🧾 Referrer-Policy Selector

Pick a value to see exactly what it sends, or browse all of them below.

The same link under four policies

Picking a value here shows its description and the header string; nothing is read from your site. What the choice controls is the Referer request header the browser attaches when someone leaves a page. Say the visitor is on https://shop.example.com/orders/8412?email=ada@example.com:

strict-origin-when-cross-origin   same site  the whole URL
                                  elsewhere  https://shop.example.com/
strict-origin                     always     https://shop.example.com/
same-origin                       elsewhere  no header at all
unsafe-url                        always     the whole URL, address included

The header name has two r's; the request header it governs is spelled Referer, a misspelling from 1996 that was never fixed.

Choosing one

If a URL contains a reset token or an email address, the referrer is the smallest of your problems - it is also in server logs, browser history and anything the user pastes. Keep secrets out of the path and query string.

Frequently asked questions

What is the default Referrer-Policy?

strict-origin-when-cross-origin in every current major browser. Same-origin navigation sends the full URL, anything cross-origin sends just your origin, and an HTTPS page linking to an HTTP one sends nothing.

Will no-referrer break my analytics?

Not your own - your analytics runs on your pages and sees the URL directly. It does break the other direction: partners and sites you link to lose the record of where the visit came from.

Is unsafe-url ever the right choice?

Rarely. It exists for cases where a downstream service genuinely needs the full path, such as some legacy attribution and syndication setups. It sends the whole URL cross-origin and over plain HTTP, so anything in a query string travels with it.