Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A referrer can still tell a cookieless analytics system where a visit came from. What it cannot do on its own is recognize that the same person has returned. Cookies, or another durable identifier, are what connect visits over time, and dropping them changes which conversions can be credited to which earlier source.

This explainer draws on Matomo’s published documentation, accessed 7 October 2026, because it covers referrer capture, referrer privacy, and cookieless reporting in one place. It describes Matomo’s documented behavior and uses it as a worked example. It is not a benchmark for every analytics product.

What a referrer does and does not tell you

A referrer is the address of the page a visitor was on before arriving at yours. Matomo’s HTTP Tracking API accepts an optional urlref parameter, which it describes as the full HTTP Referrer URL and uses to determine how a visitor arrived. Its tracker can also read the browser’s HTTP Referer header to identify a website, search engine, or social network as the source.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That gives you a source for one visit. It does not give you a history. A referrer answers “how did this visit start?” It does not answer “is this the same person who visited last Tuesday?” Keeping those two questions separate prevents most of the confusion that shows up in cookieless reports.

#1 Best Overall

Referrer URLs can carry more personal detail than you need

Matomo warns that referrer URLs may contain identifiers or other information that could identify someone when combined with other data. A cookieless setup removes one identifier, but it does not remove identifiers that already sit inside a URL. Treat the referrer as potentially personal data, whatever your cookie setting.

Matomo offers four levels of control. Choose one deliberately, because each step down reduces precision.

Setting What gets stored What you give up
Do not anonymize The full referrer URL, including query parameters Nothing in diagnosis; highest identification risk
Remove query parameters The referrer URL without its parameters Parameter-level detail, such as which search or share link was used
Keep only the domain The referrer domain Page-level path detail. Matomo notes the subdomain is still kept, and a subdomain can itself contain identifying information
Stop recording the URL A broad source type only, with no URL Most diagnostic precision, but the least identifying data

Matomo also states that campaign information taken from the current URL is not affected by these referrer anonymization settings. Tightening referrer storage does not automatically strip campaign tags from the landing address, so review both.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What happens to attribution without cookies

Matomo’s documentation for cookieless tracking gives the clearest account of the trade-off, and it is worth quoting directly: “When the conversion happens in the same visit, Matomo will be able to credit the website referrer (even if cookies are disabled).”

The limit appears when a visit spans more than one session. Matomo’s example follows a visitor who arrives through a tagged newsletter campaign, leaves without buying, then returns later by typing the address directly and converts.

  • With cookies enabled: the stored visitor identity links the return visit to the earlier newsletter, so the campaign can receive credit for the sale.
  • Without cookies: the earlier campaign information is unavailable, so the conversion is reported as direct traffic.
  • Visitor counts: unique, new, and returning visitor metrics become inaccurate when cookies are disabled.
  • Multi-attribution and cohort reports: these will not show data for cookieless visits, according to Matomo.

This is why a campaign can look weaker than it was in a cookieless report. The newsletter did its job at the first visit, but the system has no way to carry that fact forward.

Attribution rules are choices you must make explicit

Attribution is a rule for deciding which referrer gets credit when a visitor has several. Matomo’s attribution documentation describes three approaches, and each produces a different report from the same data.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rule Which touchpoint receives credit Practical effect
Last non-empty referrer (Matomo default) The most recent referrer recorded before the conversion Favors the closing channel; direct return visits can absorb credit
First referrer (available as a tracker setting) The referrer that started the visit sequence Favors discovery channels; depends on identity persisting between visits
Multi-channel attribution Credit distributed across multiple referrers Shows the path to conversion; needs persistent visitor identity for cross-visit paths

In a cookieless setup, the first-referrer rule and multi-channel attribution cannot reach beyond the current visit for returning visitors. Pick the rule that matches what your cookieless data can actually see, not the one that matches your ideal report.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Tracker controls for building a referrer setup

If you implement Matomo’s JavaScript tracker yourself, three calls control referrer handling and cookie behavior:

  • setReferrerUrl() overrides the detected HTTP referrer. Use it when a redirect or single-page navigation hides the true origin.
  • setExcludedReferrers() tells the tracker to ignore specified hosts or domains, such as your own subdomains or a payment provider that returns visitors to your site.
  • disableCookies() turns off first-party cookies, which is the step that creates the cross-visit limits described above.

Set these before the first tracking call fires, and check the result in a test environment. An override that runs after the page view has already been sent will not change that visit’s recorded referrer.

A practical checklist before you go cookieless

  • Decide which referrer detail you need for diagnosis, then choose the least identifying setting that still provides it.
  • Confirm that campaign parameters on your landing URLs are handled separately from referrer anonymization.
  • Write down which attribution rule your reports use, and tell stakeholders that cookieless visits cannot credit an earlier campaign on a later return.
  • Expect visitor counts and cohort views to be unreliable for cookieless traffic, and label them that way.
  • Do not describe cookieless tracking as anonymous or free of personal data. Referrer URLs can still contain personal information, and the documentation does not settle the legal position in any jurisdiction, so check that with your own advisers.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.