Skip to content

URL & UTM guide

Tool guide. Updated .

How XGM URL & UTM splits a URL into its parts and decoded query, builds UTM campaign links, and helps spot encoding problems and suspicious links.

The anatomy of a URL

A URL with every part
https://user:pass@shop.example.com:8443/products/shoes?color=blue&size=42#reviews
└─┬─┘   └───┬───┘ └──────┬───────┘ └┬─┘└─────┬───────┘ └───────┬────────┘ └──┬──┘
scheme  credentials     host       port    path            query          fragment
URL components
PartExampleMeaning
Protocol (scheme)https:How to access the resource
Username and passworduser:pass@Credentials embedded in the URL; rare and discouraged
Hostnameshop.example.comThe server; decides where the request goes
Port8443Omitted when it is the scheme's default (443 for HTTPS, 80 for HTTP)
Path/products/shoesThe resource on the server
Query?color=blue&size=42Parameters as key=value pairs
Fragment#reviewsA position inside the page; never sent to the server
Originhttps://shop.example.com:8443Scheme, host and port together; the browser's security boundary
How the parser reads your inputThe input gets https:// added if it has no scheme, is parsed by the browser's URL implementation, and is shown as parts plus a table of decoded query parameters.InputA full URL, or a bare host and path such asexample.com/pricingAdd a scheme if missinghttps:// is assumed; mailto:, tel:, data: andurn: are keptParse with the URL APIThe same WHATWG URL rules browsers usePartsProtocol, username, masked password, hostname,port, path, query, fragment, originQuery parametersEach key and value, decoded
The input gets https:// added if it has no scheme, is parsed by the browser's URL implementation, and is shown as parts plus a table of decoded query parameters.

How to parse a URL

  1. Open the URL & UTM and paste a URL.
  2. Read the table of parts; a password in the URL is masked in the display.
  3. Check the query parameters table for each key and its decoded value.
  4. Copy what you need, or continue with the UTM Builder or URL Encoder.

Parsing happens in your browser. Long tracking links often contain email addresses, session identifiers or tokens in their parameters, so the tool does not send them anywhere.

Building UTM campaign links

The second mode of URL & UTM builds campaign links. Analytics tools read five parameters: utm_source (where the visitor came from, such as newsletter), utm_medium (the channel, such as email or cpc), utm_campaign (your name for the campaign), and optionally utm_term and utm_content. The first three are expected on every tagged link.

The builder keeps existing query parameters, encodes values, and warns about spaces and capital letters, because analytics tools treat Newsletter and newsletter as different sources. Presets fill the usual values for a newsletter, a LinkedIn post and a Google Ads link.

Campaign URL
https://example.com/pricing?utm_source=newsletter&utm_medium=email&utm_campaign=september-launch

Query strings and encoding

Query parameters are separated by &, keys and values by =. Characters with special meaning, such as &, =, #, + and spaces, must be percent-encoded inside values: a space becomes %20 (or + in form encoding), & becomes %26. The parser shows values decoded, so name=Ana%20Pop appears as Ana Pop.

Encoding problems you can spot
What you seeCause
A parameter value is cut off at &An unencoded & inside the value started a new parameter
%2520 in the URLA value was encoded twice (% encoded as %25)
+ where a space should be, or the reverseForm encoding versus percent-encoding mixed up
The same key appears several timesAllowed; many frameworks read it as a list, others take the first or last value
Text after # missing on the serverFragments are never sent in HTTP requests

The URL Encoder encodes and decodes individual values with either component or full-URI rules, which is the right tool when you build URLs by hand.

Phishing links rely on people reading the wrong part of a URL. The hostname is the only part that decides which server you reach, and within it the registered domain is the last labels before the top-level domain. Everything else can be made to look official.

Deceptive patterns
LinkReal hostTrick
https://example.com.login.example.net/example.com.login.example.netThe trusted name is a subdomain of another domain
https://example.com@example.net/example.netText before @ is a username, not the host
https://example.net/example.com/loginexample.netThe trusted name is only in the path
https://examp1e.com/examp1e.comLookalike characters
https://xn--exmple-cua.com/Punycode for a name with a non-ASCII letterInternationalised lookalike domain

Do not open a link to check it

Paste suspicious links into the parser instead of clicking them. If the real host is not the organisation you expect, report the message rather than visiting the page.

For links that redirect, the parser shows only the first URL. The Redirect Checker follows a domain's redirect chain from the XGM server, and WHOIS shows when a domain was registered, which is often very recent for phishing domains.

Tracking parameters and privacy

Many links carry parameters that have nothing to do with the page content: campaign tags such as utm_source and utm_campaign, click identifiers added by advertising platforms, and email-specific IDs that tie a click to a recipient. The parameters table makes them easy to see. Removing them before sharing a link keeps your own activity and the original recipient's identity out of other people's analytics.

Common parameters
ParameterPurpose
utm_source, utm_medium, utm_campaignCampaign attribution in analytics tools
utm_term, utm_contentKeyword and ad variant attribution
Click IDs from ad platformsLinking a visit to a specific ad click
Session or token parametersAuthentication or state; never share links that contain them

If you publish campaign links yourself, build them consistently with the UTM Builder. Lowercase values and a fixed naming scheme keep analytics reports clean, because most tools treat Email and email as different sources.

Parsing URLs in code

Use the platform's URL parser instead of regular expressions or string splitting. Edge cases such as credentials, IPv6 hosts in brackets, default ports and encoded characters break hand-written parsers, and inconsistent parsing between components has caused many security bugs, for example in redirect allowlists.

The URL API in JavaScript
const url = new URL("https://shop.example.com/products?color=blue&size=42");
url.hostname;                 // "shop.example.com"
url.searchParams.get("size"); // "42"
url.searchParams.set("size", "43");
url.toString();               // "https://shop.example.com/products?color=blue&size=43"

When validating redirect targets or allowed origins, compare the parsed origin or hostname exactly against an allowlist. Checks such as startsWith("https://example.com") accept https://example.com.example.net, which is a classic open-redirect mistake.

FAQ

Is the URL sent to XGM?

No. Parsing uses your browser's URL implementation, and nothing is uploaded.

What happens if I paste a URL without https://?

The parser assumes https:// so inputs like example.com/pricing work. Schemes such as mailto: and tel: are kept as they are.

Why is the fragment not in my server logs?

Browsers never send the part after # to the server. It is only used by the page itself.

What is the origin?

The combination of scheme, host and port. Browsers use it for the same-origin policy, cookies scoping rules and CORS.

Why is the port shown as default?

The URL uses the standard port for its scheme, 443 for HTTPS or 80 for HTTP, so no port number is written.

Can a URL contain a password?

The syntax allows user:password@host, but browsers warn about it and it exposes credentials in logs and history. The parser masks the password in its display.

Why do some parameters appear twice?

A key can be repeated in a query string. How the server interprets repeats depends on the framework.

What is Punycode?

An ASCII encoding for internationalised domain names, starting with xn--. Browsers may show either form; the parser shows the hostname as the URL API returns it.

What is the difference between a URL and a URI?

A URI identifies a resource; a URL is a URI that also says how to locate it, such as with https:. In everyday web use the terms are used interchangeably.

Can a hostname be an IP address?

Yes. IPv4 addresses appear as they are, and IPv6 addresses appear in square brackets, for example https://[2001:db8::1]/. Links with raw IP addresses are unusual for normal websites and worth a second look.

How do I build a campaign URL?

Use the UTM Builder, which adds utm_source, utm_medium and utm_campaign parameters with correct encoding.

Sources