Referer header
Referer is a request header naming the resource from which the target URI was obtained.
Referer is a request header naming the resource from which the target URI was obtained. The field name is misspelled, and the specification preserves the misspelling deliberately, noting it in place with a bracketed sic.
#What it may and may not contain
RFC 9110 requires that the fragment and userinfo components be excluded from the value. It permits a user agent to truncate anything beyond the referring origin, so a short value is not evidence of tampering. Where the target URI came from something with no URI of its own, such as typed input or a bookmark, the header must either be omitted or sent as about:blank.
Referer: http://www.example.org/hypertext/Overview.html
#The downgrade rule
A user agent must not send Referer in an unsecured HTTP request when the referring resource was accessed over a secure protocol, and should not send it across origins when the referring resource was secure, unless that resource allows it. This is a hard requirement, not a preference, and it explains a great many missing headers that get blamed on something else.
The W3C Referrer Policy specification defines the tokens that control the rest: no-referrer, same-origin, origin, strict-origin, origin-when-cross-origin, strict-origin-when-cross-origin, unsafe-url and no-referrer-when-downgrade. Which of them a browser applies by default has changed over time and differs between browsers, so observe it rather than assume it.
#Using it when scraping
Sites use the header for analytics, for deep-link restrictions and as one input to request-forgery defences, while the specification notes that not all requests carry it. Fabricating a value that matches the navigation you are claiming to have made is consistent; fabricating one that contradicts your other headers is not. It is a weak signal on its own and we make no claim about its effect on any particular target.
#Commonly confused with
Origin carries only a scheme, host and port and is sent on requests where the full path would be too revealing. Referer may carry a path. See also user agent, cookie jar and anti-bot systems, which read these headers together rather than separately.