HTML Anchor Attributes Table

AttributeWhat it doesField note
hrefThe destinationOmit href and the anchor is a PLACEHOLDER link - unfocusable, unvisited
target="_blank"New tabNEVER without rel=noopener - the opened page could navigate the opener
rel="noopener"Severs window.openerModern browsers imply it for _blank; explicit costs nothing and covers old ones
rel="nofollow"Link is not an endorsementSponsored links need nofollow (or sponsored); UGC gets ugc
downloadSave instead of navigateSame-origin only for the filename hint - cross-origin ignores the value
hreflangLanguage of the destinationA hint for users and crawlers; pairs with alternate links in head
#fragmentSame-page jumphref=#id scrolls - and scroll-behavior:smooth makes it glide
type / pingMIME hint / analyticstype is advisory only; ping fires tracking beacons - know when you send them
Reference: the MDN anchor element reference. The anchor is the web's original interactive element, and its attributes are mostly CONTRACTS: target=_blank without rel=noopener hands the new tab a window.opener reference it could weaponize (tabnabbing); nofollow tells search engines a link is not your endorsement - the trio nofollow/sponsored/ugc sorts paid and user-generated links. Bottom line: every _blank ships with noopener, paid links get nofollow or sponsored, and download only honors its filename hint same-origin - cross-origin download attributes are security-restricted by design. Related tools: meta tags table (the head-side link element), security headers table (header-level isolation: COOP), and semantic elements table (nav landmarks around your anchors).

The anchor is the web's original interactive element, and its attributes are contracts with three audiences: users (target, download, #fragment), search engines (rel=nofollow/sponsored/ugc), and the browser's security model (noopener). One tag, three promises.

Bottom line: every target=_blank ships with rel=noopener - without it, the opened page receives a window.opener handle and can navigate YOUR tab to a phishing copy (tabnabbing). Paid and user-generated links carry the rel trio so search engines know a link is not your endorsement.

The honest part: the href-less anchor is a placeholder, not a button - unfocusable and unvisited, it fails keyboard users and search alike. If it acts, it is a button element; if it navigates, it needs an href. The a-without-href pattern is a semantics bug that CSS cursor:pointer cannot paper over.

How to use

  1. Standard external link: <a href=https://example.com target=_blank rel=noopener> - the pair belongs together even though modern browsers imply noopener for _blank.
  2. Sort your outbound rels: paid links get rel=sponsored (or nofollow), user-generated links get rel=ugc, editorial links get nothing - that is the whole decision tree.
  3. Offer downloads: <a href=report.pdf download=2026-report.pdf> - same-origin lets you rename the file; cross-origin destinations ignore the value by security design.

Frequently asked questions

Why does target=_blank need rel=noopener?

Because a page opened into a new tab can, by default, reach back through window.opener and navigate the ORIGINAL tab to any URL - a phishing clone of your site while the user reads the new one. That attack is tabnabbing, and rel=noopener closes it by severing the opener reference. Modern browsers imply noopener for target=_blank anchors automatically, but the explicit attribute costs nothing, documents intent, and covers older engines and non-anchor contexts. For maximum isolation, the header-level counterpart is COOP (Cross-Origin-Opener-Policy).

What is the difference between nofollow, sponsored and ugc?

All three tell search engines the same mechanical thing - do not count this link as an endorsement - but they say WHY, and that context helps search engines tune ranking systems. nofollow is the original catch-all (untrusted or paid); sponsored specifically marks advertising and paid placements; ugc marks user-generated content like comments and forum posts, where you vouch for the platform but not each author. Since 2019 Google treats them as HINTS rather than directives, and rel values combine space-separated: rel='ugc nofollow' is valid.

Does the download attribute work for cross-origin files?

Partially - and the boundary is deliberate. Same-origin: the download attribute both forces a download instead of navigation AND lets you suggest a filename. Cross-origin: browsers IGNORE the filename hint (a page could otherwise rename and rebrand files from other sites), and whether a download is forced at all depends on the Content-Disposition header the serving site sends. The reliable cross-origin pattern is the server setting Content-Disposition: attachment; filename=... - the attribute alone is a same-origin convenience.

When should an anchor omit its href?

Almost never. An anchor without href is a PLACEHOLDER: it cannot receive keyboard focus, is not announced as a link, shows no visited state, and middle-click does nothing - it is an a-shaped span. The two legitimate uses are the current-page indicator (aria-current=page on a nav item) and a link whose href is filled in by script at runtime. Everything else that LOOKS clickable but acts in-page is a button element - semantically correct, keyboard-operable for free, and honest to assistive technology. Styling a span as a link is the reverse mistake.

Related tools