What is utm_source vs utm_medium?
utm_source names who sent the visit, such as google, facebook or a newsletter. utm_medium names the kind of link, such as cpc, email or social. GA4 reads the pair together to pick a channel. A swapped pair or an unknown spelling usually lands in the wrong channel or in Unassigned.
By Joris van Huët, Founder & CEOUpdated 7 min read
Run the numbers for your store: the free UTM builder.
utm_source names who sent the visit, such as google, facebook or your newsletter. utm_medium names the kind of link, such as cpc, email or social. GA4 reads the two together to pick a channel. If you swap them or invent a spelling, the visit usually lands in the wrong channel or in Unassigned.
Google's help defines the pair in a line each. Source is where your traffic originates, such as Google or Bing. Medium is how users arrive, such as organic, cpc or email. A quick test keeps them apart: a source is a name, and a medium is a kind of traffic that repeats across many names.
Google itself sends you two kinds of visits. Free search results arrive as google / organic, and ad clicks as google / cpc. Same source, two mediums, two rows. The reverse works too: an ad on Facebook and an ad on TikTok can share the medium paid_social and differ only in source. Google's tagging advice wants exactly that: one unique utm_source per platform, one unique utm_medium per channel.
GA4 then files each visit under a channel with fixed rules. Each rule reads one half of the pair, or both:
- Medium only. Affiliates needs affiliate, Referral needs referral, app or link, and Display needs a medium such as banner.
- Either half. Email and SMS accept their word in either slot.
- Both halves. Paid Social needs a source on Google's list of social sites. It also needs a medium that reads as paid, such as cpc or anything starting with paid. Paid Search and Paid Video work the same way.
- Neither half. Direct is GA4's name for (direct) / (none): a visit with no referral source at all.
One channel even runs on a medium you never type. GA4 files a visit under AI Assistant only when the medium reads ai-assistant. GA4 writes that medium itself when the referrer is on its list of assistants.
What one store's data shows
One store's anonymised GA4 export, 1 January 2024 to 21 August 2026. It holds shares of revenue only: no ad spend, no order counts.
| What the export shows | Share of revenue | Source cell |
|---|---|---|
| Direct, in last click, first click and touched views | 57.7% | Channels sheet, Direct row |
| AI Assistant, in all three views | 0.0% | Channels sheet, AI Assistant row |
| Paid Social, in all three views | 0.0% | Channels sheet, Paid Social row |
| Journeys with 1 touch (0.5 days to buy) | 79.5% | Journeys sheet, 1 touch row |
On the Channels sheet, Direct holds 57.7% of revenue, whether the first visit, the last visit or any visit gets the credit. Direct is the row where both halves of the pair are missing. In this one store, journeys holding 57.7% of revenue include a visit that arrived with neither a source nor a medium.
On the Channels sheet, the AI Assistant row reads 0.0% in every view. GA4 only fills that channel after it reads the referrer and writes the ai-assistant medium itself. The export cannot say whether no such visit led to revenue here, or whether such visits arrived without a referrer and joined Direct.
Paid Social also reads 0.0% in all three views on the Channels sheet. It is one of the fussiest rules, because it needs both halves. So the zero has a few readings. This store ran no social ads, or ran them under pairs GA4 could not file, or its ads never touched a buying journey.
On the Journeys sheet, journeys with 1 touch hold 79.5% of revenue and took 0.5 days to buy. A one-touch journey carries exactly one pair. So for about four fifths of this store's revenue, one source and one medium decided where all the credit went.
What the export cannot show is the pairs themselves. It holds the channels that came out of GA4's rules, not the values that went in. Your own Traffic acquisition report holds those.
Why does the usual answer mislead?
The usual answer stops at the definition: source is where, medium is how. That is correct and not enough, for three reasons.
GA4 matches spellings, not meanings. The paid channels look your source up in Google's lists of search, social, video and shopping sites. GA4's downloadable list of social sources holds facebook and fb, but not meta. So a click tagged meta with a paid medium can miss Paid Social. It lands in Paid Other, GA4's channel for ads it cannot place as search, social, shopping or video.
You do not always write the pair. When a click carries auto-tagging and your tags together, GA4 uses the auto-tagged values for source and medium. Meta may add tags of its own: its help lists a campaign source of Facebook or Instagram and a campaign medium of paid. And GA4 writes the ai-assistant medium without asking anyone.
One shopper carries several pairs. GA4 keeps a first user source and medium for how someone first arrived, and a session pair for each visit. User acquisition reports the first pair and Traffic acquisition the session pair, and Google's help says not to compare their numbers.
What can a source and medium not tell you?
A pair is a postmark. It says who sent the visit and by what route. It says nothing about why the shopper bought, or whether they would have bought anyway.
A pair can also be inherited rather than observed. Google's help says a direct visit that follows a referred visit will never override the existing referrer. So a shopper who clicks your email on Monday and types your address on Friday can show the email's pair both times in Traffic acquisition.
And a pair never sees an ad that was watched but not clicked. That shopper may turn up later as Direct, and the pair points at nobody.
What to do this week
- List your mediums. In GA4, select Reports, then Acquisition > Traffic acquisition, and switch the table to Session medium. Pass: every value is one GA4's rules know, such as cpc, paid_social, email, affiliate or referral. Fail: a platform name such as facebook sits in the medium column, so swap the two at the sender.
- Check where your paid social clicks land. Keep the report on its default dimension, Session default channel group. Click + Add filter, pick Session source as the dimension and meta, or your own spelling, as the value, then click OK and Apply. Pass: the rows sit in Paid Social. Fail: they sit in Paid Other, so use facebook or fb as the source on new ads.
- Read your purchase paths by medium. In GA4, click Advertising, then Key event attribution paths under the Key events drop-down. Switch the table from the channel group to Medium. Pass: the paths behind most revenue name mediums you set on purpose. Fail: most read (none) or (not set), so your buyers arrive untagged.
Check the homework. Your GA4 Attribution paths export already holds the evidence. Causality Engine reads that one file and shows what each channel caused next to what last-click gave it, in 1 to 2 minutes, for €99 once (excluding VAT), refundable within 30 days. Check the homework
Sources, 1 October 2026: Traffic-source dimensions, manual tagging, and auto-tagging (Google); URL builders: Collect campaign data with custom URLs (Google); Default channel group (Google); GA4 default-channel-group sources and categories (Google); Campaigns and traffic sources (Google); Understand (direct) / (none) traffic (Google); User acquisition report vs. Traffic acquisition report (Google); Traffic acquisition report (Google); Key events attribution paths report (Google); Add URL parameters to your Meta ads in Meta Ads Manager (Meta)
Related answers
Frequently asked questions
Can utm_source and utm_medium have the same value?
Yes, and for text messages it is normal: GA4 files a visit under SMS when either the source or the medium reads exactly sms. For most links it wastes a slot, though. The source should name the sender and the medium the kind of link, so each answers a different question.Does utm_source or utm_medium decide the GA4 channel?
Usually the medium sorts a visit into a family, such as paid, email, referral or affiliate. For paid clicks, the source then picks the channel by matching Google's lists of search, social, video and shopping sites. An unknown source with a paid medium lands in Paid Other.Why does google show up as both organic and cpc?
Because Google sends you two kinds of visits. The source names the sender, google both times. The medium names the route: organic for free search results, cpc for clicks on Google Ads. Same sender, two routes, two rows in your report and two different channels.
Go deeper: Causal attribution, explained.
Sixty-second versions of these ideas: Causality Engine on YouTube Shorts.
Keep reading
Terms in this article
- Ad SpendAd Spend is the total amount invested in advertising campaigns. It is measured against Return on Ad Spend (ROAS) to evaluate campaign effectiveness.
- AnalyticsAnalytics is the systematic computational analysis of data. It reveals customer behavior and measures campaign performance.
- AttributionAttribution identifies user actions that contribute to a desired outcome and assigns value to each. It reveals which marketing touchpoints drive conversions.
- CausalityCausality is the relationship where one event directly causes another, essential for identifying specific actions that drive desired outcomes in marketing.
- NewsletterNewsletter is a regularly distributed email publication containing news, updates, and promotional content for subscribers.
- RevenueRevenue is the total income generated by the sale of goods or services related to a company's primary operations.
- Traffic SourceTraffic Source is the origin through which users find a site. Common sources include organic search, paid search, direct traffic, and referrals.
- UTM ParametersUTM Parameters are URL tags marketers use to track campaign effectiveness across traffic sources. They provide data for accurate campaign tracking and attribution in analytics platforms.