Referrer-Policy Generator
The Referer header tells other websites which page a visitor came from, and can reveal paths, search terms and even tokens in your URLs. Pick one of the eight policies and the generator shows, for an example address on your site, exactly what would be sent to your own pages, to other HTTPS sites and to plain HTTP sites, before giving you the configuration.
- Runs in your browser
- No sign-up
- Free to use
How to use Referrer-Policy Generator
- Choose a policy.
- Enter a typical address from your site, ideally one with a query string.
- Compare what each kind of request would receive.
- Copy the header, the meta tag or the server configuration.
Referrer-Policy Generator features
All eight policies
From no-referrer to unsafe-url, each explained.
Live preview
The exact Referer value for three kinds of destination.
Leak detection
Warns when tokens or personal data in URLs would be sent to other sites.
Meta tag
The correct <meta name="referrer"> form for pages you cannot add headers to.
Server output
Apache, Nginx, IIS, static hosts, Express and PHP.
Private
Your example address is processed only in the browser.
When to use Referrer-Policy Generator
- Stopping order numbers or reset tokens in URLs from leaking to third parties.
- Keeping analytics working for your own site while hiding paths from others.
- Choosing a policy for an intranet or admin area.
- Answering a security scan that reports a missing Referrer-Policy.
Referrer-Policy Generator FAQ
Why is it “Referer” in the header but “Referrer” in the policy?
The header name was misspelled in the original HTTP specification and kept for compatibility. The newer Referrer-Policy header uses the correct spelling.
Which policy should I use?
strict-origin-when-cross-origin is a good default: full addresses within your site, only the domain for other sites, nothing to insecure sites. Use no-referrer or same-origin for areas with sensitive URLs.
Will this break analytics?
Your own analytics sees full addresses with strict-origin-when-cross-origin. Other sites only learn the domain the visit came from, which is usually all referral reports need.
Is the fragment (#…) ever sent?
No. Fragments, user names and passwords in URLs are never part of the Referer header.
Can I set a policy for one link?
Yes, with the referrerpolicy attribute on a, img, script, iframe and link elements, or rel="noreferrer" on links.
What happens without any policy?
Current browsers apply strict-origin-when-cross-origin by default. Setting it explicitly protects visitors using older browsers and documents the choice.
What the Referer header reveals
When a visitor follows a link, loads an image or submits a form, the browser normally tells the destination which page the request came from in the Referer header. That is how analytics tools build referral reports and how some sites protect against hotlinking. It also means the destination learns the address of the page, which can include more than intended.
Addresses often carry information. A path can reveal a medical topic someone was reading, a query string can contain a search term, an e-mail address or an order number, and badly designed sites put password-reset or session tokens in URLs. With a permissive policy, all of that goes to every embedded script, image host and outbound link on the page.
Referrer-Policy limits what is sent. The policies differ along three lines: whether the full address or only the origin is sent, whether requests to your own origin are treated differently from cross-origin ones, and whether anything is sent when moving from HTTPS to plain HTTP. The preview table on this page applies the rules to your own example address, so you can see the difference instead of reading definitions.
Browsers changed their default in 2020 from no-referrer-when-downgrade to strict-origin-when-cross-origin, which already removes paths and query strings from cross-site requests. Setting the header explicitly still helps: it protects users of older browsers, satisfies security scanners, and allows stricter choices such as same-origin for account areas or no-referrer for admin panels.
The policy can be set as an HTTP header for the whole site, with a meta tag in the page head, or per element with the referrerpolicy attribute. A stricter value on a single link always wins for that request. Remember that the policy only controls the Referer header; it does not stop the destination from seeing the visitor’s IP address or other information sent with every request.