# Referrer policy and Direct traffic

> Why most of your traffic might show as Direct, how referrer policies on your site and on other sites affect sources, and how UTM parameters fix attribution.

Sources come from `document.referrer`, which the **previous** site's
browser policy controls.

## Your own policy

If your site sends `Referrer-Policy: no-referrer` (or `same-origin`), your
**internal** navigation has no referrer, and single-page flows can look
like new direct visits. More importantly, links *from* your other
properties (blog → app) arrive without a referrer.

The browser default, `strict-origin-when-cross-origin`, is fine: other
sites send their origin (`https://news.example/`), which is all Privatus Analytics
stores anyway (we drop referrer query strings).

**Verify installation** warns when your pages send `no-referrer` or
`same-origin`.

## Other sites' policies

Many sites and apps send no referrer at all: mobile apps, email clients,
messaging apps, some social networks, and links opened from documents.
That traffic lands in **Direct**. Use UTM parameters on links you control
(newsletters, social posts, ads) so it's attributed correctly: see
[Campaigns](/docs/features/campaigns).

## HTTPS → HTTP

Browsers never send a referrer from an `https` page to an `http` page.
Serve your site over HTTPS.
