UTM parameters are five tags appended to a URL — utm_source, utm_medium, utm_campaign, utm_content and utm_term — that Google Analytics 4 and other analytics tools read to record where a visit came from. The server ignores them and returns the same page, so they never affect rankings; the damage comes from bad values, lost redirects and indexed duplicates.
What does UTM stand for?
UTM stands for Urchin Tracking Module. Urchin was a web analytics product Google acquired in the mid-2000s and turned into Google Analytics; the parameter names outlived the product and became a de facto industry standard, although no RFC defines UTM. Every major analytics platform, CRM and email tool understands the same five names.
A UTM parameter is a key=value pair appended to a URL after a question mark. Multiple pairs are joined with an ampersand. Here is a tagged link, broken down:
https://example.com/pricing?utm_source=linkedin&utm_medium=social&utm_campaign=autumn-sale
https://example.com/pricing — the page address, unchanged
? — start of the query string
utm_source=linkedin — first pair
& — pair separator
utm_medium=social — second pair
&utm_campaign=autumn-sale — third pair
The key thing to internalize: a tag is not an instruction to the server. The web server returns exactly the same page it would for a clean /pricing. No processing, no redirect, no content change — unless you wrote code that reads those parameters yourself.
What happens on the analytics side
The work is done by the tracking script on the page — the Google tag (gtag.js or Google Tag Manager), Yandex.Metrica, a CRM form script or anything else. The sequence:
- The browser loads the page at the parameterized address.
- The tracking script reads the current URL from the browser (
location.search) and extracts everything starting withutm_. - Those values are sent to the analytics backend with the first hit and stored as session attributes.
- Every later action — pageviews, key events, purchases — is attributed to that source under the platform's attribution rules.
Two practical consequences follow. First: if the tracking script never loads or throws, nothing is recorded at all. Second: if the parameters disappear from the URL before the script runs — on an intermediate redirect, say — there is nothing left to record, and the visit lands in "direct" or in a referral bucket.
A tag lives exactly until the first hit. If there is a redirect between the ad click and the page load that strips the query string, you have not lost "some data" — you have lost the entire source. Check the redirect chain before the campaign launches, not after.

What are the 5 UTM parameters?
The standard set is five parameters. Formally none of them is required: analytics will happily accept a link carrying only utm_source. The practical minimum is source + medium + campaign, because without medium the report collapses into an unreadable list of platform names — and in GA4 the visit cannot be placed in a sensible channel.
| Parameter | Practical minimum | What goes in it | Example value | Common mistake |
|---|---|---|---|---|
utm_source | yes | The specific platform or sender — "where exactly did they come from" | google, facebook, linkedin, newsletter, partner-blog | Putting a channel type (cpc) in place of a platform name |
utm_medium | yes | The channel type — "how did they get here". Drawn from a short closed vocabulary | cpc, email, social, display, referral | Free improvisation: ppc, paid, cpc-ads in one account |
utm_campaign | yes | Campaign or promotion name — the field you will group the report by | autumn-sale, black-friday-2026 | Free-form dates that break sorting |
utm_content | no | Distinguishes variants inside one campaign: creative, banner size, link position in an email | banner-300x250, footer-link, variant-b | Duplicating campaign instead of separating variants |
utm_term | no | The keyword. Historically for paid search | utm-tags, buy-hosting | Pasting an unencoded phrase with spaces |
utm_source vs utm_medium — the main confusion
This distinction ruins more reports than every other mistake combined. The rule is simple:
- source answers "where?" — a proper noun.
google,bing,facebook,linkedin,newsletter-weekly. - medium answers "how?" — the traffic type, a category.
cpc(paid click),organic,email,social,referral,display,qr.
A sanity check: a healthy account has 5–10 distinct medium values for the entire business, and as many source values as it likes. If your medium report has thirty rows, something that belonged in source or campaign leaked into it.
The same platform easily produces different mediums: an organic post on LinkedIn is utm_source=linkedin&utm_medium=social, a sponsored post on the same network is utm_source=linkedin&utm_medium=paid_social. And one medium collects many sources: utm_medium=email arrives from newsletter, from trigger-abandoned-cart and from partner-digest alike.
The extra GA4 parameters: utm_id and friends
Beyond the classic five, Google Analytics 4 recognizes a few more. utm_id carries a campaign ID and is what you join on when importing cost data from non-Google ad platforms. utm_source_platform names the buying platform (for example a DSP), while utm_creative_format and utm_marketing_tactic describe the creative type and targeting approach. Support for these in standard reports has changed over time, so check Google's own URL builders help page rather than blog posts; the base five are supported everywhere.
UTM parameters list: templates and examples by channel
Most teams do not need creativity here — they need the same template every time. The table below is a starting vocabulary that also lands each visit in the right GA4 default channel. Adapt the source names to your stack, but keep the medium column fixed.
| Channel | utm_source | utm_medium | utm_campaign | utm_content (optional) |
|---|---|---|---|---|
| Google Ads (manual tags alongside auto-tagging) | google | cpc | {campaignid} or a slug | {creative} |
| Microsoft Advertising | bing | cpc | campaign slug or ID | ad ID |
| Meta ads (Facebook, Instagram) | facebook / instagram | paid_social | {{campaign.name}} | {{ad.name}} |
| LinkedIn sponsored content | linkedin | paid_social | campaign slug | creative variant |
| Organic social post | linkedin, x, facebook | social | content series or launch | post date or format |
| Email newsletter | newsletter | email | 2026-10-weekly | header-cta, footer-link |
| Partner or guest post | partner domain slug | referral | partnership name | link position |
| Affiliate | affiliate ID or name | affiliate | program name | — |
| QR code on print | flyer, booth | qr | event slug | placement |
| SMS | provider or list name | sms | campaign slug | — |
A finished example, ready to paste:
https://example.com/webinar?utm_source=newsletter&utm_medium=email&utm_campaign=2026-10-weekly&utm_content=header-cta
How GA4 turns utm_medium into a channel
GA4 does not report your raw medium as a channel. It runs source and medium through an ordered list of rules called the default channel group. Anything that matches no rule becomes Unassigned — the most common reason a well-tagged campaign "disappears" from the channel report while still showing up under source/medium. Simplified:
| utm_medium you send | Typical GA4 channel | Note |
|---|---|---|
cpc, ppc, paid_social, retargeting | Paid Search / Paid Social / Paid Other | Depends on whether the source is on Google's list of search engines or social networks |
email, e-mail | mail or newsletter as a medium ends up Unassigned | |
social, social-media, sm | Organic Social | A known social source also qualifies on its own |
display, banner, cpm | Display | Unless an earlier paid rule catches it first |
referral, link, app | Referral | — |
affiliate | Affiliates | — |
sms | SMS | — |
organic | Organic Search | Rarely needed: search engines already send organic traffic without tags |
qr, print, anything invented | Unassigned | Fine if intentional; otherwise build a custom channel group |
The rules are evaluated top to bottom and Google revises them occasionally, so treat the help page as the source of truth. If you need qr or podcast as a first-class channel, create a custom channel group in GA4 admin instead of bending your medium values to fit the default one.
How to add UTM parameters to a URL by hand
Building one manually takes about twenty seconds and requires a few mechanical rules:
- The first parameter is separated by
?, every following one by&. - If the URL already has parameters (
/catalog?page=2), tags are appended with&, never with a second?. - Lowercase Latin letters, digits, hyphen and underscore only. No spaces, no accented or non-Latin characters, no punctuation inside values.
- Anything outside that set must be percent-encoded: a space becomes
%20or+, an accented or non-Latin character becomes a%XXbyte sequence. - Tags go before the fragment. Correct:
/page?utm_source=linkedin#faq. Wrong:/page#faq?utm_source=linkedin— in the second case the browser never sends anything after the hash to the server and it never lands in the query string.
# Bad: spaces, mixed case, a second question mark
https://example.com/catalog?page=2?utm_source=Google&utm_medium=CPC&utm_campaign=autumn 2026
# Good: one ?, then &, all lowercase
https://example.com/catalog?page=2&utm_source=google&utm_medium=cpc&utm_campaign=autumn-2026
# If a value genuinely needs non-ASCII characters, encode it
https://example.com/?utm_source=google&utm_medium=cpc&utm_term=caf%C3%A9-menu
You can verify how the string parses on the client side straight from a terminal:
# Split a query string into parameters (python3 is available almost everywhere)
python3 - <<'EOF'
from urllib.parse import urlsplit, parse_qsl
u = "https://example.com/catalog?page=2&utm_source=google&utm_medium=cpc"
for k, v in parse_qsl(urlsplit(u).query):
print(f"{k:15} = {v}")
EOF
# Encode a value correctly before pasting it into a link
python3 -c "from urllib.parse import quote; print(quote('autumn sale'))"
In a browser, the same check is one line in the DevTools console (Chrome, Edge, Firefox or Safari) on the landing page itself: Object.fromEntries(new URLSearchParams(location.search)). If the object is empty after you clicked a tagged link, the tags were lost before the page loaded.
UTM parameters generator: what a UTM builder does — and what it does not
A builder is a form with five fields that concatenates a string. Google publishes its own free Campaign URL Builder, and most email platforms, social schedulers and CRMs have one built in. Three things about builders are genuinely useful: they will not let you forget an &, they encode special characters correctly, and the better ones offer a dropdown of allowed medium values, which keeps a team disciplined. Saved templates and history help too, so that different people do not invent email, e-mail and mail in parallel.
A shared spreadsheet works as a UTM template for small teams: one tab with the allowed source and medium values as data-validation lists, one tab where each row is a link, and a formula that joins the base URL and the values. What matters is that nobody types a medium freehand.
What a builder does not do:
- it does not verify that a tracking script exists on the destination page;
- it does not verify that the parameters survive the redirect chain to that page;
- it does not remove parameterized duplicates from the search index;
- it does not know your internal vocabulary and will not stop a fourth spelling of the same campaign.
In other words, a builder solves syntax. Every interesting problem — vocabulary semantics and the technical behavior of your site — remains yours.

UTM parameters in Google Analytics 4: where the report lives
GA4 reads UTM parameters automatically; there is nothing to enable. The values arrive with the first hit of the session and become available as traffic-acquisition dimensions.
There are two ways to use them. The first is the ready-made traffic acquisition report, which groups sessions by dimensions such as Session source / medium and Session campaign; the user acquisition report shows the First user equivalents — the source that brought each user the first time. The second, far more useful one, is adding a UTM-based dimension such as Session manual ad content or Session manual term to an exploration — so you can look at conversion rate broken down by utm_content, or isolate a single campaign. Exact menu labels change periodically, so navigate by the acquisition report group and the dimension list rather than by a memorized click path.
To confirm a new link works before spending money, open it in a fresh private window and watch the Realtime report: within a minute or so the visit should appear with your source and campaign. That checks the whole path — link, redirects, tag firing — in one go.
Technical details that most often distort the picture:
- Session vs user scope. Campaign parameters are recorded per session. A tag encountered on the landing page defines that session. A tag encountered mid-session is a new traffic source touchpoint, with all the consequences described below.
- The script must actually run. If the tracking snippet is loaded late on a heavy page, or blocked until a consent banner is answered, some users leave before it fires and their tag is never recorded.
- Auto-tagging is a separate mechanism. Ad platforms append their own click identifiers —
gclidfor Google Ads,msclkidfor Microsoft Advertising,fbclidfor Meta,yclidfor Yandex Direct. These are not UTM tags; for Google Ads, thegclidis a direct link between the ad account and the analytics account. Both can live in the same URL simultaneously. If your traffic includes Russian-language markets, the counter on the other side of that pairing is covered in our guide to Yandex.Metrica and Webvisor.
Google Ads: auto-tagging (gclid) vs UTM parameters
Ad platforms give you two independent ways to pass data into analytics, and they get confused constantly.
Auto-tagging means the platform appends its own click ID and analytics pulls campaign, ad group, keyword and cost details straight from the linked ad account. In Google Ads it is on by default in most accounts and carries far more detail than manual tags — but the data is only resolvable inside Google's ecosystem, and only if the Google Ads and GA4 properties are linked.
Manual UTM tagging is what you need when the data has to travel somewhere else: a third-party analytics stack, a CRM, a cross-channel report, a spreadsheet that sits next to every other channel.
| Auto-tagging (gclid) | Manual UTM | |
|---|---|---|
| Who writes it | Google Ads, on every click | You, in the Final URL suffix or tracking template |
| What reaches GA4 | Campaign, ad group, keyword, query, cost — via account linking | Exactly the five strings you typed |
| Readable by a CRM or other tools | No, it is an opaque ID | Yes, plain text |
| Needs account linking | Yes | No |
| Breaks when | The site or a redirect strips unknown parameters | Same, plus typos and inconsistent vocabulary |
Keep auto-tagging on and add UTMs only if something outside GA4 needs the data. When a click carries both and the accounts are linked, GA4 uses the gclid data for Google Ads traffic; the manual values do not override it. Google's ValueTrack documentation lists the placeholders the platform fills in at click time.
Where to put UTM parameters in Google Ads
Do not edit every final URL. Use the Final URL suffix field in the campaign URL options (it exists at account, campaign, ad group and ad level; the most specific one wins). The suffix is written without a leading question mark — Google adds ? or & as needed:
# Google Ads — Final URL suffix (no leading "?")
utm_source=google&utm_medium=cpc&utm_campaign={campaignid}&utm_content={creative}&utm_term={keyword}
# Yandex Direct tracking template
?utm_source=yandex
&utm_medium=cpc
&utm_campaign={campaign_id}
&utm_content={ad_id}
&utm_term={keyword}
A few rules that save time:
- Keep
utm_medium=cpcconstant across paid search, and setutm_sourceto the search engine, not the ad product. The temptation to writeutm_source=adwordsis real, but then paid and organic traffic from the same engine split by product name instead of by traffic type, which makes them awkward to compare. - Put the campaign identifier in
utm_campaignrather than its name: you will rename the campaign eventually, and historical data will split into two rows. - A substituted keyword can contain spaces. Check what the final URL looks like after a click on a real ad, not just the template in the interface.
- The available macro set changes over time — check the ad platform's current help before bulk-reuploading campaigns.
Microsoft Advertising works the same way: it auto-tags with msclkid and also accepts a final URL suffix with its own substitution parameters, so the same utm_source=bing&utm_medium=cpc pattern applies.

UTM parameters in Meta ads (Facebook and Instagram)
Meta appends fbclid to outbound clicks on its own, but that ID means nothing to GA4, which is why Meta traffic without UTMs usually lands in Organic Social under sources like l.facebook.com or l.instagram.com, with no campaign breakdown and paid spend mixed in with unpaid posts. The fix is the URL parameters field at the ad level in Ads Manager (under the destination/tracking section), not the website URL field itself. Meta's dynamic parameters fill in the names at delivery time:
# Meta Ads Manager — URL parameters field
utm_source=facebook&utm_medium=paid_social&utm_campaign={{campaign.name}}&utm_content={{ad.name}}&utm_term={{adset.name}}
Other documented placeholders include {{campaign.id}}, {{adset.id}}, {{ad.id}}, {{placement}} and {{site_source_name}}. Two practical points: prefer IDs if your team renames ads often, and if you want Instagram placements to report separately, derive the source from the placement parameter rather than hardcoding facebook. Use paid_social (or cpc) as the medium: GA4 only files the visit under Paid Social when the medium looks paid; utm_medium=social would put your ad spend into Organic Social.
LinkedIn, email and social scheduling tools
LinkedIn Campaign Manager lets you add UTM parameters to each ad's destination URL, and it has a URL tracking option that can append parameters for every ad in a campaign automatically, including dynamic campaign and creative values. The exact macro names have changed over the years, so pick them from the interface rather than copying a list from an old post. The same vocabulary applies: utm_source=linkedin&utm_medium=paid_social for sponsored content, utm_medium=social for organic company-page posts.
Email platforms such as Mailchimp, HubSpot and Klaviyo can tag every link in a campaign automatically. Check what they write before trusting it: some default to their own name as the source and a medium that does not match your vocabulary. Set the defaults once so every send reports as utm_medium=email.
Social schedulers (Hootsuite, Buffer and similar) also append UTMs on publish. The failure mode is double tagging: the scheduler adds its own set to a link that already carries yours. Parsers then usually take the first value, and which one wins depends on the order. Decide which layer owns tagging and turn the other off.
UTM parameters in Salesforce and HubSpot
Analytics sees the tag on the landing page, but a CRM sees only the form submission, often several pages later. To get utm_source onto a lead record you have to carry it there yourself:
- Read the parameters on landing and store them for the session (a first-party cookie or
sessionStorage), because they vanish from the URL on the next click. - Add hidden fields to your forms and fill them from that storage on submit.
- In Salesforce, create custom fields on the Lead object for each parameter and map the form fields to them (Web-to-Lead, Account Engagement or your form tool's connector). In HubSpot, the tracking code captures the original source automatically, and custom contact properties hold the raw UTM values.
- Decide on first-touch or last-touch explicitly: overwrite the fields on every visit, or only when they are empty.
Never put personal data in a tag — an email address in utm_content, a customer ID from your CRM export. Google Analytics terms prohibit sending personally identifiable information, and a tagged URL gets copied, forwarded and logged by every proxy on the way.
UTM tags in Webflow, WordPress and other site builders
From a site builder's point of view a UTM tag is just extra baggage in the URL that it must ignore while serving the right page. Essentially every popular builder — Webflow, Wix, Squarespace, Shopify, WordPress, Tilda — does exactly that: the query string does not affect routing. So "does this builder support UTM tags" almost always answers itself — there is nothing to support.
Real problems start not with recognizing tags but in three other places where the builder makes decisions on your behalf:
1. Redirects and the canonical host
A builder usually merges www and the bare domain itself, and forces HTTPS. Those are redirects, and the only question that matters is whether the parameters reach the final address. The good news: on serious platforms they do. The bad news: if your own redirect sits on top — from an old domain to a new one, for instance — it may well eat the parameters. Test the actual production link, not the platform in the abstract.
2. Internal links inside prebuilt blocks
Blocks like "promo" or "banner" are configured through the same field as external links, and it is very tempting to put UTM tags in them. That is a mistake, and the most expensive one on this list: a tag on an internal link overrides the original source. Someone arrives from paid search, clicks a banner carrying utm_source=site&utm_medium=banner, and the purchase is credited to that internal banner. The ad channel zeroes out in the report.
3. Canonical tags and the sitemap
Builders normally emit rel="canonical" for you. Make sure the canonical address is served without parameters — that is precisely what protects you from duplicates. And check that parameterized URLs never reach sitemap.xml: see our walkthrough of the XML sitemap.
Never put UTM tags on internal links of your own site. Analytics platforms have dedicated mechanisms for internal navigation — events, key events, click tracking. UTM exists for inbound traffic only.
Do UTM parameters affect SEO?
Tags do not influence ranking by themselves. A crawler arriving at a tagged URL receives exactly the same HTML as at the clean one: content, headings and speed are unchanged. There is no direct ranking bonus or penalty here.
The problem is elsewhere. To a crawler, every unique parameter combination is a separate URL. Three campaigns pointing at one landing page produce four addresses with identical content. Once those addresses become known to a search engine — through someone else's blog, a social post, your sitemap, your own internal links — measurable damage begins:
- Duplicates in the index. The same text under several addresses. The engine picks a primary one itself, and its choice need not match yours.
- Diluted signals. External links and behavioral data spread across clones instead of accumulating on one URL.
- Wasted crawl budget. The crawler spends fetches re-reading identical pages. Barely noticeable on a small site; very noticeable on a large catalog. We cover crawl mechanics in how website indexing works.
- Junk in the SERP. A user sees a URL carrying someone else's campaign tag and, after clicking, lands in someone else's statistics.
Three defenses, and which engine honors which
| Mechanism | Yandex | What it does | |
|---|---|---|---|
rel="canonical" without parameters | honored | honored | Declares the preferred address. The baseline, mandatory measure for both engines |
Clean-param in robots.txt | no, not supported | yes, a Yandex directive | Tells the crawler to ignore the listed parameters and merge the addresses |
Disallow: /*utm* | not recommended | not recommended | Blocks crawling. The crawler never sees the canonical and cannot merge anything — the cure is worse than the disease |
Always start with canonical. It is the only mechanism both engines understand, and it fixes the problem at the root: the clean, parameter-free address is declared canonical. Google describes the approach in its guide to consolidating duplicate URLs.
<!-- In the <head> of a page opened at /pricing?utm_source=linkedin -->
<link rel="canonical" href="https://example.com/pricing">
<!-- Check a production page with one command -->
curl -sSL 'https://example.com/pricing?utm_source=linkedin&utm_medium=social' | grep -io '<link[^>]*canonical[^>]*>'
The second layer matters only if you also care about Yandex, the main search engine in Russia: Clean-param. This is a robots.txt directive that only Yandex understands. Google has no equivalent, and the URL Parameters tool in Search Console was retired — Google's guidance is to rely on canonical instead. The two approaches must not be blended into a single recommendation; they belong to different search engines.
# robots.txt — Yandex section
User-agent: Yandex
Clean-param: utm_source&utm_medium&utm_campaign&utm_content&utm_term&yclid&gclid&fbclid /
# Syntax: Clean-param: parameters_joined_by_ampersand [path_prefix]
# The trailing path is optional; without it the rule applies site-wide.
# The directive has a length limit — long lists are split
# across several consecutive Clean-param lines.
A live example sits on this very domain: the robots.txt of enterno.io carries a Clean-param line covering the full set of advertising parameters, including utm_*, gclid, yclid and fbclid. The rest of the file's directives are covered in our robots.txt guide.
Do not block parameterized URLs with
Disallow. Blocking a crawl does not remove a page from the index — it merely stops the crawler from reading it. The crawler will never see yourcanonical, will never learn it is a duplicate, and may well keep the URL in results without a description. The correct pair is open crawling plus a correct canonical, with Clean-param added for Yandex.
What are common UTM mistakes?
Case: Google and google are two different strings
Tag values are transmitted verbatim, character for character, and GA4 treats them as case-sensitive: Google and google become two rows with half the traffic each, and period-over-period comparison falls apart. Some other tools lowercase values when building reports, but you cannot know in advance which report you will open six months from now.
The rule needs no exceptions: lowercase everything, always. That applies to values and to parameter names alike — many platforms will not recognize UTM_Source as a tag at all.
Tags on internal links reset the original source
Covered above for site builders, but the mistake appears in hand-built sites too: a tag on a banner inside the account area, a tag on the "proceed to checkout" button, a tag on a link in the site-wide header. Every one of those is a mid-session source override. Universal Analytics used to start a new session outright; GA4 keeps the session but records the internal tag as the newest traffic source, so key events that follow — and later returning visits that would otherwise inherit the ad source — are credited to your own button.
The symptom that catches it: the acquisition report shows an implausible number of sessions from your own domain or from a medium like banner/site, while paid channels convert noticeably worse than the ad platforms report.
Tags in canonical, sitemap and hreflang
Three places a parameterized URL must never appear. A canonical carrying a tag declares the tagged address canonical — you are personally asking the engine to index an advertising clone. The same goes for the sitemap: it means "these are the addresses I consider correct". If your sitemap generator builds URLs from logs or from internal links, tags leak in easily.
Losing tags on a redirect
The most technical and most frustrating failure: the link is tagged correctly and nothing arrives in analytics. The cause is a redirect along the way that returns a Location without the query string. The classic is a web server config that substitutes only the path:
# nginx — tags are lost: $uri does not include the query string
location /old { return 301 https://example.com$uri; }
# nginx — tags survive: $request_uri includes path AND parameters
location /old { return 301 https://example.com$request_uri; }
# Apache mod_rewrite — if the substitution contains its own '?',
# the original query string is discarded. The QSA flag brings it back:
RewriteRule ^old/(.*)$ /new/$1?lang=en [R=301,L,QSA]
The danger is that everything looks fine: the user lands on the right page and no error appears. The difference is visible only in the address bar and in the report. A related variant is link shorteners and tracking domains that add an extra hop — every hop is another chance to drop parameters. Full chain analysis is in how to check redirects; the choice between redirect codes is covered in 301 vs 302 redirects.
Are UTM tags lost when redirecting from HTTP to HTTPS? It depends on how the redirect is configured. A correct config substitutes the full request including the query string and the parameters arrive intact. An incorrect one substitutes the path only, and tags vanish silently, without an error. One command settles it: curl -sSIL … -w '%{url_effective}' — every parameter must still be present in the final URL. The rest of that switch is in our HTTP to HTTPS migration guide.
An inconsistent vocabulary
After a year without a shared vocabulary, the report contains cpc, ppc, paid, cpc_ads and context — all meaning the same thing. The only cure is organizational: one document listing allowed medium values, one builder with a dropdown, a link review before every campaign launch.
Why did one source split into two rows in my report?
Three usual causes, in descending order of frequency: differing case (Google vs google), differing spelling in the vocabulary (email vs e-mail), and a stray space or character that got into the value while copying the link. All three are fixable only at the input stage — analytics does not rewrite already recorded data retroactively.
Tagging organic search or blocking tags in robots.txt
Two opposite over-corrections. Adding utm_medium=organic to links you control is pointless — search engines already identify themselves as the referrer. And blocking parameterized URLs in robots.txt with Disallow is actively harmful, as shown above: the crawler can no longer read the page and see the canonical. For Yandex the right tool is Clean-param; for Google nothing is needed in robots.txt at all.
Tags and caching
One more non-obvious side effect. CDN caches and server-side page caches are usually keyed on the full URL including the query string. That means every unique tag combination is a separate cache entry and a miss on first request. A mass mailing with a per-recipient tag can both bloat the cache and spike backend load.
The fix is cache key normalization: exclude utm_* from the key so the page is served from the shared cache. This does not affect tracking — the script reads the URL from the browser, not from the server response, so the tag is still recorded. Caching headers on a production page are easy to inspect with the HTTP header checker.

How to check your UTM tags
Run the checks from mechanics to consequences. The first three belong before a campaign launch, the last two are recurring hygiene.
1. Do tags survive the redirects
The critical check. Take a real tagged link and see what is left at the end of the chain:
# Walk the whole chain, print the final URL and the redirect count
curl -sSIL 'http://example.com/pricing?utm_source=linkedin&utm_medium=social' -o /dev/null -w 'final=%{url_effective}\nredirects=%{num_redirects}\ncode=%{http_code}\n'
# Show every hop: status lines and Location headers
curl -sSIL 'http://example.com/pricing?utm_source=linkedin&utm_medium=social' | grep -iE '^(HTTP/|location:)'
The final= line must contain all of your parameters. If it does not, a redirect along the way is stripping the query string, and the fix belongs in the server config, not in the link. The same chain, with every intermediate hop laid out, is shown by the redirect checker (English version) — paste the full tagged URL, not the bare domain. To see the response headers of the final page, including cache headers, use the HTTP header checker.
2. What canonical does a tagged page return
# canonical must point at the clean address WITHOUT utm parameters
curl -sSL 'https://example.com/pricing?utm_source=linkedin' | grep -io '<link[^>]*canonical[^>]*>'
The expected result is a link to https://example.com/pricing. If tags appear inside the canonical, fix the page template: the canonical URL is most likely being assembled from the current request URL in full. How canonical interacts with redirects is covered in redirects and SEO.
3. Does the visit reach GA4
Open the tagged link in a private window with no ad blocker and check the Realtime report. If the visit shows up as direct, the tag was lost on the way; if it does not show up at all, the tracking script did not fire.
4. Is robots.txt correct
Verify that you have not accidentally blocked parameterized URLs with Disallow, and, if you target Yandex, that Clean-param is present in the Yandex section. Directive syntax and scope are analyzed by the robots.txt checker.
5. Have tagged URLs reached the index
In Google, a search operator does the job: a query like site:example.com inurl:utm_ reveals indexed parameterized addresses, and the Pages report in Search Console shows which duplicates Google has already folded into your canonical. In Yandex, open the indexed-pages section of Yandex Webmaster and filter the list by the substring utm. Any hits mean an external or internal link carrying a tag exists somewhere and the canonical did not override it.
Once a quarter it is worth crawling the whole site: an SEO audit surfaces duplicate titles and descriptions, incorrect canonicals and pages reachable at several addresses at once — and parameterized clones show up in exactly those reports.
Pre-launch checklist
- All tag values are lowercase Latin, with no spaces or special characters.
- source, medium and campaign are filled in at minimum; medium comes from the shared vocabulary and maps to the GA4 channel you expect.
- The first parameter is separated by
?, the rest by&; if the page already has parameters, tags are appended with&. - Tags sit before the
#fragment, not after it. - Google Ads auto-tagging is on and the accounts are linked; manual tags live in the Final URL suffix.
- Meta and LinkedIn ads use a paid medium (
paid_socialorcpc), notsocial. - The production link is verified with
curl -sSIL: parameters survive to the end of the redirect chain. - The destination page carries a tracking script, it fires before users leave, and a test click appears in GA4 Realtime.
- No personal data appears in any tag value.
- The tagged page's
rel="canonical"points at the clean, parameter-free address. - If you target Yandex, the Yandex section of
robots.txtcontainsClean-paramlisting the advertising parameters. - Parameterized URLs never reach
sitemap.xml. - No internal link on the site carries UTM tags.
- The CDN or server cache key ignores
utm_*. - Tagged URLs are confirmed absent from the index:
site:… inurl:utm_and, for Yandex, the indexed-pages report in Yandex Webmaster.
FAQ
What does UTM stand for?
Urchin Tracking Module. Urchin was the analytics company Google bought and rebuilt as Google Analytics; the parameter names survived and are now read by practically every analytics tool, CRM and email platform.
What are the 5 UTM parameters?
utm_source (the platform: google, facebook, newsletter), utm_medium (the channel type: cpc, email, social), utm_campaign (the campaign name or ID), utm_content (the creative or link variant) and utm_term (the keyword). The first three are the practical minimum; GA4 also accepts utm_id and a few newer ones.
How do I set up UTM parameters?
Agree on a medium vocabulary, build links with a builder or a shared template, and put ad-platform tags in the platform's own field: the Final URL suffix in Google Ads, URL parameters in Meta Ads Manager. Then click one real link, confirm the parameters survive redirects and that the visit appears in GA4 Realtime.
What are common UTM mistakes?
Mixed case (Google vs google), confusing source with medium, invented mediums that GA4 files as Unassigned, UTM tags on internal links, redirects that drop the query string, and tagged URLs leaking into canonical tags and sitemaps.
Should I use UTM parameters with Google Ads auto-tagging?
Keep auto-tagging on — it gives GA4 far more detail. Add UTMs in the Final URL suffix only if a CRM or a non-Google analytics tool needs the data. For Google Ads traffic, GA4 uses the gclid data when both are present.
Do UTM tags affect SEO?
Not directly: the engine receives identical content either way. Indirectly, yes — if tagged addresses get crawled and spawn duplicates. A parameter-free canonical fixes it; for Yandex add Clean-param. Never block the tagged URLs with Disallow.