Every time you click a link, your browser sends an HTTP Referer header to the destination website. This header reveals exactly which page you came from — exposing private URLs, internal dashboards, and search queries. Here's how to strip it completely.
What Is the HTTP Referer Header?
The Referer header is automatically sent by browsers when navigating between pages. If you're on yoursite.com/private-dashboard and click an outbound link, the destination receives: Referer: https://yoursite.com/private-dashboard.
Why Remove the Referrer?
- Protect private URLs — Internal dashboards and staging links should never reach external sites.
- Hide traffic sources — Competitors can see exactly where your visitors originate.
- Prevent affiliate tracking — Networks log your source via the referrer header.
- Protect users — Shared links can expose session tokens and profile URLs.
Which Method Should You Actually Use
These four methods aren't interchangeable for every situation. A dereferer is best for one-off link sharing where you don't control the destination site's headers. The Referrer-Policy server header is the right choice for protecting an entire site's outbound links at once, since it applies site-wide without touching individual link tags. The HTML attribute is useful when you need different referrer behavior on specific links within the same page, and the meta tag is a fallback for static sites with no server-side header control.
A Browser Compatibility Gotcha
The referrerpolicy HTML attribute and the Referrer-Policy header are both well-supported in all current browsers, but very old browser versions (pre-2018 roughly) may ignore them entirely and send the full referrer regardless. For links where referrer leakage would be genuinely sensitive, a dereferer service is the more reliable choice precisely because it doesn't depend on the visitor's browser honoring a policy — the browser never even sees the original URL to send as a referrer.
Method 1: Use a Dereferer (Fastest)
A dereferer routes links through an anonymous server — the destination sees only the dereferer, not your original page. Anonymiz Dereferer creates anonymous links instantly — free, no account needed.
Method 2: Referrer-Policy HTTP Header
Add this to your server config to stop all outbound referrers: Referrer-Policy: no-referrer
Method 3: HTML referrerpolicy Attribute
For individual links: <a href="https://example.com" referrerpolicy="no-referrer">Link</a>
Method 4: Meta Tag
For a full page: add <meta name="referrer" content="no-referrer"> to <head>.
For sharing individual links quickly, use Anonymiz Dereferer. For protecting your website's outbound links, use the Referrer-Policy header.


