Referrer-Policy Disclosure Simulator

Show the modeled referrer for entered source and destination URLs under a selected policy without browsing.

Inputs stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Model referrer controls

The eight policy values from the W3C Referrer Policy specification, plus the default a page gets when it sets none.

An absolute http or https URL, including the path and query you care about. Credentials and the fragment are removed before the value is worked out.

The page being linked to, navigated to or loaded. Only the scheme, host and port decide same-origin and downgrade.

Optional, up to 50 URLs. Each one is added to the table with the same source and policy.

Processed in your browser. Your inputs stay on this device.

Showing a generated example. Generate again for a new result.

How to use Referrer-Policy Disclosure Simulator

  1. Supply the referrer-policy and source page url using the supported input described beside the controls.
  2. Review the selected options and the declared scope, then run the referrer policy simulator.
  3. Read the result and unresolved findings before downloading or sharing a report. The original input is not changed.

Example: Referrer-Policy Disclosure Simulator

Show referrer values for declared source/destination/policy scenarios. This example uses synthetic public data.

You add
Referrer-Policy: default Source page URL: https://ada:[email protected]/orders/checkout?cart=42#payment Destination URL: https://ads.partner.example/landing?utm_source=shop Extra destinations, one per line: https://shop.example.com/help/returns http://news.example.net/story
You get
With strict-origin-when-cross-origin, the main destination sees the origin only. https://ads.partner.example | cross origin | Origin only: https://shop.example.com Extra 1 | same origin | Full URL: https://shop.example.com/orders/checkout?cart=42 Extra 2 | cross origin, secure page to plain http | No referrer is sent

Options

Source and destination
Enter the exact HTTP(S) URLs for the scenario. Origins include scheme, host and effective port.
Policy
Select a named policy or the stated default. HTTPS-to-HTTP transitions can change whether a referrer is sent.

Supported inputs and limits

Offline HTTP(S) scenario model only. No browsing, network trace, certificate check or audit of actual site privacy.

Where your input is processed

This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

The displayed value explains a disclosure choice

Different policies can send no referrer, an origin or a fuller source URL. Credentials and fragments are removed, while a policy that sends a fuller URL can disclose its path and query. The result models the entered URLs and policy; it does not inspect real request headers or prove a browser applied that policy.

Questions about Referrer-Policy Disclosure Simulator

Are credentials or fragments sent?

They are stripped from the modeled referrer. Paths and queries depend on the selected policy.

Does this show an actual request?

No. It calculates the declared scenario without loading the URLs.

What does origin contain?

The scheme, host and effective port, without the path, query or fragment.

Project manager: Tony Hines · Content updated 4 October 2026 · Report a problem