⚠️ DEV TOOL — This website intentionally contains SEO issues for testing. Not for public use.Issues Index →

Referrer Policy by HTTP Header

0 Intentional Issues

A page with no referrer meta tag whose policy is nonetheless declared — as a comma-separated fallback list, in the response header.

Expected result: meta_name_referrer NOT DETECTED

And referrer_policy_header (#70) not detected either. This page carries no referrer meta tag at all, which is what makes it an edge case rather than a copy of /fp-meta-referrer: a check that looks for the tag finds nothing, and a page that has declared its policy correctly gets reported.

The header this page sends

Referrer-Policy: no-referrer, strict-origin-when-cross-origin

A comma-separated list, which is what the specification defines the field value to be. A browser uses the last token it understands, so an old one falls back to no-referrer and a current one applies the recommended strict-origin-when-cross-origin. Both members are in the specification's token list; a validator that compared the whole string against that list would reject a correct header.

The three delivery routes, and which page uses each

  • Referrer-Policy response headerused here

    Set for this path in public/_headers. The first source httpSecurityHeaders.js reads, and the one a CDN or a framework config normally owns.

  • <meta http-equiv="Referrer-Policy">

    The second source. Used by /meta-referrer-gap, which has no name tag and no header.

  • <meta name="referrer">

    The third source, and the oldest. Used by /fp-meta-referrer.

Index: /fp-edge-fixtures. The plain false-positive case is /fp-meta-referrer; the two malformed cases are /invalid-meta-referrer-empty and /invalid-meta-referrer-token.