What Is a Referrer? HTTP Referer, Referrer-Policy and Examples

A referrer is the web page a visitor was on right before they clicked through to your page. If someone reads a news article and clicks a link to your shop, that news page is the referrer. The browser sends its address in an HTTP header called Referer, and analytics tools use it to tell you where your traffic came from.
This guide covers how the referrer is built and sent, why it is spelled two ways, how much of it browsers pass along today, when it is missing, how to check it yourself, and how to turn referrer data into conversions and revenue. If you came here for the person who recommends a business, jump to referrer, referral and referee.
What Is a Referrer?
In web terms, the referrer (also called the referring URL or HTTP referrer) is the address of the resource that led to the current request. Most of the time that is the page with the link someone clicked. It also applies to the files a page loads: when your page pulls in an image or a script, the request for that file carries your page as its referrer.
The referrer is generated by the visitor’s browser, not by your site or the linking site’s server. Your server reads it from the incoming request, your access logs record it, and your analytics script reads it from the page. It tells you where a visit came from. It does not tell you who the visitor is.
A simple example:
- A reader is on
https://news.example.com/2026/best-tools. - They click a link to
https://yourshop.com/. - The browser requests your homepage and includes
Referer: https://news.example.com/. Only the domain arrives, because of the default policy explained below. - Your analytics tool records
news.example.comas the source of the visit.
How a Referrer Works
Every time a browser asks a server for a page, it sends a request with a set of headers: which browser it is, which languages it accepts, and, when there is one, where the request came from. That last one is the Referer header. The current HTTP standard, RFC 9110 (section 10.1.3), defines it as the address of the resource from which the requested URL was obtained, and lists its uses: back-links for simple analytics, logging, caching, and finding broken or outdated links. A request looks like this:
GET /pricing HTTP/1.1
Host: yourshop.com
User-Agent: Mozilla/5.0 ...
Referer: https://news.example.com/A few rules from the standard shape what you see:
- The browser must strip the fragment (
#section-3) and anyusername:passwordpart before sending a URL as a referrer. - If the address came from somewhere that has no URL, such as a typed address or a bookmark, the browser either sends no Referer or sends
about:blank. - The browser may trim everything after the origin. Modern browsers do exactly that for cross-site links.
- A browser must not send a referrer from an HTTPS page in a plain HTTP request.
Nothing special has to happen on the linking site. If your site links to another site, that site sees your page as the referrer by default, without any server configuration on your side.
Referer or referrer?
Referrer, with two r’s, is the correct English word, and yes, it is a real word: a person or thing that refers. The HTTP header is spelled Referer because the misspelling made it into the early HTTP specification and could not be fixed without breaking software. RFC 9110 still marks it with “[sic]”. Everything added later uses the correct spelling: the Referrer-Policy header, the document.referrer property and the <meta name="referrer"> tag. Common synonyms are referring URL, referring page, referral source and traffic source, although the last two are analytics groupings rather than the raw value.
Three Places You See the Referrer
| Where | What it is | Who reads it |
|---|---|---|
| Referer request header | The value the browser sends with each request | Your web server, CDN and access logs |
| document.referrer (sometimes searched as window referrer) | A read-only JavaScript string with the same value for the current page; an empty string when there is none | Analytics tags, tag managers, your own scripts |
| Analytics dimensions | A processed version: source, referring domain, page referrer, channel | You, in reports |
Two details matter in practice. document.referrer cannot be edited by your scripts, so tags that need a different value must override it in the analytics call itself (Adobe Analytics, for example, has an s.referrer variable for this). Inside an iframe, document.referrer holds the parent page’s address, or only its origin when the iframe comes from a different site.
Referrer URL vs Referring Domain
| Term | Example | Typical use |
|---|---|---|
| Referrer URL (full) | https://news.example.com/2026/best-tools?ref=nav | Debugging one journey; rare today for cross-site visits |
| Referrer origin | https://news.example.com/ | What most cross-site visits now carry |
| Referring domain | news.example.com | Analytics source reports; SEO tools counting linking sites |
| Referral source / channel | Referral, Organic Search, Organic Social | Channel reports built from referrer plus tags |
Referrer-Policy: How Much Gets Sent
The page that holds the link decides how much of its address leaves with the click. It does so with a Referrer-Policy, set as an HTTP response header, a <meta name="referrer"> tag, a referrerpolicy attribute on a single link, or rel="noreferrer". According to the MDN Referrer-Policy reference, when a page sets nothing, browsers use strict-origin-when-cross-origin. The older default, no-referrer-when-downgrade, sent full URLs, which is why older articles and old reports show complete referring pages. The eight possible values:
| Policy | Link to your own site | Link to another site | HTTPS to HTTP |
|---|---|---|---|
| no-referrer | Nothing | Nothing | Nothing |
| no-referrer-when-downgrade | Full URL | Full URL | Nothing |
| origin | Origin | Origin | Origin |
| origin-when-cross-origin | Full URL | Origin | Origin |
| same-origin | Full URL | Nothing | Nothing |
| strict-origin | Origin | Origin | Nothing |
| strict-origin-when-cross-origin (default) | Full URL | Origin | Nothing |
| unsafe-url | Full URL | Full URL | Full URL |
The practical result: for visits from other sites, you almost always get the domain and not the page. You cannot change that from your side, because the policy belongs to the page that sent the visitor.
Which Referrer-Policy Should Your Site Use?
Your own policy controls what other sites learn about your pages when visitors leave. Most guides list the values and stop. Here is a decision rule:
| Your situation | Use | Why |
|---|---|---|
| A normal marketing site or store | strict-origin-when-cross-origin, set explicitly | Partners still see your domain as the source; paths and query strings stay private |
| Pages with secrets in the URL: password reset links, order or invoice IDs, internal search with emails | no-referrer on those pages | Any third-party image, script or outbound link on the page would otherwise receive the URL |
| An affiliate or partner program that needs the exact page that sent the click | Tag the links with UTM or partner IDs instead | Tags survive every policy; unsafe-url leaks every path on HTTP too |
| A site that wants destinations to credit it at all | Avoid no-referrer site-wide | Every click you send would show up as Direct on the other side |
noreferrer vs noopener: The Link Attribute That Hides You
A common source of missing referrers is a link attribute added for security. When a link opens in a new tab, the new page used to get a handle on the old one (window.opener). The fix is rel="noopener". Many CMSs and linters add rel="noopener noreferrer" instead, and noreferrer also removes the Referer header entirely. It even implies noopener on its own.
So if you link out with noreferrer, the sites you send visitors to record them as Direct. If you run a partnership, ask partners to check their link markup before you argue about numbers. If you want credit for traffic you send, noopener alone handles the security issue, and modern browsers already apply noopener behavior to target="_blank" links by default.
When There Is No Referrer
An empty referrer is normal. It happens when:
- The visitor typed the address, used a bookmark or opened a saved tab.
- The link was clicked inside an app, an email client, a PDF or a chat. In-app browsers often send little or nothing.
- The source page set
no-referreror the link carriedrel="noreferrer". - The click went from an HTTPS page to an HTTP page.
- A redirect chain dropped or replaced the value, or a privacy extension or proxy stripped it.
- An AI assistant opened the link in a way that sends no referrer.
All of these land in Direct. That is why Direct should be read as “no referrer available,” not “people who know our URL.” Links shared in messaging apps (often called dark social) are a large part of it.
Types of Referrers in Analytics
Analytics tools sort referrers into groups so you can compare them:
- Search engines: google.com, bing.com, duckduckgo.com. The referrer shows the engine but not the keyword.
- Social networks: facebook.com, linkedin.com, reddit.com, often via short redirect domains such as t.co or l.facebook.com.
- Websites: blogs, news sites, directories, review sites and partners that link to you.
- AI assistants: chatgpt.com, perplexity.ai and others, when they pass a referrer. See AI traffic analytics for how to separate them.
- Campaigns: any link with UTM tags, which most tools group by tag instead of by referrer.
- Direct: not a referrer type at all, but the bucket for visits without one.
How Google Analytics turns these into channels such as Referral, Organic Social or Organic Search is covered in what is referral traffic.
Referrers vs UTM tags and click IDs
UTM parameters live in the landing page URL, so they survive when the referrer is stripped. When both exist, analytics tools generally trust the tags. Use them on anything you control: emails, social posts, QR codes, partner links. Paid ads are a special case: clicks pass through the ad platform’s redirect, so the referrer describes the redirect, and the click ID added by auto-tagging (such as gclid) is what ties the visit to a campaign.
Referrers That Are Not Traffic Sources
Some referrers show up in reports but did not send you anyone new:
- Payment pages: a buyer returns from PayPal or Stripe checkout, and the payment domain becomes the referrer of the thank-you page, stealing credit for the sale.
- Login and SSO screens: accounts.google.com or your identity provider after a sign-in.
- Your own domains: a subdomain, a separate checkout domain or a tag that loads on one domain but not the other (self-referrals).
- Your own tools: clicks from project boards, CMS previews and internal dashboards.
Exclude these in your analytics settings (GA4 calls it “List unwanted referrals”) and filter internal traffic. Where a redirect or payment step loses the real referrer, some tools let you pass the original value manually, like Adobe’s s.referrer.
Can a Referrer Be Faked?
Yes. Any script, bot or command-line tool can send whatever Referer it likes, and browsers can be told to send none. Two consequences:
- Referrer spam: bots send hits with fake referring domains so the site name shows up in your reports and someone visits it. Watch for new, irrelevant domains with zero engagement and zero conversions, then filter them.
- Not a security control: RFC 9110 notes that some servers use the header to block deep links or cross-site request forgery, but not all requests contain it. Use signed URLs, tokens and SameSite cookies for anything that matters.
How to Check a Referrer Yourself
To see what referrer a page actually received:
- Browser DevTools: click the link you want to test, press F12, open the Network tab, reload, click the first document request and look for
Refererunder Request Headers. Check the source page’s response headers forReferrer-Policytoo. - Console: on the landing page, type
document.referrerand press Enter. An empty string means no referrer. - Server logs: the common “combined” access log format includes the Referer for every request.
- Analytics: in GA4, add the Page referrer dimension to an exploration to see the value sent with each page view.
Referrers on Single-Page Apps
On sites built as single-page apps (React, Vue, Next.js with client routing), the browser loads one document and then swaps screens with the History API. document.referrer is set once, at that first load. If the visitor arrived from Google and then clicked through four screens, document.referrer still says google.com on the fourth screen.
That breaks page-level referrer reports unless your analytics updates the referrer for each virtual page view. Google’s guide to measuring single-page applications says the key is to send a page view for each screen and get the page referrer right, and to check that both page referrer and page location update. It also warns against enabling GA4’s automatic history tracking when Google Tag Manager already sends those page views, which double-counts them. If your Page referrer report shows an external site as the referrer of deep internal pages, this is the likely cause.
From Referrer to Revenue: A Worked Example
A referrer tells you where visits came from. The useful question is which referrers bring buyers. Here is an illustrative example for a B2B site where a demo request is the conversion.
First, put a value on the conversion (illustrative numbers):
Then compare two referring domains over one month:
| Referring domain | Sessions | Demo requests | Value | Value per session |
|---|---|---|---|---|
| blog-a.example | 400 | 8 | 8 × $120 = $960 | $960 ÷ 400 = $2.40 |
| directory-b.example | 150 | 9 | 9 × $120 = $1,080 | $1,080 ÷ 150 = $7.20 |
The blog sends more than twice the visits, but each directory visit is worth three times as much ($7.20 vs $2.40). A visits-only report would rank them the other way round.
Because cross-site referrers arrive as a domain only, you do not know which blog-a article linked to you. Join the referring domain with the landing page: if 320 of the 400 sessions landed on your pricing comparison page and 7 of the 8 demo requests came from them, the link is almost certainly on blog-a’s article about that topic. Find it with a site search on their domain, then ask for a tagged link so the next report shows the exact page.
Referrer, Referral and Referee: The People Meaning
Outside web analytics, a referrer is a person who recommends someone or sends them elsewhere. In a customer referral or loyalty program, the referrer shares a link or code, a friend uses it, and both often get a reward once the friend signs up or buys.
| Word | Who or what | Example |
|---|---|---|
| Referrer | The person or page that recommends or sends | A customer sharing a discount code; a doctor sending you to a specialist; a news page linking to you |
| Referral | The recommendation, or the visit it produces | Getting a referral to a cardiologist; a visit from another website |
| Referee | The person who is referred | The friend who signs up with the code |
The two meanings meet in referral programs: a unique referral link carries a code in its URL, so the program credits the right referrer even when the browser sends no Referer header.
Where Definitions Disagree
- Is “direct” a type of referrer? Some glossaries and AI answers list Direct as a referrer category. Strictly, it is the absence of one: the browser sent nothing (or
about:blank, which RFC 9110 allows for typed addresses and bookmarks). Treat it as unknown, not as a source. - Are campaigns referrers? One glossary groups tagged links as a kind of referrer. In practice the tag, not the referrer, decides the source, and the tagged visit may have no referrer at all.
- Full URL or domain? Older articles describe the referrer as the full previous URL. That was true before the default changed. Today you get the full URL only for links within your own site or when the source page opts in.
FAQ
What is a URL referrer?
A URL referrer is the address of the page that sent a visitor to the current page. The browser passes it in the Referer request header, and scripts can read it from document.referrer. Since browsers now trim cross-site referrers by default, you usually see only the referring domain, such as https://news.example.com/, not the exact article.
What is my referer?
There is no single referer attached to you. It is set per request: each time you click a link, your browser decides what to send based on the page you came from and its Referrer-Policy. To see it, open DevTools, go to the Network tab, click the page request and look for Referer under Request Headers, or type document.referrer in the console.
Who is the referral person?
In a referral program the person who recommends a business is the referrer, the person who is recommended and signs up is the referee, and the recommendation itself is the referral. In healthcare and hiring the same pattern holds: the doctor or contact who makes the referral is the referrer.
What does it mean if you get a referral?
It means someone recommended you or sent you to someone else, for example a doctor sending you to a specialist or a friend sharing a sign-up link. On a website, a referral is a visit that arrived by clicking a link on another site, and the site that sent it is the referrer.
Is it referrer or referer?
Both appear, in different places. Referrer is the correct English spelling and is used in Referrer-Policy, document.referrer and the referrer meta tag. Referer, with one r, is only the name of the HTTP request header, a misspelling that the HTTP standard kept for compatibility.
Why is my referrer empty?
The visitor typed the URL or used a bookmark, the link was opened from an app, email client or PDF, the source page set no-referrer or used rel="noreferrer", or the click went from an HTTPS page to an HTTP page. Analytics tools count all of these as Direct, so Direct really means no referrer was available.
See which referrers bring conversions, not just visits.
SEOConversion is a cookieless, first-party tracker that reports conversions and their value by landing page for organic search and AI assistants. Visits with no referrer stay Direct instead of being guessed.
Start free