Referrer-Policy Builder

Pick a Referrer-Policy value with a description of what it does.

Default in modern browsers. Recommended.
Referrer-Policy: strict-origin-when-cross-origin

All values

ValueDescription
no-referrerNever send Referer.
no-referrer-when-downgradeDon't send when HTTPS → HTTP.
originSend only origin.
origin-when-cross-originOrigin for cross-origin, full URL for same-origin.
same-originOnly on same-origin.
strict-originOrigin only, and not on HTTPS → HTTP.
strict-origin-when-cross-originDefault in modern browsers. Recommended.
unsafe-urlAlways full URL (not recommended).

About this tool

All eight standard Referrer-Policy values with one-line explanations and recommended defaults.

An unhandled error has occurred. Reload ×