referrerpolicy

When a page loads an image, runs a fetch or follows a link, the browser may add a Referer request header naming the page the request came from. (The misspelling dates from the original HTTP specification; the newer Referrer-Policy header and referrerpolicy attribute are spelled correctly.) Servers use it for analytics and hotlink protection, but it also leaks: https://shop.example/reset?token=9f2c41 tells every third-party image, font and analytics host a secret. The fragment and any user:password@ part are never sent; the path and query string can be. A referrer policy decides how much goes out, here for a request from that reset page:

What each referrer policy sends ("origin only" is https://shop.example/)
Policy To same origin To another HTTPS origin To an HTTP URL
no-referrer Nothing Nothing Nothing
no-referrer-when-downgrade Full URL Full URL Nothing
origin Origin only Origin only Origin only
origin-when-cross-origin Full URL Origin only Origin only
same-origin Full URL Nothing Nothing
strict-origin Origin only Origin only Nothing
strict-origin-when-cross-origin (default) Full URL Origin only Nothing
unsafe-url Full URL Full URL Full URL

With no policy, browsers apply strict-origin-when-cross-origin. Until Chrome 85 1 switched in August 2020, the common default was no-referrer-when-downgrade, which sent full URLs, query strings included, to every HTTPS site; many older tutorials still describe that behavior.

You can set a policy with the Referrer-Policy response header, a <meta name="referrer"> tag, the referrerpolicy attribute on <a>, <area>, <img>, <iframe>, <link> and <script>, the rel="noreferrer" link type, or fetch()'s referrerPolicy option. The most specific setting wins.

Referrer policies at document and element levelHTMLLive
<!-- Document-wide; the header "Referrer-Policy: same-origin" does the same -->
<meta name="referrer" content="same-origin">
<!-- A partner's pixel may learn which site, but not which page -->
<img src="https://stats.partner.example/p.gif" referrerpolicy="strict-origin" alt="">
<!-- rel="noreferrer" omits Referer and also implies noopener -->
<a href="https://forum.example/thread/88" target="_blank" rel="noreferrer">Discuss</a>

The header alone accepts comma-separated fallbacks with the preferred policy last, because the browser applies the last value it understands; attributes and <meta> take one value.

Pitfalls: some payment callbacks and hotlink filters check Referer, so no-referrer can break an embedded widget. And never treat Referer as proof of origin: extensions and proxies strip it, and any non-browser client can forge it.