2) clever antivirus/firewall software
3) htaccess tricks will often drop headers
4) javascript
5) things like amazon silk
6) people spoofing things to make their browser work
7) anonymizer services
8) proxies
10) bookmarks
>In testing links from Facebook and Twitter over HTTPS the referer is present in most cases.
"Clients SHOULD NOT include a Referer header field in a (non-secure) HTTP request if the referring page was transferred with a secure protocol."
However, it's possible that Facebook is passing users through an HTTP gateway.
Give it a try yourself: https://twitter.com/vikrum5000/status/256898972478763008 Note the protocol.
There's probably room here to do some investigation as to what Google is doing to make outbound links from mail.google.com completely drop the referer. (Also, what about other web based mail clients? Yahoo? MSN? Aol? Corporate Outlook?)