Skip to content

HTTP security configuration

What is Referrer-Policy?

Whether responses set a Referrer-Policy header that limits how much of the page address is shared with other sites.

Part of the External Security Check. Free during the preview.

What it checks

Whether responses set a Referrer-Policy header that limits how much of the page address is shared with other sites.

A pass means: A Referrer-Policy limits what is shared with other sites.

Possible findings

No Referrer-Policy

Severity: InformationConfidence: ConfirmedKind: Recommended hardening

What we found

Responses do not set a Referrer-Policy header.

Why it matters

Modern browsers default to a reasonable policy, so the risk is small. Setting one explicitly stops full URLs, which can contain identifiers, leaking to other sites.

How to fix it

Add Referrer-Policy: strict-origin-when-cross-origin.

References