Hidden Fields in Forms: How to Carry UTM Tags, gclid, fbclid and the Landing Page Into Every Lead
Hidden fields in forms are the quiet plumbing that carries a visitor's UTM tags, click IDs and landing page into the lead your team opens. This guide explains how they work, what to put in them and how to set them up on common form tools.
By DigiPix Flow team

In this guide
Your Google Ads link carries ?utm_campaign=pune-3bhk&gclid=…, the visitor lands on your page, fills in the enquiry form, and the lead arrives in your inbox with a name, a phone number and nothing about where it came from. The tags were there, in the address bar, for the whole visit. They simply had no way into the form.
Hidden fields in forms fix that. They are form fields the visitor never sees, filled in automatically and submitted with everything else. This guide is about the mechanics: what a hidden field is, which values to carry, the three ways to fill them and how to set them up on the form tools Indian businesses use most. For the wider question of tracking and reporting every lead's source, read our guide to lead source tracking.
What a hidden field is
In HTML, a hidden field is an input with type="hidden", a name and a value, for example an input named utm_source whose value is google. The browser doesn't draw it, the visitor can't type in it, and when the form is submitted its name and value travel with the visible answers. Most form builders offer the same thing under a name like Hidden field or Hidden value.
Two properties matter in practice. First, hidden is not secure: anyone can see the values in the page source and change them before submitting, so use them for tracking, never for prices or permissions. Second, a hidden field starts empty unless something fills it. That "something" is the whole job.
Which values to carry
| Field name | What it holds | Where the value comes from |
|---|---|---|
| utm_source | Where the click came from, e.g. facebook | The page address |
| utm_medium | Type of traffic, e.g. cpc or paid-social | The page address |
| utm_campaign | Campaign name, e.g. pune-3bhk-diwali | The page address |
| utm_content | Which ad or link, e.g. video-a | The page address |
| utm_term | Search keyword | The page address |
| gclid | Google Ads click ID | Added by Google Ads when auto-tagging is on |
| fbclid | Meta click ID | Added by Meta to links clicked on Facebook and Instagram |
| landing_page | The full address the visitor arrived on | The browser, at arrival |
| referrer | The site that sent them, if the browser shares it | The browser, at arrival |
| form_name | Which form on which page | A fixed value you set per form |
If UTM tags are unfamiliar, our glossary entry on UTM parameters explains each one, and the free UTM builder builds consistent tagged links. Use the exact names above in your fields; most tools match a hidden field to an address parameter by name, so utm_Source and utm_source are not the same.
Three ways to fill a hidden field
1. Read the current page address
The simplest method: when the form loads, copy each parameter from the address into the matching field. Many form plugins do this with a setting. It works perfectly when the form sits on the landing page the ad points to.
2. Save the values on arrival, then reuse them
Real visitors wander. Example: someone lands on your Diwali offer page from an Instagram ad, reads the About page, then fills in the form on the Contact page. The Contact page's address has no tags, so method 1 submits blanks. The fix is a small script on every page that saves the tags, landing page and referrer the first time a tagged address is seen, in the browser's session storage or a cookie, and fills the hidden fields from there on any page. Keep the first campaign rather than overwriting it with later untagged visits. If you use a cookie, check that your cookie notice covers it.
3. Set fixed values per form
Some values never come from the address. A field called form_name with the value pricing-page-callback tells you which of your five forms produced the lead. A hosted form link that you share in a WhatsApp broadcast can carry its own UTM tags in the link itself, so each placement is labelled.
Setting hidden fields up on common form tools
| Tool | How to add a hidden field filled from the address |
|---|---|
| Hand-coded HTML form | Add an input with type="hidden" for each value, then a short script that fills them from the address or from session storage (method 2). |
| Contact Form 7 (WordPress) | Use the hidden form-tag with the default:get option, e.g. [hidden utm_source default:get]. It takes the value of the matching parameter from the page address. See its hidden field documentation. |
| Gravity Forms (WordPress) | Add a Hidden field, open its Advanced tab, tick "Allow field to be populated dynamically" and enter utm_source as the parameter name. See its dynamic population guide. |
| WPForms (WordPress) | WPForms' Smart Tags include a query string tag, {query_var key="utm_source"}, that reads a value from the page address; check WPForms' documentation for using it as a Hidden Field's default value. |
| Google Forms | Pre-filled links fill in answers that the respondent can still see and change, so they work as a stop-gap but are not truly hidden. |
| Meta lead forms | These live on Facebook and Instagram, not your site, so there's no page address. Use the form's tracking parameters setting instead (see below). |
Note that the WordPress options above read the address of the page the form is on, which is method 1. If visitors browse before enquiring, add a method-2 script, or use a form that keeps the tags for the visit.
Ad platform lead forms
Lead forms inside ad platforms never touch your website, so there are no address tags to read. Meta's instant forms have their own version of hidden fields: in the form's Settings you can add tracking parameters such as utm_source with a value of facebook. Meta says people don't see them, and they appear in downloaded lead files and are passed to integrated CRM systems. Your CRM also needs to read them, so check that before relying on them.
How to test hidden fields before a campaign
- Build a test link to your landing page with every tag filled in, e.g. ?utm_source=test&utm_medium=test&utm_campaign=hidden-field-check&gclid=TEST123.
- Open it in a private browser window, click through to a second page, then submit the form there.
- Open the lead in your CRM and check every value arrived, in the right field, in lower case.
- Repeat with an untagged visit and confirm the fields are blank, not filled with an old value.
- Delete the test lead so it doesn't distort reports.
Common hidden field mistakes
- Names that don't match. A field named source will never pick up utm_source.
- Tags lost between pages. The classic cause of "why do half our leads have no source?"
- Cached pages. If a page is cached with values already filled in on the server, every visitor can submit the first visitor's tags. Fill values in the browser instead.
- Overwriting the first source. A returning visitor's untagged visit replaces the campaign that found them.
- Mapping nobody finished. The form collects the values, but the CRM has no field to store them in, so they are dropped. Check your field mapping.
Where DigiPix Flow fits
If you use DigiPix Flow's website forms, you don't have to build the plumbing yourself. The embed snippet and the hosted form page read utm_source, utm_medium, utm_campaign, utm_content and utm_term, Google's gclid and Meta's fbclid from the page address, along with the landing page and the referrer, and save them with the lead. The first campaign a visitor arrived from is kept for that browser tab's session, so a form filled in on a later page of the same visit still carries it.
A utm_* hidden field on the form takes priority over the page address, which helps when one form sits on pages for different campaigns, and a server that posts entries itself can send the same details. Everything shows on the lead's capture details, as described on the UTM tracking page. Tags are held for the visit in that tab only, so tag the links in your follow-up emails and messages too.
Do your website leads arrive with their campaign attached? Talk to an expert and we'll check a tagged visit end to end with your own forms.
Frequently asked questions
What are hidden fields in forms?
Hidden fields are form fields that are not shown to the visitor but are submitted with the form. They are usually filled in automatically, for example with the UTM tags, click IDs and landing page of the visit, so each lead arrives with its source attached.
How do I pass UTM parameters into a form?
Add a hidden field for each tag, named utm_source, utm_medium, utm_campaign, utm_content and utm_term, and fill them from the page address when the form loads. If visitors may browse to another page first, save the tags when they arrive and fill the fields from the saved values.
Can I capture gclid and fbclid in a hidden field?
Yes. They appear in the page address like UTM tags: gclid when Google Ads auto-tagging is on, and fbclid on links clicked from Facebook and Instagram. Add hidden fields named gclid and fbclid and fill them the same way.
Are hidden fields secure?
No. Anyone can see and change hidden field values in the page source before submitting. They are fine for tracking information, but never use them for prices, discounts, internal notes or anything you would not want a visitor to edit.
Why are my hidden fields arriving empty?
Usually the link wasn't tagged, the field names don't match the parameters, or the visitor moved to another page before filling in the form. Cached pages and CRM fields that were never mapped are other common causes. Test with a tagged link and a two-page visit.
Does Google Forms support hidden fields?
Google Forms offers pre-filled links, which fill in answers through the link, but those answers stay visible and editable to the respondent. They can carry a campaign label as a stop-gap, but they are not hidden fields.
Put this guide into practice
See qualification questions, lead scoring and follow-up built into one workspace, using your own lead sources.

