Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

HTTP_REFERER is the misspelled standard name of an HTTP request header that tells a server which URI context led to the current request. Depending on browser policy, it may contain the referring page’s origin, path and query string—or only the origin, or nothing at all. It is useful for analytics and diagnostics, but it is not a reliable identity credential or authorization proof.

What the HTTP Referer header means

The header field is spelled Referer, although “referrer” is the correct English spelling. It is defined as a request header: the user agent sends a URI reference for the resource from which the target URI was obtained. Servers commonly use it for traffic attribution, link diagnostics, logging, caching decisions and finding obsolete links.

The related response header is spelled Referrer-Policy. The different spellings are intentional standards terminology: use Referer when reading the request and Referrer-Policy when controlling what browsers disclose.

What information can be in Referer?

A Referer value can be a complete URL, an origin, or be absent. A complete value can include the scheme, host, port, path and query string. It cannot include a URL fragment (the part after #) or username/password information. Browsers can also truncate or omit information according to policy, privacy settings, redirects, extensions or intermediary behavior.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For example, a request generated from https://shop.example/account/orders?customer=42 might include:

Referer: https://shop.example/account/orders?customer=42

Under a stricter policy, the same cross-origin request could send only:

Referer: https://shop.example

Putting secrets, access tokens, personal data or confidential identifiers in URLs is therefore risky: a path or query string can be disclosed to another origin, logged by infrastructure or retained in analytics systems.

Rank #2
Sale
HTML and CSS: Design and Build Websites
  • HTML CSS Design and Build Web Sites
  • Comes with secure packaging
  • It can be a gift option

How Referrer-Policy controls disclosure

Site operators normally set an HTTP response header:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Referrer-Policy: strict-origin-when-cross-origin

HTML can provide a site-wide fallback or a targeted override with a <meta> element or an element’s referrerpolicy attribute. The HTTP response header is the primary control because it applies before subsequent page requests are made.

Policy Same-origin requests Cross-origin requests HTTPS page to HTTP destination
no-referrer No Referer No Referer None
same-origin Full URL No Referer No cross-origin Referer
strict-origin Origin only Origin only None
strict-origin-when-cross-origin Full URL Origin only None
unsafe-url Full URL Full URL Full URL

When no valid policy is supplied, MDN documents strict-origin-when-cross-origin as the browser default. That default preserves the full URL for same-origin navigation, but sends only the origin to another origin and suppresses the header when moving from HTTPS to HTTP.

Choosing a policy

  • Use no-referrer when referral context is unnecessary and maximum suppression is preferred.
  • Use same-origin when internal analytics need full URLs but external sites should receive nothing.
  • Use strict-origin when destinations need origin-level attribution without paths or queries.
  • Use strict-origin-when-cross-origin when you want the modern default balance between internal diagnostics and cross-origin privacy.
  • Avoid unsafe-url unless full cross-origin URL disclosure is an explicit, understood requirement; it can expose private URL data to insecure destinations.

Browser and protocol safeguards

Under RFC 9110 §10.1.3, a user agent must not include fragments or userinfo in Referer. It must not send the header in an unsecured HTTP request when the referring resource was accessed securely. These rules limit accidental disclosure, but they do not make URL paths and query strings private.

Requests may also lack Referer because a user navigated directly, a policy suppressed it, a privacy feature removed it, a redirect changed the context, or an intermediary deleted it. Conversely, the value is context supplied by a client and should not be treated as proof that a navigation actually occurred.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can Referer be trusted for security?

No—not by itself. Do not use a present Referer as the sole authorization check, and do not treat its absence as proof of a malicious request. RFC 9110 notes that some sites use the field in CSRF defenses, but intermediaries can remove it and legitimate requests can omit it.

Rank #4
Sale
Web Design with HTML, CSS, JavaScript and jQuery Set
  • Brand: Wiley
  • Set of 2 Volumes
  • A handy two-book set that uniquely combines related technologies Highly visual format and accessible language makes these books highly effective learning tools Perfect for beginning web designers and front-end developers

CSRF protection

Use an established CSRF defense such as a server-validated anti-CSRF token, with appropriate cookie settings such as SameSite. Referer (and, where applicable, the related Origin request header) can be supplementary signals, but a missing value must not break legitimate clients unless your threat model and fallback behavior have been carefully designed.

Access control and authentication

Enforce permissions with authenticated sessions, access tokens and server-side authorization. A Referer value does not establish who made the request, what they are allowed to access, or whether the value was preserved unchanged across proxies.

Practical configuration examples

HTTP response header

HTTP/1.1 200 OK
Referrer-Policy: strict-origin-when-cross-origin
Content-Type: text/html

HTML document fallback

<meta name="referrer" content="strict-origin-when-cross-origin">

Per-element control

<a href="https://partner.example/report"
   referrerpolicy="no-referrer">Open report</a>

Apply the broad policy at the HTTP layer, then use a more restrictive element-level setting for links, images, frames or requests that need additional privacy.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to interpret a Referer value safely

  1. Parse it as untrusted input and validate its syntax before logging or displaying it.
  2. Expect it to be missing, shortened to an origin, or altered by browser and network privacy controls.
  3. When matching an internal source, compare a normalized scheme, host and port rather than trusting arbitrary text.
  4. Never echo the value into HTML, scripts or headers without context-appropriate output encoding.
  5. Remove or protect sensitive query parameters in your own URLs, since policy cannot guarantee that every client or intermediary will suppress them.

Common misunderstandings

“Referer always contains the previous page.”

It may be absent, reduced to an origin, or removed in transit. A direct visit has no referring page to report.

“The header is called Referrer.”

The request field’s standardized spelling is Referer. Referrer-Policy is the correctly spelled control header.

“A full Referer proves the request came from my site.”

It is only client-supplied context and is not an authorization credential. Use server-side authentication and authorization instead.

“HTTPS prevents URL leakage.”

HTTPS protects transport between the browser and an HTTPS server, but a page’s path or query can still be sent to another origin when policy permits it and can be recorded by the receiving server.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Bottom Line

Use Referer as optional context for analytics and troubleshooting, control it with a deliberate Referrer-Policy, keep secrets out of URLs, and never rely on it alone for CSRF defense, authentication or access control.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.