URL & UTM guide
How XGM URL & UTM splits a URL into its parts and decoded query, builds UTM campaign links, and helps spot encoding problems and suspicious links.
The anatomy of a URL
https://user:pass@shop.example.com:8443/products/shoes?color=blue&size=42#reviews
└─┬─┘ └───┬───┘ └──────┬───────┘ └┬─┘└─────┬───────┘ └───────┬────────┘ └──┬──┘
scheme credentials host port path query fragment| Part | Example | Meaning |
|---|---|---|
| Protocol (scheme) | https: | How to access the resource |
| Username and password | user:pass@ | Credentials embedded in the URL; rare and discouraged |
| Hostname | shop.example.com | The server; decides where the request goes |
| Port | 8443 | Omitted when it is the scheme's default (443 for HTTPS, 80 for HTTP) |
| Path | /products/shoes | The resource on the server |
| Query | ?color=blue&size=42 | Parameters as key=value pairs |
| Fragment | #reviews | A position inside the page; never sent to the server |
| Origin | https://shop.example.com:8443 | Scheme, host and port together; the browser's security boundary |
How to parse a URL
- Open the URL & UTM and paste a URL.
- Read the table of parts; a password in the URL is masked in the display.
- Check the query parameters table for each key and its decoded value.
- Copy what you need, or continue with the UTM Builder or URL Encoder.
Parsing happens in your browser. Long tracking links often contain email addresses, session identifiers or tokens in their parameters, so the tool does not send them anywhere.
Building UTM campaign links
The second mode of URL & UTM builds campaign links. Analytics tools read five parameters: utm_source (where the visitor came from, such as newsletter), utm_medium (the channel, such as email or cpc), utm_campaign (your name for the campaign), and optionally utm_term and utm_content. The first three are expected on every tagged link.
The builder keeps existing query parameters, encodes values, and warns about spaces and capital letters, because analytics tools treat Newsletter and newsletter as different sources. Presets fill the usual values for a newsletter, a LinkedIn post and a Google Ads link.
https://example.com/pricing?utm_source=newsletter&utm_medium=email&utm_campaign=september-launchQuery strings and encoding
Query parameters are separated by &, keys and values by =. Characters with special meaning, such as &, =, #, + and spaces, must be percent-encoded inside values: a space becomes %20 (or + in form encoding), & becomes %26. The parser shows values decoded, so name=Ana%20Pop appears as Ana Pop.
| What you see | Cause |
|---|---|
A parameter value is cut off at & | An unencoded & inside the value started a new parameter |
%2520 in the URL | A value was encoded twice (% encoded as %25) |
+ where a space should be, or the reverse | Form encoding versus percent-encoding mixed up |
| The same key appears several times | Allowed; many frameworks read it as a list, others take the first or last value |
Text after # missing on the server | Fragments are never sent in HTTP requests |
The URL Encoder encodes and decodes individual values with either component or full-URI rules, which is the right tool when you build URLs by hand.
Checking a suspicious link
Phishing links rely on people reading the wrong part of a URL. The hostname is the only part that decides which server you reach, and within it the registered domain is the last labels before the top-level domain. Everything else can be made to look official.
| Link | Real host | Trick |
|---|---|---|
https://example.com.login.example.net/ | example.com.login.example.net | The trusted name is a subdomain of another domain |
https://example.com@example.net/ | example.net | Text before @ is a username, not the host |
https://example.net/example.com/login | example.net | The trusted name is only in the path |
https://examp1e.com/ | examp1e.com | Lookalike characters |
https://xn--exmple-cua.com/ | Punycode for a name with a non-ASCII letter | Internationalised lookalike domain |
Do not open a link to check it
For links that redirect, the parser shows only the first URL. The Redirect Checker follows a domain's redirect chain from the XGM server, and WHOIS shows when a domain was registered, which is often very recent for phishing domains.
Tracking parameters and privacy
Many links carry parameters that have nothing to do with the page content: campaign tags such as utm_source and utm_campaign, click identifiers added by advertising platforms, and email-specific IDs that tie a click to a recipient. The parameters table makes them easy to see. Removing them before sharing a link keeps your own activity and the original recipient's identity out of other people's analytics.
| Parameter | Purpose |
|---|---|
utm_source, utm_medium, utm_campaign | Campaign attribution in analytics tools |
utm_term, utm_content | Keyword and ad variant attribution |
| Click IDs from ad platforms | Linking a visit to a specific ad click |
| Session or token parameters | Authentication or state; never share links that contain them |
If you publish campaign links yourself, build them consistently with the UTM Builder. Lowercase values and a fixed naming scheme keep analytics reports clean, because most tools treat Email and email as different sources.
Parsing URLs in code
Use the platform's URL parser instead of regular expressions or string splitting. Edge cases such as credentials, IPv6 hosts in brackets, default ports and encoded characters break hand-written parsers, and inconsistent parsing between components has caused many security bugs, for example in redirect allowlists.
const url = new URL("https://shop.example.com/products?color=blue&size=42");
url.hostname; // "shop.example.com"
url.searchParams.get("size"); // "42"
url.searchParams.set("size", "43");
url.toString(); // "https://shop.example.com/products?color=blue&size=43"When validating redirect targets or allowed origins, compare the parsed origin or hostname exactly against an allowlist. Checks such as startsWith("https://example.com") accept https://example.com.example.net, which is a classic open-redirect mistake.
FAQ
Is the URL sent to XGM?
No. Parsing uses your browser's URL implementation, and nothing is uploaded.
What happens if I paste a URL without https://?
The parser assumes https:// so inputs like example.com/pricing work. Schemes such as mailto: and tel: are kept as they are.
Why is the fragment not in my server logs?
Browsers never send the part after # to the server. It is only used by the page itself.
What is the origin?
The combination of scheme, host and port. Browsers use it for the same-origin policy, cookies scoping rules and CORS.
Why is the port shown as default?
The URL uses the standard port for its scheme, 443 for HTTPS or 80 for HTTP, so no port number is written.
Can a URL contain a password?
The syntax allows user:password@host, but browsers warn about it and it exposes credentials in logs and history. The parser masks the password in its display.
Why do some parameters appear twice?
A key can be repeated in a query string. How the server interprets repeats depends on the framework.
What is Punycode?
An ASCII encoding for internationalised domain names, starting with xn--. Browsers may show either form; the parser shows the hostname as the URL API returns it.
What is the difference between a URL and a URI?
A URI identifies a resource; a URL is a URI that also says how to locate it, such as with https:. In everyday web use the terms are used interchangeably.
Can a hostname be an IP address?
Yes. IPv4 addresses appear as they are, and IPv6 addresses appear in square brackets, for example https://[2001:db8::1]/. Links with raw IP addresses are unusual for normal websites and worth a second look.
How do I build a campaign URL?
Use the UTM Builder, which adds utm_source, utm_medium and utm_campaign parameters with correct encoding.