Referrer-Policy header

Baseline Widely available *

This feature is well established and works across many devices and browser versions. It’s been available across browsers since January 2020.

* Some parts of this feature may have varying levels of support.

The HTTP Referrer-Policy response header controls how much referrer information (sent with the Referer header) should be included with requests. Aside from the HTTP header, you can set this policy in HTML.

Header type Response header

Syntax

http
Referrer-Policy: no-referrer
Referrer-Policy: no-referrer-when-downgrade
Referrer-Policy: origin
Referrer-Policy: origin-when-cross-origin
Referrer-Policy: same-origin
Referrer-Policy: strict-origin
Referrer-Policy: strict-origin-when-cross-origin
Referrer-Policy: unsafe-url

Note: The header name Referer is a misspelling of the word "referrer". The Referrer-Policy header does not share this misspelling.

Directives

no-referrer

The Referer header will be omitted: sent requests do not include any referrer information.

no-referrer-when-downgrade

Send the origin, path, and query string in Referer when the protocol security level stays the same or improves (HTTP→HTTP, HTTP→HTTPS, HTTPS→HTTPS). Don't send the Referer header for requests to less secure destinations (HTTPS→HTTP, HTTPS→file).

origin

Send only the origin in the Referer header. For example, a document at https://example.com/page.html will send the referrer https://example.com/.

origin-when-cross-origin

When performing a same-origin request, send the origin, path, and query string. Send only the origin for cross origin requests and requests to less secure destinations (HTTPS→HTTP).

same-origin

Send the origin, path, and query string for same-origin requests. Don't send the Referer header for cross-origin requests.

strict-origin

Send only the origin when the protocol security level stays the same (HTTPS→HTTPS). Don't send the Referer header to less secure destinations (HTTPS→HTTP).

strict-origin-when-cross-origin (default)

Send the origin, path, and query string when performing a same-origin request. For cross-origin requests send the origin (only) when the protocol security level stays same (HTTPS→HTTPS). Don't send the Referer header to less secure destinations (HTTPS→HTTP).

Note: This is the default policy if no policy is specified, or if the provided value is invalid (see spec revision November 2020). Previously the default was no-referrer-when-downgrade.

unsafe-url

Send the origin, path, and query string when performing any request, regardless of security.

Warning: This policy will leak potentially-private information from HTTPS resource URLs to insecure origins. Carefully consider the impact of this setting.

Integration with HTML

You can also set referrer policies inside HTML. For example, you can set the referrer policy for the entire document with a <meta> element with a name of referrer:

html
<meta name="referrer" content="origin" />

You can specify the referrerpolicy attribute on <a>, <area>, <img>, <iframe>, <script>, or <link> elements to set referrer policies for individual requests:

html
<a href="http://example.com" referrerpolicy="origin">…</a>

Alternatively, you can set a noreferrer link relation on an a, area, or link elements:

html
<a href="http://example.com" rel="noreferrer">…</a>

Warning: As seen above, the noreferrer link relation is written without a dash. When you specify the referrer policy for the entire document with a <meta> element, it should be written with a dash: <meta name="referrer" content="no-referrer">.

Integration with CSS

CSS can fetch resources referenced from stylesheets. These resources follow a referrer policy as well:

  • External CSS stylesheets use the default policy (strict-origin-when-cross-origin), unless it's overwritten by a Referrer-Policy HTTP header on the CSS stylesheet's response.
  • For <style> elements or style attributes, the owner document's referrer policy is used.

Examples

no-referrer

From document Navigation to Referrer used
https://example.com/page anywhere (no referrer)

no-referrer-when-downgrade

From document Navigation to Referrer used
https://example.com/page https://example.com/otherpage https://example.com/page
https://example.com/page https://mozilla.org https://example.com/page
https://example.com/page http://example.com (no referrer)
http://example.com/page anywhere http://example.com/page

origin

From document Navigation to Referrer used
https://example.com/page anywhere https://example.com/

origin-when-cross-origin

From document Navigation to Referrer used
https://example.com/page https://example.com/otherpage https://example.com/page
https://example.com/page https://mozilla.org https://example.com/
https://example.com/page http://example.com/page https://example.com/

same-origin

From document Navigation to Referrer used
https://example.com/page https://example.com/otherpage https://example.com/page
https://example.com/page https://mozilla.org (no referrer)

strict-origin

From document Navigation to Referrer used
https://example.com/page https://mozilla.org https://example.com/
https://example.com/page http://example.com (no referrer)
http://example.com/page anywhere http://example.com/

strict-origin-when-cross-origin

From document Navigation to Referrer used
https://example.com/page https://example.com/otherpage https://example.com/page
https://example.com/page https://mozilla.org https://example.com/
https://example.com/page http://example.com (no referrer)

unsafe-url

From document Navigation to Referrer used
https://example.com/page?q=123 anywhere https://example.com/page?q=123

Specify a fallback policy

If you want to specify a fallback policy in case the desired policy hasn't got wide enough browser support, use a comma-separated list with the desired policy specified last:

http
Referrer-Policy: no-referrer, strict-origin-when-cross-origin

In the above scenario, no-referrer is used only if the browser does not support the strict-origin-when-cross-origin policy.

Note: Specifying multiple values is only supported in the Referrer-Policy HTTP header, and not in the referrerpolicy attribute.

Browser-specific preferences/settings

Firefox preferences

You can configure the default referrer policy in Firefox preferences. The preference names are version specific:

  • Firefox version 59 and later: network.http.referer.defaultPolicy (and network.http.referer.defaultPolicy.pbmode for private networks)
  • Firefox versions 53 to 58: network.http.referer.userControlPolicy

All of these settings take the same set of values: 0 = no-referrer, 1 = same-origin, 2 = strict-origin-when-cross-origin, 3 = no-referrer-when-downgrade.

Specifications

Specification
Referrer Policy
# referrer-policy-header

Browser compatibility

desktop mobile
Chrome
Edge
Firefox
Opera
Safari
Chrome Android
Firefox for Android
Opera Android
Safari on iOS
Samsung Internet
WebView Android
WebView on iOS
Referrer-Policy
Chrome – Full support
Chrome 56 (Release date: 2017-01-25)
footnote Full support
Edge – Full support
Edge 79 (Release date: 2020-01-15)
footnote Full support
Firefox – Full support
Firefox 50 (Release date: 2016-11-15)
footnote Full support
Opera – Full support
Opera 43 (Release date: 2017-02-07)
footnote Full support
Safari – Full support
Safari 11.1 (Release date: 2018-04-12)
footnote Full support
Chrome Android – Full support
Chrome Android 56 (Release date: 2017-02-01)
footnote Full support
Firefox for Android – Full support
Firefox for Android 50 (Release date: 2016-11-15)
footnote Full support
Opera Android – Full support
Opera Android 43 (Release date: 2017-09-27)
footnote Full support
Safari on iOS – Full support
Safari on iOS 12 (Release date: 2018-09-17)
footnote Full support
Samsung Internet – Full support
Samsung Internet 7.2 (Release date: 2018-06-20)
footnote Full support
WebView Android – Full support
WebView Android 56 (Release date: 2017-02-01)
footnote Full support
WebView on iOS – Full support
WebView on iOS 12 (Release date: 2018-09-17)
footnote Full support
Default policy is strict-origin-when-cross-origin
Chrome – Full support
Chrome 85 (Release date: 2020-08-25)
footnote Full support
Edge – Full support
Edge 85 (Release date: 2020-08-27)
footnote Full support
Firefox – Full support
Firefox 87 (Release date: 2021-03-23)
footnote Full support
Opera – Full support
Opera 71 (Release date: 2020-09-15)
footnote Full support
Safari – Full support
Safari 15 (Release date: 2021-09-20)
footnote Full support
Chrome Android – Full support
Chrome Android 85 (Release date: 2020-08-25)
footnote Full support
Firefox for Android – Full support
Firefox for Android 87 (Release date: 2021-03-23)
footnote Full support
Opera Android – Full support
Opera Android 60 (Release date: 2020-09-23)
footnote Full support
Safari on iOS – Full support
Safari on iOS 15 (Release date: 2021-09-20)
footnote Full support
Samsung Internet – Full support
Samsung Internet 14 (Release date: 2021-04-17)
footnote Full support
WebView Android – Full support
WebView Android 85 (Release date: 2020-08-25)
footnote Full support
WebView on iOS – Full support
WebView on iOS 15 (Release date: 2021-09-20)
footnote Full support
no-referrer-when-downgrade
Chrome – Full support
Chrome 56 (Release date: 2017-01-25)
footnote Full support
Edge – Full support
Edge 79 (Release date: 2020-01-15)
footnote Full support
Firefox – No support
Firefox 50 – 91 (Release date: 2016-11-15)
footnote Removed in 92 and later
Opera – Full support
Opera 43 (Release date: 2017-02-07)
footnote Full support
Safari – No support
Safari 11.1 – 12.1 (Release date: 2018-04-12)
footnote Removed in 13 and later
Chrome Android – Full support
Chrome Android 56 (Release date: 2017-02-01)
footnote Full support
Firefox for Android – No support
Firefox for Android 50 – 91 (Release date: 2016-11-15)
footnote Removed in 92 and later
Opera Android – Full support
Opera Android 43 (Release date: 2017-09-27)
footnote Full support
Safari on iOS – No support
Safari on iOS 12 – 12.2 (Release date: 2018-09-17)
footnote Removed in 13 and later
Samsung Internet – Full support
Samsung Internet 7.2 (Release date: 2018-06-20)
footnote Full support
WebView Android – Full support
WebView Android 56 (Release date: 2017-02-01)
footnote Full support
WebView on iOS – No support
WebView on iOS 12 – 12.2 (Release date: 2018-09-17)
footnote Removed in 13 and later
origin-when-cross-origin
Chrome – Full support
Chrome 56 (Release date: 2017-01-25)
footnote Full support
Edge – Full support
Edge 79 (Release date: 2020-01-15)
footnote Full support
Firefox – No support
Firefox 50 – 91 (Release date: 2016-11-15)
footnote Removed in 92 and later
Opera – Full support
Opera 43 (Release date: 2017-02-07)
footnote Full support
Safari – No support
Safari 11.1 – 12.1 (Release date: 2018-04-12)
footnote Removed in 13 and later
Chrome Android – Full support
Chrome Android 56 (Release date: 2017-02-01)
footnote Full support
Firefox for Android – No support
Firefox for Android 50 – 91 (Release date: 2016-11-15)
footnote Removed in 92 and later
Opera Android – Full support
Opera Android 43 (Release date: 2017-09-27)
footnote Full support
Safari on iOS – No support
Safari on iOS 12 – 12.2 (Release date: 2018-09-17)
footnote Removed in 13 and later
Samsung Internet – Full support
Samsung Internet 7.2 (Release date: 2018-06-20)
footnote Full support
WebView Android – Full support
WebView Android 56 (Release date: 2017-02-01)
footnote Full support
WebView on iOS – No support
WebView on iOS 12 – 12.2 (Release date: 2018-09-17)
footnote Removed in 13 and later
same-origin
Chrome – Full support
Chrome 61 (Release date: 2017-09-05)
footnote Full support
Edge – Full support
Edge 79 (Release date: 2020-01-15)
footnote Full support
Firefox – Full support
Firefox 52 (Release date: 2017-03-07)
footnote Full support
Opera – Full support
Opera 48 (Release date: 2017-09-27)
footnote Full support
Safari – Full support
Safari 11.1 (Release date: 2018-04-12)
footnote Full support
Chrome Android – Full support
Chrome Android 61 (Release date: 2017-09-05)
footnote Full support
Firefox for Android – Full support
Firefox for Android 52 (Release date: 2017-03-07)
footnote Full support
Opera Android – Full support
Opera Android 45 (Release date: 2018-02-15)
footnote Full support
Safari on iOS – Full support
Safari on iOS 12 (Release date: 2018-09-17)
footnote Full support
Samsung Internet – Full support
Samsung Internet 7.2 (Release date: 2018-06-20)
footnote Full support
WebView Android – Full support
WebView Android 61 (Release date: 2017-09-05)
footnote Full support
WebView on iOS – Full support
WebView on iOS 12 (Release date: 2018-09-17)
footnote Full support
strict-origin
Chrome – Full support
Chrome 61 (Release date: 2017-09-05)
footnote Full support
Edge – Full support
Edge 79 (Release date: 2020-01-15)
footnote Full support
Firefox – Full support
Firefox 52 (Release date: 2017-03-07)
footnote Full support
Opera – Full support
Opera 48 (Release date: 2017-09-27)
footnote Full support
Safari – Full support
Safari 11.1 (Release date: 2018-04-12)
footnote Full support
Chrome Android – Full support
Chrome Android 61 (Release date: 2017-09-05)
footnote Full support
Firefox for Android – Full support
Firefox for Android 52 (Release date: 2017-03-07)
footnote Full support
Opera Android – Full support
Opera Android 45 (Release date: 2018-02-15)
footnote Full support
Safari on iOS – Full support
Safari on iOS 12 (Release date: 2018-09-17)
footnote Full support
Samsung Internet – Full support
Samsung Internet 7.2 (Release date: 2018-06-20)
footnote Full support
WebView Android – Full support
WebView Android 61 (Release date: 2017-09-05)
footnote Full support
WebView on iOS – Full support
WebView on iOS 12 (Release date: 2018-09-17)
footnote Full support
strict-origin-when-cross-origin
Chrome – Full support
Chrome 61 (Release date: 2017-09-05)
footnote Full support
Edge – Full support
Edge 79 (Release date: 2020-01-15)
footnote Full support
Firefox – Full support
Firefox 52 (Release date: 2017-03-07)
footnote Full support
Opera – Full support
Opera 48 (Release date: 2017-09-27)
footnote Full support
Safari – Full support
Safari 11.1 (Release date: 2018-04-12)
footnote Full support
Chrome Android – Full support
Chrome Android 61 (Release date: 2017-09-05)
footnote Full support
Firefox for Android – Full support
Firefox for Android 52 (Release date: 2017-03-07)
footnote Full support
Opera Android – Full support
Opera Android 45 (Release date: 2018-02-15)
footnote Full support
Safari on iOS – Full support
Safari on iOS 12 (Release date: 2018-09-17)
footnote Full support
Samsung Internet – Full support
Samsung Internet 7.2 (Release date: 2018-06-20)
footnote Full support
WebView Android – Full support
WebView Android 61 (Release date: 2017-09-05)
footnote Full support
WebView on iOS – Full support
WebView on iOS 12 (Release date: 2018-09-17)
footnote Full support
unsafe-url
Chrome – Full support
Chrome 56 (Release date: 2017-01-25)
footnote Full support
Edge – Full support
Edge 79 (Release date: 2020-01-15)
footnote Full support
Firefox – No support
Firefox 50 – 91 (Release date: 2016-11-15)
footnote Removed in 92 and later
Opera – Full support
Opera 43 (Release date: 2017-02-07)
footnote Full support
Safari – No support
Safari 11.1 – 12.1 (Release date: 2018-04-12)
footnote Removed in 13 and later
Chrome Android – Full support
Chrome Android 56 (Release date: 2017-02-01)
footnote Full support
Firefox for Android – No support
Firefox for Android 50 – 91 (Release date: 2016-11-15)
footnote Removed in 92 and later
Opera Android – Full support
Opera Android 43 (Release date: 2017-09-27)
footnote Full support
Safari on iOS – No support
Safari on iOS 12 – 12.2 (Release date: 2018-09-17)
footnote Removed in 13 and later
Samsung Internet – Full support
Samsung Internet 7.2 (Release date: 2018-06-20)
footnote Full support
WebView Android – Full support
WebView Android 56 (Release date: 2017-02-01)
footnote Full support
WebView on iOS – No support
WebView on iOS 12 – 12.2 (Release date: 2018-09-17)
footnote Removed in 13 and later

Legend

Tip: you can click/tap on a cell for more information.

Full support
Full support

See also