Referrer policy and Direct traffic
Why most of your traffic might show as Direct, how referrer policies on your site and on other sites affect sources, and how UTM parameters fix attribution.
Sources come from document.referrer, which the previous site's
browser policy controls.
Your own policy#
If your site sends Referrer-Policy: no-referrer (or same-origin), your
internal navigation has no referrer, and single-page flows can look
like new direct visits. More importantly, links from your other
properties (blog → app) arrive without a referrer.
The browser default, strict-origin-when-cross-origin, is fine: other
sites send their origin (https://news.example/), which is all Privatus
stores anyway (we drop referrer query strings).
Verify installation warns when your pages send no-referrer or
same-origin.
Other sites' policies#
Many sites and apps send no referrer at all: mobile apps, email clients, messaging apps, some social networks, and links opened from documents. That traffic lands in Direct. Use UTM parameters on links you control (newsletters, social posts, ads) so it's attributed correctly: see Campaigns.
HTTPS → HTTP#
Browsers never send a referrer from an https page to an http page.
Serve your site over HTTPS.