TL;DR, Quick Answer
7 min readBrowsers now send only the domain (not full URL) as referrer for cross-origin requests, and strip referrers entirely for HTTPS-to-HTTP. Compensate by tagging every link you control with UTM parameters.
Direct traffic keeps growing and nobody changed a campaign, which is the browser referrer policies analytics impact in one line: modern browsers now pass the domain rather than the full URL.
Referrer data used to feel simple: someone clicked a link, the destination site received the previous page URL, and analytics reported where the visit came from. Modern browsers are more careful. That is good for privacy, but it changes attribution.
If your analytics reports show more "direct" traffic than expected, fewer full referral URLs, or missing campaign detail, referrer policy may be one reason.
What the Referrer Header Does
The HTTP Referer header, misspelling included, tells a destination page where the request came from. Analytics tools use it to classify traffic as search, referral, social, or direct.
Without any extra campaign tagging, a visit from:
https://partner.example/reviews/best-analytics-toolsmight historically arrive with the full referring URL. That allowed the analytics tool to show not just partner.example, but the exact article.
Today, browsers commonly send less. MDN documents strict-origin-when-cross-origin as the default referrer policy in modern browsers, and Chrome announced the same default beginning with Chrome 85. Under that policy:
- same-origin requests can send the full URL
- cross-origin HTTPS-to-HTTPS requests send only the origin, such as
https://partner.example - HTTPS-to-HTTP requests send no referrer
That means your analytics tool may know the domain, but not the exact page.

Why Browsers Reduced Referrer Detail
Full referrer URLs can leak sensitive information. A URL can contain search terms, account IDs, reset tokens, document names, email addresses, or private paths. If that full URL is sent to every third-party resource on a page, privacy risk grows quickly.
Reduced referrer defaults are a browser-level attempt to limit passive data leakage. This is separate from cookies, pixels, and link tracking parameters. Even a site with no cookies can be affected by referrer policy.
How It Affects Analytics Reports
The biggest impact is loss of detail, not total loss of attribution.
You may still see that traffic came from github.com, news.ycombinator.com, linkedin.com, or a partner domain. You may not see which specific thread, profile, repository, or article sent it.
You may also see more direct traffic when:
- the source app does not send referrers
- the click happens inside a native app or email client
- the source uses
rel="noreferrer" - traffic moves from HTTPS to HTTP
- privacy tools strip referrers
- redirects remove attribution before the visitor lands
This is why "direct" traffic is not the same as "people typed the URL." It often means "the analytics tool did not receive a reliable source."
Flowsery
Start Your 14-Day Free Trial
Real-time dashboard
Goal tracking
Cookie-free tracking
Why UTM Tags Still Matter
UTM parameters are campaign labels you add to links you control. Google Analytics documents manual tagging with UTM parameters as a way to collect traffic-source dimensions, and the same concept works in privacy-first analytics tools.
A clean campaign URL looks like this:
https://flowsery.com/?utm_source=newsletter&utm_medium=email&utm_campaign=product_launchUse UTMs for links in:
- email newsletters
- paid ads
- social posts
- partner campaigns
- QR codes
- creator sponsorships
- webinars
- downloadable PDFs
Do not use UTMs on internal links. Internal UTMs overwrite the original acquisition source and make reports worse.
A Practical UTM Naming System
Keep names lowercase, predictable, and boring:
| Parameter | Use | Example |
|---|---|---|
utm_source | where the click came from | linkedin, newsletter, partnername |
utm_medium | channel type | social, email, cpc, referral |
utm_campaign | campaign name | privacy_audit_2026 |
utm_content | creative or placement | footer_cta, carousel_2 |
utm_term | paid keyword, when needed | cookieless_analytics |
Document allowed values. If one person uses LinkedIn, another uses linkedin.com, and a third uses li, your reports fragment.
Privacy Caveats
UTM tags should describe campaigns, not people. Never put personal data in URL parameters. Avoid:
- email addresses
- names
- phone numbers
- customer IDs
- account IDs
- invoice IDs
- free-form search terms from private contexts
URLs are copied, logged, shared, indexed, and sent through referrer headers in some contexts. Treat every campaign parameter as potentially visible.
- A channel name like newsletter or linkedin
- A campaign label like privacy_audit_2026
- A placement detail like footer_cta
- Email addresses or names
- Phone numbers
- Customer, account, or invoice IDs
- Free-form search terms from private contexts
What to Configure on Your Site
Set an explicit referrer policy. For most websites, strict-origin-when-cross-origin is a sensible default because it preserves same-origin functionality while reducing cross-site leakage:
Referrer-Policy: strict-origin-when-cross-originIf you handle especially sensitive paths, consider stricter policies such as same-origin or no-referrer for those areas. For example, account, billing, health, legal, or admin pages should not leak full URLs to third parties.
Also check redirects. If a campaign link passes through a shortener, affiliate system, consent manager, or redirect service, confirm that UTMs survive until the final landing page.
The Right Mental Model
Referrers are opportunistic. UTMs are intentional.
Use referrer data to understand organic mentions and uncontrolled traffic. Use UTMs to measure campaigns you control. Use both, but do not expect browser referrers to provide full-fidelity attribution in a privacy-conscious web.
That tradeoff is healthy. You can still measure marketing performance without demanding that browsers leak every page a visitor came from.

Flowsery
Start Your 14-Day Free Trial
Real-time dashboard
Goal tracking
Cookie-free tracking
QA for Campaign Links
Before a campaign launches, test the full click path. Click from the email, ad preview, social scheduler, partner page, QR code, and short link. Confirm the final landing page keeps the expected UTM parameters, uses HTTPS, avoids duplicate redirects, and does not add personal data to the URL.
Then check what your analytics tool records. The source, medium, campaign, landing page, and conversion should match the naming plan. If a link passes through a payment page, consent manager, or app store, document where attribution may be lost. This small QA routine catches campaign mistakes while there is still time to fix them, and it reduces the temptation to rely on invasive referrer recovery techniques later.
Referrer QA Checklist
Before a campaign launches, test the full click path from each placement and confirm that HTTPS, redirects, referrer policy, and UTM handling behave as expected. Then compare what analytics records with the naming plan. If attribution disappears at a shortener, consent step, payment page, or app-store handoff, document that gap instead of trying to rebuild the visitor's path with more invasive tracking.
Frequently Asked Questions
Why does my analytics dashboard show more direct traffic than before?
Modern browsers default to the strict-origin-when-cross-origin referrer policy, which sends only the domain instead of the full page URL on cross-origin requests. Chrome adopted this default starting with Chrome 85, and other browsers follow the same MDN-documented default. When the referrer is stripped or reduced, many analytics tools label the visit as direct.
What does the strict-origin-when-cross-origin referrer policy actually send?
Same-origin requests still send the full URL. Cross-origin HTTPS-to-HTTPS requests send only the origin, such as https://partner.example. Requests from HTTPS to HTTP send no referrer at all.
Can I still trust UTM parameters if a link goes through a redirect service?
Only if you confirm the parameters survive the hop. The QA routine in this guide calls for checking that UTMs stay intact through shorteners, affiliate systems, consent managers, and other redirect services before a campaign launches. If a redirect strips the query string, the landing page analytics loses the campaign source even though the click itself was tracked correctly.
Should I add UTM tags to links on my own site?
Keep UTMs off internal links entirely. Tagging a link from one page of your site to another overwrites the visitor's original acquisition source, so a visitor who arrived from a newsletter link would look like they came from wherever the internal link pointed. Save UTM tagging for links you control that live outside your site: newsletters, ads, social posts, partner campaigns, and similar channels.
Does rel="noreferrer" affect my traffic reports?
Yes, links marked rel="noreferrer" send no referrer header at all, so any visit through one shows up as direct traffic regardless of the referrer policy in place. This is one of the reasons direct traffic grows even when a visitor genuinely clicked a tracked link. UTM parameters are unaffected by rel="noreferrer" since they travel in the URL itself, not the referrer header.
Why do social and app traffic often show up as direct?
Native apps and email clients frequently send no referrer at all, and the same goes for many in-app browsers. Combined with privacy tools that strip referrers, that traffic lands in analytics as direct even though it followed a link. Tagging those links with UTM parameters recovers the source without relying on the browser to pass any referrer.
What is the difference between utm_medium and utm_source?
utm_source names where the click came from, such as linkedin, newsletter, or a partner's name. utm_medium names the channel type carrying it, such as social, email, cpc, or referral. Keeping the two separate and documenting allowed values stops the same channel from fragmenting into labels like LinkedIn, linkedin.com, and li.
Is it safe to put a customer ID or email address in a UTM parameter?
UTM tags should describe the campaign, not the person clicking it. This guide lists emails, names, phone numbers, and customer, account, or invoice IDs as data that should never appear in a URL parameter, because URLs get copied, logged, shared, and indexed. Free-form search terms taken from private contexts carry the same risk.
How can I tell if referrer loss or a broken UTM link caused a traffic drop?
Check whether the domain still shows up in your reports at all. If you see the partner or platform domain but lose the specific page or post, that is referrer policy reducing detail, not a tracking failure. If the source, medium, or campaign fields are empty or wrong for a link you tagged yourself, the UTM parameters likely got stripped somewhere in the click path, such as at a redirect or consent manager.
What should I check before launching a new campaign link?
Click through the full path from every placement, including the email, ad preview, social scheduler, partner page, QR code, and short link. Confirm the landing page keeps the expected UTM parameters, loads over HTTPS, and does not pick up duplicate redirects. Then check that your analytics tool records the source, medium, campaign, and landing page you planned for.
Was This Article Helpful?
Let us know what you think!
See us more often in Google
One click marks Flowsery as a preferred source, so our articles sit higher in your Top Stories, AI Mode, and AI Overviews.
Before you go...
Flowsery
Revenue-first analytics for your website
Track every visitor, source, and conversion in real time. Simple, powerful, and cookie-free.
Real-time dashboard
Goal tracking
Cookie-free tracking
Related Articles


A Practical Guide to Ad Campaign Tracking
UTM discipline, defined conversion goals and a clear view of GCLID auto-tagging give you directional campaign ROI without any third-party cookies.


A Practical Guide to 404 Errors
A 404 error is a failed journey, not just a status code. Track them as events, rank broken URLs by lost traffic, then redirect only the ones that matter.
A Practical Guide to Ab Testing Tracking
This AB testing tracking guide shows how to compare variants with tags, measure conversions, and run lightweight experiments in privacy-focused analytics.

