HTML Anchor Attributes Table
| Attribute | What it does | Field note |
|---|---|---|
href | The destination | Omit href and the anchor is a PLACEHOLDER link - unfocusable, unvisited |
target="_blank" | New tab | NEVER without rel=noopener - the opened page could navigate the opener |
rel="noopener" | Severs window.opener | Modern browsers imply it for _blank; explicit costs nothing and covers old ones |
rel="nofollow" | Link is not an endorsement | Sponsored links need nofollow (or sponsored); UGC gets ugc |
download | Save instead of navigate | Same-origin only for the filename hint - cross-origin ignores the value |
hreflang | Language of the destination | A hint for users and crawlers; pairs with alternate links in head |
#fragment | Same-page jump | href=#id scrolls - and scroll-behavior:smooth makes it glide |
type / ping | MIME hint / analytics | type is advisory only; ping fires tracking beacons - know when you send them |
The anchor is the web's original interactive element, and its attributes are contracts with three audiences: users (target, download, #fragment), search engines (rel=nofollow/sponsored/ugc), and the browser's security model (noopener). One tag, three promises.
Bottom line: every target=_blank ships with rel=noopener - without it, the opened page receives a window.opener handle and can navigate YOUR tab to a phishing copy (tabnabbing). Paid and user-generated links carry the rel trio so search engines know a link is not your endorsement.
The honest part: the href-less anchor is a placeholder, not a button - unfocusable and unvisited, it fails keyboard users and search alike. If it acts, it is a button element; if it navigates, it needs an href. The a-without-href pattern is a semantics bug that CSS cursor:pointer cannot paper over.
How to use
- Standard external link: <a href=https://example.com target=_blank rel=noopener> - the pair belongs together even though modern browsers imply noopener for _blank.
- Sort your outbound rels: paid links get rel=sponsored (or nofollow), user-generated links get rel=ugc, editorial links get nothing - that is the whole decision tree.
- Offer downloads: <a href=report.pdf download=2026-report.pdf> - same-origin lets you rename the file; cross-origin destinations ignore the value by security design.
Frequently asked questions
Why does target=_blank need rel=noopener?
Because a page opened into a new tab can, by default, reach back through window.opener and navigate the ORIGINAL tab to any URL - a phishing clone of your site while the user reads the new one. That attack is tabnabbing, and rel=noopener closes it by severing the opener reference. Modern browsers imply noopener for target=_blank anchors automatically, but the explicit attribute costs nothing, documents intent, and covers older engines and non-anchor contexts. For maximum isolation, the header-level counterpart is COOP (Cross-Origin-Opener-Policy).
What is the difference between nofollow, sponsored and ugc?
All three tell search engines the same mechanical thing - do not count this link as an endorsement - but they say WHY, and that context helps search engines tune ranking systems. nofollow is the original catch-all (untrusted or paid); sponsored specifically marks advertising and paid placements; ugc marks user-generated content like comments and forum posts, where you vouch for the platform but not each author. Since 2019 Google treats them as HINTS rather than directives, and rel values combine space-separated: rel='ugc nofollow' is valid.
Does the download attribute work for cross-origin files?
Partially - and the boundary is deliberate. Same-origin: the download attribute both forces a download instead of navigation AND lets you suggest a filename. Cross-origin: browsers IGNORE the filename hint (a page could otherwise rename and rebrand files from other sites), and whether a download is forced at all depends on the Content-Disposition header the serving site sends. The reliable cross-origin pattern is the server setting Content-Disposition: attachment; filename=... - the attribute alone is a same-origin convenience.
When should an anchor omit its href?
Almost never. An anchor without href is a PLACEHOLDER: it cannot receive keyboard focus, is not announced as a link, shows no visited state, and middle-click does nothing - it is an a-shaped span. The two legitimate uses are the current-page indicator (aria-current=page on a nav item) and a link whose href is filled in by script at runtime. Everything else that LOOKS clickable but acts in-page is a button element - semantically correct, keyboard-operable for free, and honest to assistive technology. Styling a span as a link is the reverse mistake.