When a page loads an image, runs a fetch or follows a link, the browser may add a Referer request header naming the page the request came from. (The misspelling dates from the original HTTP specification; the newer Referrer-Policy header and referrerpolicy attribute are spelled correctly.) Servers use it for analytics and hotlink protection, but it also leaks: https://shop.example/reset?token=9f2c41 tells every third-party image, font and analytics host a secret. The fragment and any user:password@ part are never sent; the path and query string can be. A referrer policy decides how much goes out, here for a request from that reset page:
| Policy | To same origin | To another HTTPS origin | To an HTTP URL |
|---|---|---|---|
| no-referrer | Nothing | Nothing | Nothing |
| no-referrer-when-downgrade | Full URL | Full URL | Nothing |
| origin | Origin only | Origin only | Origin only |
| origin-when-cross-origin | Full URL | Origin only | Origin only |
| same-origin | Full URL | Nothing | Nothing |
| strict-origin | Origin only | Origin only | Nothing |
| strict-origin-when-cross-origin (default) | Full URL | Origin only | Nothing |
| unsafe-url | Full URL | Full URL | Full URL |
With no policy, browsers apply strict-origin-when-cross-origin. Until Chrome 85 1 switched in August 2020, the common default was no-referrer-when-downgrade, which sent full URLs, query strings included, to every HTTPS site; many older tutorials still describe that behavior.
You can set a policy with the Referrer-Policy response header, a <meta name="referrer"> tag, the referrerpolicy attribute on <a>, <area>, <img>, <iframe>, <link> and <script>, the rel="noreferrer" link type, or fetch()'s referrerPolicy option. The most specific setting wins.
<!-- Document-wide; the header "Referrer-Policy: same-origin" does the same -->
<meta name="referrer" content="same-origin">
<!-- A partner's pixel may learn which site, but not which page -->
<img src="https://stats.partner.example/p.gif" referrerpolicy="strict-origin" alt="">
<!-- rel="noreferrer" omits Referer and also implies noopener -->
<a href="https://forum.example/thread/88" target="_blank" rel="noreferrer">Discuss</a>The header alone accepts comma-separated fallbacks with the preferred policy last, because the browser applies the last value it understands; attributes and <meta> take one value.
Pitfalls: some payment callbacks and hotlink filters check Referer, so no-referrer can break an embedded widget. And never treat Referer as proof of origin: extensions and proxies strip it, and any non-browser client can forge it.