Source is the analytics dimension that records where a visit came from: a search engine such as google or bing, a website such as linkedin.com or a supplier’s blog, or a name you set yourself, such as spring-newsletter. In GA4 it is almost always read together with medium, which records the type of traffic.
How source works
GA4 works out the source of a session in one of three ways:
- Campaign tags. If the link carries a utm_source parameter, that value is used exactly as written.
- Click identifiers. A gclid on the URL tells GA4 the visit came from Google Ads when the accounts are linked.
- The referrer. With no tags, GA4 reads the referring domain the browser passes on, so a click from a news article shows that site’s domain.
If none of these exist, the source is (direct). Source appears in several forms in GA4. Session source describes what started each visit. First user source describes what first brought a person to the site and stays attached to them. In the advertising reports, key events are credited to sources through an attribution model. These are different questions, so expect different numbers.
Source is also limited by what the browser passes on. Many apps, email clients and secure-to-insecure jumps strip the referrer, and some privacy tools remove click identifiers. Those visits arrive with no source information and end up as direct, which is why tagging the links you control matters so much.
Why it matters
Source is the most specific view you have of where traffic comes from. The channel group might say Referral, but only the source tells you that the referral came from a trade association directory, a local council business listing or a single blog post that keeps sending enquiries. For a UK business deciding whether to renew a paid directory listing or sponsor a newsletter, that detail is the evidence.
It also exposes tracking faults. Payment pages are the usual culprit: when a customer pays through PayPal, Stripe Checkout or their bank’s card verification screen and returns to your thank-you page, the payment provider can appear as the source of the sale. A sudden source called paypal.com with a high conversion rate is a broken report, not a marketing channel.
Common mistakes
- Inconsistent capitals. Source is case-sensitive. Facebook, facebook and FB become three rows.
- Tagging internal links. UTM tags on links between your own pages overwrite the real source mid-visit.
- Missing referral exclusions. Payment gateways and booking tools on other domains take credit for sales.
- Your own domain as a source. A self-referral usually means a page is missing the tag or a subdomain is not configured.
- Vague names. A source of email tells you nothing that the medium does not already say. Name the list or the sender.
How to act on it
Write down a naming convention: lowercase, hyphens instead of spaces, and the platform or publication name as the source. Build every campaign link with a UTM link builder so the convention is applied without anyone having to remember it. Then check the traffic acquisition report by session source / medium each month, look for duplicates, your own domain and payment providers, and add referral exclusions (GA4 calls them unwanted referrals) where needed.
Clean source data is what lets you judge every paid and organic channel fairly, and it underpins the reporting in my performance marketing service.
