headers by 0x6a03448f4d
← All headers
Privacy

Referrer-Policy

Don't leak URLs to third parties.

What it is

Controls how much of the current URL is sent in the Referer header when the user navigates or loads a resource.

Why it matters

URLs often contain tokens, IDs or private paths you don't want leaking to analytics, ads or external links.

Risk without it

A permissive policy (or the browser default) can send full URLs — including query strings — to any third party you link to or load resources from.

Recommended

strict-origin-when-cross-origin (a good default) or no-referrer (maximum privacy).

Set it

add_header Referrer-Policy "strict-origin-when-cross-origin" always;

References