Skip to main content
Common policies include:
  • no-referrer: No referrer data sent.
  • no-referrer-when-downgrade: No data for HTTPS-to-HTTP transitions.
  • origin: Only origin sent.
  • origin-when-cross-origin: Full URL for same-origin, origin for cross-origin.
  • same-origin: Full URL for same-origin only.
  • strict-origin: Origin for same-security transitions.
  • strict-origin-when-cross-origin: Full URL for same-security, origin for cross-origin.
  • unsafe-url: Full URL always.
Default browser policies (e.g., Chrome, Safari) are strict-origin-when-cross-origin. Google does not include keywords in referrers; use Google Search Console. Set your site’s referrer policy with:
<meta name="referrer" content="no-referrer-when-downgrade"/>
Use UTM parameters for links you control to improve traffic source tracking.