DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
curl

HTTP Referer Header: A Complete Guide for Web Scraping

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The HTTP Referer header optionally tells a server the URI from which a request’s target was obtained. For a scraper, it is request metadata—not proof of a human visit, an access credential, or a universally required setting. Send it only when it accurately reflects the request context or the destination’s documented requirements.

What the HTTP Referer header means

The field name is spelled Referer, a long-standing misspelling of “referrer.” The related policy is correctly spelled Referrer-Policy. RFC 9110 defines Referer as a URI reference for the resource from which the target URI was obtained. Its value may be an absolute URI or a partial URI. When a user agent generates the field, it must omit the URI’s fragment and userinfo components. RFC 9110 §10.1.3

For example, if a browser follows a link from https://example.com/catalog to https://example.com/item/42, the request for the item may carry a Referer value identifying the catalog page. That is a possible navigation context, not a guarantee: requests do not always contain the field, and user agents may omit or truncate it.

What it can—and cannot—tell a scraper

Servers may use referrer information for backlinks, basic analytics, logging, link maintenance, caching decisions, deep-link checks, or some CSRF-related checks. But its presence and contents are not dependable enough to establish how a person arrived at a page. An absent header does not prove there was no referring page; a present one does not prove that the request came from a browser or an authorized user. RFC 9110 §10.1.3

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • It is optional. Not all requests include it.
  • It may be incomplete. A user agent can omit it or truncate information beyond the referring origin.
  • It is not authentication. A header value does not identify or authorize the caller.
  • It is not permission to scrape. A plausible-looking value cannot substitute for permission, a documented API, or compliance with applicable rules.

Do not fabricate a referrer simply to make automated traffic look like a human journey. Doing so misrepresents the request context, and the field is not an access grant. If a site documents a specific requirement for the header, follow that requirement only for requests you are authorized to make.

When a scraper should send Referer

When it genuinely represents the request context

If your application fetched a page and then requests a linked resource from it, you can set the referring page URI when that is accurate and appropriate. Keep the value to the relevant URI; do not include credentials or a fragment. If your client is making a direct request without a referring resource, omitting the field is more truthful than inventing one.

When the destination documents a requirement

A service may use Referer for validation or operational purposes. Check the destination’s own documentation and distinguish a stated requirement from an assumption based on a failed request. If the destination’s rule is unclear, contact its operator rather than cycling through guessed values.

When privacy or security argues against it

A full referring URI can disclose sensitive path or query information, such as an account area or a private resource identifier. Avoid sending more context than necessary. RFC 9110 says a user agent must not send a Referer on an unsecured HTTP request when the referring resource was accessed over a secure protocol. It also says a user agent should not send it on a secure cross-origin request unless the referring resource explicitly allows it. RFC 9110 §10.1.3

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to set or omit the header in a scraper

The examples below show ordinary ways to express an optional request header. They do not make a client behave exactly like a browser, and there is no universal referrer value for scraping. Use a real referring URI only when it matches your request context; otherwise omit the header. Adapt the target URL and referring URI to your authorized use.

Python with Requests

Install the dependency with python -m pip install requests. The example supplies an accurate example referrer explicitly; remove the Referer entry from headers to omit it.

import requests

url = "https://example.com/item/42"
headers = {"Referer": "https://example.com/catalog"}

response = requests.get(url, headers=headers, timeout=30)
response.raise_for_status()
print(response.status_code)
print(response.url)
print(response.text[:500])

raise_for_status() makes unsuccessful HTTP status responses visible as exceptions rather than treating an error page as successful content. A production scraper should also decide how to handle redirects, retries, response size, and the destination’s rate limits; a Referer header does not solve any of those concerns.

cURL

Use -H to send the field. Remove that option when you should not send a referrer.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl --fail --show-error --location 
  -H 'Referer: https://example.com/catalog' 
  'https://example.com/item/42'

Node.js fetch

In a modern Node.js runtime that provides the built-in fetch API, pass the header in the request options. Remove the header property to omit it.

const url = 'https://example.com/item/42';
const res = await fetch(url, {
  headers: { Referer: 'https://example.com/catalog' }
});

if (!res.ok) {
  throw new Error(`HTTP ${res.status}`);
}
console.log(res.status, res.url);
console.log((await res.text()).slice(0, 500));

These examples demonstrate header syntax, not a browser-equivalence guarantee. Client behavior can differ, especially around redirects and restricted or automatically managed headers. Check the documentation for the specific HTTP client and runtime you deploy.

Referrer-Policy: why browser requests may differ

For browser-originated requests and navigations, a document’s Referrer-Policy controls how much referrer information is sent. The W3C specification includes policies such as no-referrer, same-origin, origin, strict-origin, origin-when-cross-origin, strict-origin-when-cross-origin, no-referrer-when-downgrade, and unsafe-url. W3C Referrer Policy

A policy can be delivered in an HTTP Referrer-Policy response header, through a meta element, or using a referrerpolicy attribute on supported elements; noreferrer is another way to suppress referrer information in applicable HTML contexts. The policy mechanism describes browser document behavior. A standalone scraper should not assume that its HTTP library interprets page policy or generates browser navigation metadata in the same way.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The W3C report describes no-referrer-when-downgrade as the default in the behavior it documents when no policy is otherwise set. Do not treat that statement as a guarantee for every current browser or HTTP client: defaults can depend on current specifications and implementation.

Referer, robots.txt, and permission are separate questions

A Referer value does not override a site’s crawler guidance or grant access. RFC 9309 explicitly says robots.txt rules are requested of crawlers and “are not a form of access authorization.” RFC 9309 §1 Treat crawler rules, authorization, terms, and referrer metadata as distinct concerns. An allowed path in robots.txt is not itself permission, and a disallowed path is not made acceptable by sending a different header.

Privacy and implementation trade-offs

  • Sending the full page URI can help a destination understand link context, but can reveal sensitive paths or query values.
  • Sending only an origin discloses less detail, though it may not satisfy a destination that documents a more specific requirement.
  • Omitting the field avoids unnecessary disclosure and is appropriate when there is no genuine referrer or no reason to provide one.
  • Removing it indiscriminately can interfere with legitimate server checks, including some CSRF-related defenses. Privacy filtering should be deliberate rather than treated as universally harmless.

RFC 9110 notes that intermediaries have removed Referer indiscriminately, which can interfere with CSRF protections. The right choice depends on the actual request and the destination’s documented behavior—not on a rule that every scraper should always send or always suppress the field. RFC 9110 §10.1.3

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting common Referer problems

The server says the referrer is missing

First determine whether the destination actually requires the field and what value it documents. If you have a real referring page, set that URI explicitly in your HTTP client and inspect the outgoing request using the client’s supported diagnostics. If there is no real referrer, do not invent one to imitate a browser; ask the service operator for an approved integration method.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The value differs from what a browser sends

That can be expected. Browser document policy can limit, shorten, or suppress referrer information, while a standalone client may use different rules. Inspect the page’s applicable policy and your client’s own documentation. Do not infer a universal browser default from the behavior of one request.

A cross-origin request omits the full path

A policy may send only the origin for cross-origin requests, and secure-context rules also constrain disclosure. If you control the source page, review its policy and whether a more detailed referrer is appropriate. If you do not control it, do not try to override the visitor’s privacy choice by fabricating a full URL.

A request works in a browser but not in a scraper

The referrer may be one difference, but it is not the only possible cause. Browser policy, cookies, authentication, redirects, JavaScript, and other request details can differ. Check the destination’s documented API or integration instructions; there is no universal header fix or browser-identical behavior for any named library.

A scraper is blocked despite sending Referer

The field is not authorization and does not make a request legitimate. Stop guessing header values. Verify that you are permitted to access the resource and use the destination’s supported API or contact its operator for access guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Or skip the browser setup

If your goal is a visual capture rather than parsing a page’s HTML, ScreenshotNeo offers a screenshot API and MCP server. A single GET request can return an image or PDF. See the ScreenshotNeo documentation for API parameters and setup details.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

ScreenshotNeo removes supported cookie/consent banners, newsletter popups, and chat widgets before capture; bot checks, blank pages, and failed loads are not billed. Its MCP server lets AI agents take screenshots, and the Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Sign up for free and try 1,000 screenshots a month with no card.

Practical decision checklist

  • Do you have an actual referring resource? If yes, decide whether sending its URI is accurate and appropriate; if not, omit the field.
  • Does the destination document a requirement? Follow its stated instructions only for requests you are authorized to make.
  • Could the URI expose private path or query data? Reduce disclosure or leave the field out.
  • Are you relying on browser behavior? Check the applicable policy and the exact client implementation rather than assuming the scraper behaves like a browser.
  • Are you using the header to bypass a block or claim permission? Stop: Referer does neither.

Frequently Asked Questions

Why is the header spelled Referer instead of Referrer?

Referer is the historical spelling retained in the HTTP field name; the policy mechanism uses the ordinary spelling, Referrer-Policy.

Does an empty or missing Referer prove a request was direct?

No. User agents can omit the field, and policy or implementation can limit it. Its absence does not establish how a request originated.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can a Referer header bypass a robots.txt restriction or a login?

No. The header does not grant authorization, and robots.txt rules are not access authorization. Use only access methods permitted by the site.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.