After some testing, I see the Referrer Filter is doing a good job blocking POST requests outside of the current environment using the default configuration ("Allow Hosts" is blank). And the documentation states "By default, all variations of localhost and the current host names the server is bound ...