๐งญ Referrer-Policy Header Builder
Referrer-Policy: strict-origin-when-cross-origin
Choose and generate a Referrer-Policy header, which controls how much information the browser includes in the Referer header when a visitor clicks a link to another site, from the eight values defined by the spec.
How to use
- Select the policy you want to apply from the list.
- The generated Referrer-Policy header string is shown automatically.
- Use the "Copy" button to copy the header string and set it on your web server or in a meta tag.
How the calculation works
The Referer header tells a server which page a visitor came from when they follow a link or load an image. The Referrer-Policy header controls how much of that is sent, and the W3C specification defines eight values: no-referrer: never send it no-referrer-when-downgrade: do not send it from HTTPS to HTTP origin: send only the origin (https://example.com/) origin-when-cross-origin: full URL within the site, origin only to other sites same-origin: send it only within the same origin strict-origin: origin only, and nothing from HTTPS to HTTP strict-origin-when-cross-origin: full URL within the site, origin only to other sites, nothing from HTTPS to HTTP unsafe-url: always send the full URL Major browsers use strict-origin-when-cross-origin when no policy is set.
Worked example
Clicking a link to another site from https://example.com/account/orders?id=123 strict-origin-when-cross-origin: https://example.com/ no-referrer: nothing is sent unsafe-url: https://example.com/account/orders?id=123 Header syntax Referrer-Policy: strict-origin-when-cross-origin
Things to be aware of
- Do not use unsafe-url on pages whose URLs contain personal data or tokens; it leaks them to other sites.
- Individual links and images can override the policy with the HTML referrerpolicy attribute or rel="noreferrer".
- For analytics, strict-origin-when-cross-origin is usually enough, since full URLs are still sent within your own site.
FAQ
What is Referrer-Policy?
It's an HTTP header that controls how much information is included in the Referer header sent to the destination site when a visitor navigates away โ letting you omit all or part of the originating URL for privacy.
Which policy should I choose?
Most major browsers default to strict-origin-when-cross-origin, a balanced setting that sends the full URL to same-origin destinations and only the origin to cross-origin (and otherwise secure) destinations. It's a good default if you're unsure.
Can this be set somewhere other than an HTTP header?
Yes โ the same value can be set with an HTML `<meta name="referrer" content="...">` tag. If both the HTTP header and a meta tag are present, the page-level setting takes precedence.