# Referrer policy and Direct traffic

> Why most of your traffic might show as Direct, how referrer policies on your site and on other sites affect sources, and how UTM parameters fix attribution.

Sources come from `document.referrer`, which the **previous** site's
browser policy controls.

## Your own policy

Your own `Referrer-Policy` controls what your pages send to the sites
they link to, not what you receive. If a site of yours sends
`Referrer-Policy: no-referrer` (or `same-origin`), links *from* it to your
other properties (blog → app) arrive without a referrer and show as
Direct there.

The browser default, `strict-origin-when-cross-origin`, is fine: other
sites send their origin (`https://news.example/`). Privatus Analytics
stores the referrer's host and path when the browser sends them, and
never its query string.

**Verify installation** warns when your pages send `no-referrer` or
`same-origin`.

## Other sites' policies

Many sites and apps send no referrer at all: mobile apps, email clients,
messaging apps, some social networks, and links opened from documents.
That traffic lands in **Direct**. Use UTM parameters on links you control
(newsletters, social posts, ads) so it's attributed correctly: see
[Campaigns](/docs/features/campaigns).

## HTTPS → HTTP

With the default policy, browsers send no referrer from an `https` page
to an `http` page. Serve your site over HTTPS.
