security / security headers / referrer-policy
Security headers

Referrer-Policy

Referrer-Policy controls how much information about your pages is shared with other sites when a visitor clicks a link away from you.

Severity if missing
Low
Category
Security headers
Standard
W3C Referrer Policy

What it is

When someone clicks a link from your site to another, the browser normally tells the destination which page they came from — the full URL, including any sensitive parts. The Referrer-Policy header lets you control how much of that information is sent, or whether any is sent at all.

It's a privacy and information-leakage control that keeps your internal URLs from spilling out to third parties.

Why it matters

URLs can contain sensitive details — session tokens, account identifiers, internal paths. Without a Referrer-Policy, all of that can be handed to any external site your users click through to, including analytics and advertising domains. A sensible policy limits what leaks.

The risk
Without a Referrer-Policy, full URLs — sometimes containing sensitive parameters — can leak to any external site your visitors navigate to.

How Pentrawl checks it

Pentrawl checks your response headers for a Referrer-Policy header. Its presence passes the check; its absence is flagged as a low-severity issue.

How to fix it

Add the Referrer-Policy header to your server. The value below shares just enough for analytics to work while protecting the full URL and cross-site privacy.

Recommended
Referrer-Policy: strict-origin-when-cross-origin
Check your domain's Referrer-Policy in seconds
Pentrawl scans this and 20+ other security checks in one automated pass.
Scan your website →