TL;DR, Quick Answer
6 min readUTM parameters describe campaigns, not people. Use consistent source, medium, campaign, term, and content values on external links, and never use UTMs for internal navigation.
Campaign reporting falls apart the moment three people spell the same source three different ways. A UTM parameters campaign tracking guide is really a naming agreement: five tags that describe the link rather than the person clicking it.
UTM parameters are simple URL tags that tell your analytics tool where a visit came from. They are one of the most privacy-friendly campaign measurement methods because they describe the link, not the individual person.
A tagged URL looks like this:
https://example.com/privacy-analytics?utm_source=newsletter&utm_medium=email&utm_campaign=april_launchWhen someone clicks it, your analytics tool can group the visit under that campaign.
The Five Standard UTM Parameters
| Parameter | Purpose | Example |
|---|---|---|
| utm_source | Who sent the traffic | newsletter, linkedin, partner_name |
| utm_medium | Channel type | email, paid_social, referral, cpc |
| utm_campaign | Campaign name | april_launch, gdpr_webinar |
| utm_term | Paid search keyword or targeting term | privacy_analytics |
| utm_content | Creative, placement, or link variant | hero_cta, footer_link, image_ad |
Use source, medium, and campaign for almost every campaign link. Use term and content only when they add real reporting value.
![]()
Naming Rules
Create a shared naming convention:
- Lowercase everything.
- Use underscores or hyphens consistently.
- Avoid spaces.
- Avoid personal data.
- Use stable channel names.
- Keep campaign names readable.
- Document allowed values.
Bad:
utm_source=LinkedIn&utm_medium=Social&utm_campaign=Bob's Test Campaign Final v3Better:
utm_source=linkedin&utm_medium=paid_social&utm_campaign=privacy_webinar_2026Analytics tools often treat capitalization differences as different values. linkedin and LinkedIn can split reports.
Do Not Use UTMs on Internal Links
UTMs are for external acquisition. If you add UTMs to internal links, you overwrite the original source and corrupt attribution.
For internal placement tracking, use event properties or custom dimensions such as cta_location = header, footer, pricing_card. Keep campaign tags for links coming from outside your site.
Privacy Considerations
UTMs should not identify a person. Do not put email addresses, customer IDs, names, phone numbers, or unique recipient IDs in UTM values.
Avoid:
utm_campaign=renewal_for_jane_smith
utm_content=user_123456
utm_source=email_jane@example.comIf you need per-recipient email analytics, handle it inside your email platform with appropriate consent and privacy controls. Your public website analytics usually only needs aggregate campaign performance.
Flowsery
Start Your 14-Day Free Trial
Real-time dashboard
Goal tracking
Cookie-free tracking
UTMs and Browser Tracking Protection
Browser privacy features increasingly target link decoration used for cross-site tracking. WebKit describes link decoration as tracking via identifiers added to URLs and explains related protections in its Tracking Prevention documentation. These protections focus especially on parameters that identify a user or click across sites.
Standard UTMs generally describe campaign context rather than a unique person. That makes them more durable and more privacy-friendly than click IDs such as gclid, fbclid, or unique email recipient parameters. Still, keep UTMs generic and avoid turning them into identifiers.
- Describe campaign context, not a person
- More durable under browser tracking protection
- Identify a user or a click across sites
- Targeted by tracking prevention features
Campaign Examples
Email newsletter
utm_source=newsletter
utm_medium=email
utm_campaign=monthly_privacy_roundup
utm_content=top_ctaLinkedIn paid campaign
utm_source=linkedin
utm_medium=paid_social
utm_campaign=ga4_alternative_2026
utm_content=founder_videoPartner link
utm_source=partner_acme
utm_medium=referral
utm_campaign=agency_partner_programWebinar promotion
utm_source=brevo
utm_medium=email
utm_campaign=gdpr_analytics_webinar
utm_content=reminder_2Reporting Habits
Review UTMs weekly or monthly:
- Campaigns with high traffic but low conversion.
- Sources with fewer visits but higher intent.
- Medium values that are inconsistent.
- Campaigns missing source or medium.
- Internal links accidentally tagged.
- Paid platform clicks that do not match landing-page sessions.
Privacy-first analytics tools can report UTM performance without identifying visitors. Pair campaign data with aggregate conversions and funnels, and you have enough insight for most marketing decisions.
Governance Template
Keep a shared sheet or document with:
- Campaign name.
- Owner.
- Start and end date.
- Landing page.
- Allowed UTM values.
- Goal or conversion.
- Notes.
UTMs work because they are boring. The cleaner your naming, the more useful your campaign reports become.
Build a UTM Dictionary
Create a small dictionary your team can reuse:
| Field | Allowed examples |
|---|---|
| source | google, linkedin, newsletter, partner_name |
| medium | organic, cpc, paid_social, email, referral |
| campaign | product_launch_2026, gdpr_webinar, spring_offer |
| content | hero_cta, sidebar, text_link, video_ad |
| term | paid keyword or audience label only |
Do not let every tool auto-generate its own naming scheme without review. Ad platforms, email tools, affiliates, and social schedulers often use different defaults.
Handle Redirects Carefully
UTMs can be lost when links pass through shorteners, redirect chains, payment providers, app stores, or authentication flows. Test final landing URLs before a campaign launches. The browser address bar should still contain the parameters when the analytics script or server-side collector sees the landing page.
Clean Up Reporting
Even disciplined teams make mistakes. Set a monthly cleanup rule: merge obvious capitalization variants, flag unknown sources, and update the dictionary. Do not rewrite historical data unless your analytics tool supports safe annotations. Document the mistake and fix future links instead.
UTMs and Sensitive Campaigns
Campaign names can reveal sensitive targeting. Avoid names like depression_retreatment_high_income or union_vote_campaign. Use neutral internal codes when the landing page or audience could expose health, political, religious, union, financial, or other sensitive context. Campaign tracking should not turn a visitor's URL into a disclosure.
![]()
Final Pre-Launch Check
Before sending a campaign, click every final link from the same place a recipient will see it. Confirm the page loads, UTMs remain intact, no personal values appear in the URL, and the analytics dashboard records the source as expected. This five-minute check prevents days of unusable campaign data.
Good UTMs make privacy-first analytics stronger because campaign context survives without personal identifiers or third-party click IDs.
UTM Standard Checklist
Use this page as the team's UTM standard:
Flowsery
Start Your 14-Day Free Trial
Real-time dashboard
Goal tracking
Cookie-free tracking
- External campaign links get
utm_source,utm_medium, andutm_campaign. utm_contentis reserved for placement or creative variants.utm_termis used only when keyword or audience reporting is genuinely needed.- Internal links never use UTMs.
- Campaign values are lowercase, stable, and selected from the shared dictionary.
- URLs never include emails, customer IDs, names, phone numbers, account IDs, or sensitive audience labels.
- Redirects are tested before launch, and conversions are checked in the analytics dashboard after launch.
Good UTMs make privacy-first analytics stronger because campaign context survives without personal identifiers or third-party click IDs.
Frequently Asked Questions
What is a UTM parameter?
UTM parameters are URL tags that tell an analytics tool where a visit came from, using five fields called source, medium, campaign, term, and content. They describe the link rather than the person who clicked it, which is why they hold up better under privacy protections than identifiers tied to a person.
Which UTM parameters should I always include?
Use utm_source, utm_medium, and utm_campaign on nearly every external campaign link. Add utm_term only for paid search keywords or targeting terms, and utm_content only when you need to separate creatives or placements.
Why does capitalization matter in UTM values?
Analytics tools often treat capitalization differences as different values, so linkedin and LinkedIn can split into two separate rows in a report. Lowercase everything and use underscores or hyphens consistently to keep one channel from fragmenting into several.
Can I use UTM parameters on internal links?
No. Internal UTMs overwrite the original source and corrupt attribution for visitors already on your site. Use event properties or custom dimensions, such as cta_location = header, footer, or pricing_card, to track internal placements instead.
Do UTM parameters expose personal information?
UTM parameters should not. Keep email addresses, customer IDs, names, phone numbers, and unique recipient IDs out of UTM values, since anything placed in a URL can end up in browser history, server logs, or shared screenshots. If you need per-recipient email analytics, handle that inside your email platform with proper consent.
Do browser tracking protections block UTM parameters?
Standard UTMs generally survive because they describe campaign context rather than identify a person or a single click. WebKit's tracking prevention focuses on identifiers that follow a user across sites, such as gclid, fbclid, or unique email recipient parameters, not generic labels like utm_source=newsletter.
What happens if a UTM tag gets lost in a redirect?
A shortener, redirect chain, payment provider, app store, or authentication flow can strip the parameters before your analytics collector sees the landing page. Test the final landing URL before launch and confirm the address bar still carries the UTM values on the page your visitor actually reaches.
How often should I review UTM reporting?
Weekly or monthly, depending on campaign volume. Look for high traffic with low conversion, sources with fewer visits but higher intent, inconsistent medium values, campaigns missing source or medium, and internal links that got tagged by mistake.
Should every campaign name describe its audience in detail?
No. Avoid names such as depression_retreatment_high_income or union_vote_campaign, since a campaign name in a URL can disclose health, political, religious, union, or financial context. Use a neutral internal code when the landing page or audience is sensitive.
What belongs in a UTM governance document?
Keep a shared sheet with campaign name, owner, start and end date, landing page, allowed UTM values, goal or conversion, and notes. Pair it with a UTM dictionary of allowed source, medium, campaign, content, and term values so no tool invents its own naming scheme.
Was This Article Helpful?
Let us know what you think!
See us more often in Google
One click marks Flowsery as a preferred source, so our articles sit higher in your Top Stories, AI Mode, and AI Overviews.
Before you go...
Flowsery
Revenue-first analytics for your website
Track every visitor, source, and conversion in real time. Simple, powerful, and cookie-free.
Real-time dashboard
Goal tracking
Cookie-free tracking
Related Articles


A Practical Guide to Utm Tags
The browser referrer policies analytics impact is a swelling direct-traffic bucket. What browsers still send, and the UTM naming system that recovers it.


A Practical Guide to Web Analytics Terms
Custom dimensions attach business context to analytics events. What they are good for, what they quietly break, and the naming rules that keep schemas clean.


Explained Clearly - Export Ga3 Data
CSV, the Data API, BigQuery and Sheets compared, so you can export GA3 data and GA4 history before a migration makes the old numbers unreachable.