๐Ÿงญ Referrer-Policy Header Builder

Generated header
Referrer-Policy: strict-origin-when-cross-origin

Choose and generate a Referrer-Policy header, which controls how much information the browser includes in the Referer header when a visitor clicks a link to another site, from the eight values defined by the spec.

How to use

  1. Select the policy you want to apply from the list.
  2. The generated Referrer-Policy header string is shown automatically.
  3. Use the "Copy" button to copy the header string and set it on your web server or in a meta tag.

How the calculation works

The Referer header tells a server which page a visitor came from when they follow a link or load an image. The Referrer-Policy header controls how much of that is sent, and the W3C specification defines eight values: no-referrer: never send it no-referrer-when-downgrade: do not send it from HTTPS to HTTP origin: send only the origin (https://example.com/) origin-when-cross-origin: full URL within the site, origin only to other sites same-origin: send it only within the same origin strict-origin: origin only, and nothing from HTTPS to HTTP strict-origin-when-cross-origin: full URL within the site, origin only to other sites, nothing from HTTPS to HTTP unsafe-url: always send the full URL Major browsers use strict-origin-when-cross-origin when no policy is set.

Worked example

Clicking a link to another site from https://example.com/account/orders?id=123 strict-origin-when-cross-origin: https://example.com/ no-referrer: nothing is sent unsafe-url: https://example.com/account/orders?id=123 Header syntax Referrer-Policy: strict-origin-when-cross-origin

Things to be aware of

  • Do not use unsafe-url on pages whose URLs contain personal data or tokens; it leaks them to other sites.
  • Individual links and images can override the policy with the HTML referrerpolicy attribute or rel="noreferrer".
  • For analytics, strict-origin-when-cross-origin is usually enough, since full URLs are still sent within your own site.

FAQ

What is Referrer-Policy?

It's an HTTP header that controls how much information is included in the Referer header sent to the destination site when a visitor navigates away โ€” letting you omit all or part of the originating URL for privacy.

Which policy should I choose?

Most major browsers default to strict-origin-when-cross-origin, a balanced setting that sends the full URL to same-origin destinations and only the origin to cross-origin (and otherwise secure) destinations. It's a good default if you're unsure.

Can this be set somewhere other than an HTTP header?

Yes โ€” the same value can be set with an HTML `<meta name="referrer" content="...">` tag. If both the HTTP header and a meta tag are present, the page-level setting takes precedence.