This option protects against showing potential sensitive data that might be present in a full URL text string (for example, a Salesforce organization's ID).
Referrer URL protection is used to hide the Salesforce website's URL or any associated Visualforce pages from other websites. This means that when these pages load, the URL string salesforce.com is displayed in the referrer header instead of the actual URL string.
Let's discuss HSTS in the next section.