headway.io

.io crawl

First seen 2026-04-13 · Last seen 2026-05-06 · ok HTTP/1.1 200 1026 ms crawled 2026-05-06

US · 198.202.211.1 · AS209242 Cloudflare London, LLC

Reputation 100/100

sector b2b services type homepage

HTML metadata

Title
Headway - A World-Class Digital Product Agency
Description
Headway is a digital product agency partnering with startups and enterprise on design systems, UX, AI development, and software. Your product team for hire.
Language
en
Canonical
https://www.headway.io

Open Graph

title
Headway - A World-Class Digital Product Agency
description
Headway is a digital product agency partnering with startups and enterprise on design systems, UX, AI development, and software. Your product team for hire.

Technology

CDN
Cloudflare
Analytics
  • Google Tag Manager
Fonts
  • Adobe Fonts
  • Google Fonts
Third-party hosts loaded (15)
  • cdn.prod.website-files.com×94
  • 117154988.intellimizeio.com×1
  • ajax.googleapis.com×1
  • api.intellimize.co×1
  • cdn.embedly.com×1
  • cdn.intellimize.co×1
  • cdn.jsdelivr.net×1
  • d3e54v103j8qbb.cloudfront.net×1
  • fonts.googleapis.com×1
  • fonts.gstatic.com×1
  • js.hs-scripts.com×1
  • log.intellimize.co×1
  • use.typekit.net×1
  • valley-intent.nyc3.digitaloceanspaces.com×1
  • www.googletagmanager.com×1

Social

Contact

Email
Phone

DNS records live

NS
  • journey.ns.cloudflare.com
  • lamar.ns.cloudflare.com
CNAME
  • cdn.webflow.com

Email authentication no MX

SPF
not published
DMARC
v=DMARC1; p=none;
policy: none (monitoring only)
DKIM
  • google: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAm6OAzGesuPfgOX0MtLwr6ehwo3UWd1mOpEx0pdEwpikUdwRneb4fjAVobZHdgRzPiXzgIEVUcBaDV1…
  • smtpapi: k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDPtW5iwpXVPiH5FzJ7Nrl8USzuY9zqqzjE0D1r04xDN6qwziDnmgcFNNfMewVKN2D1O+2J9N14hRprzByFwfQW76…
selectors probed

Certificate (current)

WE1
from 2026-03-18 to 2026-06-16
Expires in 28 days

HTTP security headers

Header hygiene 80/100 Checked live page: https://www.headway.io/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
findings
  • missing content type protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
SAMEORIGIN
content-security-policy
frame-ancestors 'self'
strict-transport-security
max-age=31536000; includeSubDomains; preload

Links to (4)

Linked from (1)