A person shields a laptop screen with one hand, evoking the privacy concerns behind reduced browser referrer data.

Why Browsers Reduced Referrer Detail

Full referrer URLs can leak sensitive information. A URL can contain search terms, account IDs, reset tokens, document names, email addresses, or private paths. If that full URL is sent to every third-party resource on a page, privacy risk grows quickly.

Reduced referrer defaults are a browser-level attempt to limit passive data leakage. This is separate from cookies, pixels, and link tracking parameters. Even a site with no cookies can be affected by referrer policy.

How It Affects Analytics Reports

The biggest impact is loss of detail, not total loss of attribution.

You may still see that traffic came from github.com, news.ycombinator.com, linkedin.com, or a partner domain. You may not see which specific thread, profile, repository, or article sent it.

You may also see more direct traffic when:

  • the source app does not send referrers
  • the click happens inside a native app or email client
  • the source uses rel="noreferrer"
  • traffic moves from HTTPS to HTTP
  • privacy tools strip referrers
  • redirects remove attribution before the visitor lands

This is why "direct" traffic is not the same as "people typed the URL." It often means "the analytics tool did not receive a reliable source."

Flowsery
Flowsery

Start Your 14-Day Free Trial

Real-time dashboard

Goal tracking

Cookie-free tracking

Why UTM Tags Still Matter

UTM parameters are campaign labels you add to links you control. Google Analytics documents manual tagging with UTM parameters as a way to collect traffic-source dimensions, and the same concept works in privacy-first analytics tools.

A clean campaign URL looks like this:

https://flowsery.com/?utm_source=newsletter&utm_medium=email&utm_campaign=product_launch

Use UTMs for links in:

  • email newsletters
  • paid ads
  • social posts
  • partner campaigns
  • QR codes
  • creator sponsorships
  • webinars
  • downloadable PDFs

Do not use UTMs on internal links. Internal UTMs overwrite the original acquisition source and make reports worse.

A Practical UTM Naming System

Keep names lowercase, predictable, and boring:

ParameterUseExample
utm_sourcewhere the click came fromlinkedin, newsletter, partnername
utm_mediumchannel typesocial, email, cpc, referral
utm_campaigncampaign nameprivacy_audit_2026
utm_contentcreative or placementfooter_cta, carousel_2
utm_termpaid keyword, when neededcookieless_analytics

Document allowed values. If one person uses LinkedIn, another uses linkedin.com, and a third uses li, your reports fragment.

Privacy Caveats

UTM tags should describe campaigns, not people. Never put personal data in URL parameters. Avoid:

  • email addresses
  • names
  • phone numbers
  • customer IDs
  • account IDs
  • invoice IDs
  • free-form search terms from private contexts

URLs are copied, logged, shared, indexed, and sent through referrer headers in some contexts. Treat every campaign parameter as potentially visible.

What Belongs in a UTM Parameter
Safe to include
  • A channel name like newsletter or linkedin
  • A campaign label like privacy_audit_2026
  • A placement detail like footer_cta
Never include
  • Email addresses or names
  • Phone numbers
  • Customer, account, or invoice IDs
  • Free-form search terms from private contexts
URLs get copied, logged, and shared, so treat every parameter as visible to someone else.

What to Configure on Your Site

Set an explicit referrer policy. For most websites, strict-origin-when-cross-origin is a sensible default because it preserves same-origin functionality while reducing cross-site leakage:

Referrer-Policy: strict-origin-when-cross-origin

If you handle especially sensitive paths, consider stricter policies such as same-origin or no-referrer for those areas. For example, account, billing, health, legal, or admin pages should not leak full URLs to third parties.

Also check redirects. If a campaign link passes through a shortener, affiliate system, consent manager, or redirect service, confirm that UTMs survive until the final landing page.

The Right Mental Model

Referrers are opportunistic. UTMs are intentional.

Use referrer data to understand organic mentions and uncontrolled traffic. Use UTMs to measure campaigns you control. Use both, but do not expect browser referrers to provide full-fidelity attribution in a privacy-conscious web.

That tradeoff is healthy. You can still measure marketing performance without demanding that browsers leak every page a visitor came from.

A person taps a link on a smartphone, the kind of click-path test described in the campaign QA routine.

Flowsery
Flowsery

Start Your 14-Day Free Trial

Real-time dashboard

Goal tracking

Cookie-free tracking

Before a campaign launches, test the full click path. Click from the email, ad preview, social scheduler, partner page, QR code, and short link. Confirm the final landing page keeps the expected UTM parameters, uses HTTPS, avoids duplicate redirects, and does not add personal data to the URL.

Then check what your analytics tool records. The source, medium, campaign, landing page, and conversion should match the naming plan. If a link passes through a payment page, consent manager, or app store, document where attribution may be lost. This small QA routine catches campaign mistakes while there is still time to fix them, and it reduces the temptation to rely on invasive referrer recovery techniques later.

Referrer QA Checklist

Before a campaign launches, test the full click path from each placement and confirm that HTTPS, redirects, referrer policy, and UTM handling behave as expected. Then compare what analytics records with the naming plan. If attribution disappears at a shortener, consent step, payment page, or app-store handoff, document that gap instead of trying to rebuild the visitor's path with more invasive tracking.

Frequently Asked Questions

Why does my analytics dashboard show more direct traffic than before?

Modern browsers default to the strict-origin-when-cross-origin referrer policy, which sends only the domain instead of the full page URL on cross-origin requests. Chrome adopted this default starting with Chrome 85, and other browsers follow the same MDN-documented default. When the referrer is stripped or reduced, many analytics tools label the visit as direct.

What does the strict-origin-when-cross-origin referrer policy actually send?

Same-origin requests still send the full URL. Cross-origin HTTPS-to-HTTPS requests send only the origin, such as https://partner.example. Requests from HTTPS to HTTP send no referrer at all.

Only if you confirm the parameters survive the hop. The QA routine in this guide calls for checking that UTMs stay intact through shorteners, affiliate systems, consent managers, and other redirect services before a campaign launches. If a redirect strips the query string, the landing page analytics loses the campaign source even though the click itself was tracked correctly.

Keep UTMs off internal links entirely. Tagging a link from one page of your site to another overwrites the visitor's original acquisition source, so a visitor who arrived from a newsletter link would look like they came from wherever the internal link pointed. Save UTM tagging for links you control that live outside your site: newsletters, ads, social posts, partner campaigns, and similar channels.

Does rel="noreferrer" affect my traffic reports?

Yes, links marked rel="noreferrer" send no referrer header at all, so any visit through one shows up as direct traffic regardless of the referrer policy in place. This is one of the reasons direct traffic grows even when a visitor genuinely clicked a tracked link. UTM parameters are unaffected by rel="noreferrer" since they travel in the URL itself, not the referrer header.

Why do social and app traffic often show up as direct?

Native apps and email clients frequently send no referrer at all, and the same goes for many in-app browsers. Combined with privacy tools that strip referrers, that traffic lands in analytics as direct even though it followed a link. Tagging those links with UTM parameters recovers the source without relying on the browser to pass any referrer.

What is the difference between utm_medium and utm_source?

utm_source names where the click came from, such as linkedin, newsletter, or a partner's name. utm_medium names the channel type carrying it, such as social, email, cpc, or referral. Keeping the two separate and documenting allowed values stops the same channel from fragmenting into labels like LinkedIn, linkedin.com, and li.

Is it safe to put a customer ID or email address in a UTM parameter?

UTM tags should describe the campaign, not the person clicking it. This guide lists emails, names, phone numbers, and customer, account, or invoice IDs as data that should never appear in a URL parameter, because URLs get copied, logged, shared, and indexed. Free-form search terms taken from private contexts carry the same risk.

Check whether the domain still shows up in your reports at all. If you see the partner or platform domain but lose the specific page or post, that is referrer policy reducing detail, not a tracking failure. If the source, medium, or campaign fields are empty or wrong for a link you tagged yourself, the UTM parameters likely got stripped somewhere in the click path, such as at a redirect or consent manager.

Click through the full path from every placement, including the email, ad preview, social scheduler, partner page, QR code, and short link. Confirm the landing page keeps the expected UTM parameters, loads over HTTPS, and does not pick up duplicate redirects. Then check that your analytics tool records the source, medium, campaign, and landing page you planned for.

Was This Article Helpful?

Let us know what you think!

See us more often in Google

One click marks Flowsery as a preferred source, so our articles sit higher in your Top Stories, AI Mode, and AI Overviews.

Before you go...

Flowsery

Flowsery

Revenue-first analytics for your website

Track every visitor, source, and conversion in real time. Simple, powerful, and cookie-free.

Real-time dashboard

Goal tracking

Cookie-free tracking

Related Articles