heap.io
HTML metadata
Technology
- CDN
- Netlify
- CMS
- Next.js
- Analytics
-
- Google Tag Manager
- Cookie consent
-
- OneTrust
Third-party hosts loaded (4)
- images.ctfassets.net×23
- cdn.cookielaw.org×2
- fast.wistia.net×1
- www.googletagmanager.com×1
Social
Contact
- Address
- st DemoHelp CenterContact UsPricingSocialTwitterFacebookLinkedInYouTube©2026
DNS records live
- NS
-
- ns-1471.awsdns-55.org
- ns-1905.awsdns-46.co.uk
- ns-337.awsdns-42.com
- ns-650.awsdns-17.net
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 13 TXT records
google-site-verification=SQciY5rQ5Ndp8bPV4MpMnnhWvrtb6st-g6QplMNBmuIgoogle-site-verification=fQRlWK5ZippL6i3YeMTL5JTtamOpxlMEaHYsRtmBbccgoogle-site-verification=mQwmF0SV1aElSY2kzZVkhnxONGIEgUpdKbQs9mNn_PQgoogle-site-verification=tQjSKbUPEW4UI-U5fA0zhskF_lYCsT9QNm05TAlwJuIgoogle-site-verification=xzr5Kxxb0ergfNDmtuTv16IdkYmPxkqXKhlIeWXPsl8status-page-domain-verification=ggq0xfsy0530zapier-domain-verification-challenge=ddac77e6-055c-46a3-86d8-a61e749b64825E0FF5D237OSSRH-85467_globalsign-domain-verification=KCw5NluX1BTxRHpl1yZ3THAO0rgjicaMe3WovZmaEnd1wyv6d7zlixrd.cloudfront.netatlassian-domain-verification=wRDAm6Aok+nKIeZJ4itJ4Gipk615silynNzJYEZFjV0EfXtCv5CNIA6/oGyxdjM6google-site-verification=9UBATzQUZdTLBa0jJXHzEarYp4ruLZEXoyfBUZpXv88google-site-verification=IPoogigyckCqNT514ybBkYOozxd1VoESAzKJZjVlRMA
Email authentication strong
- SPF
-
v=spf1 include:sendgrid.net include:_spf.google.com include:stspg-customer.com include:mktomail.com include:mail.zendesk.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:ipm2ls4@ar.glockapps.com,mailto:re+tg5jazih7if@dmarc.postmarkapp.com,mailto:postmaster@heap.io; ruf=mailto:ipm2ls4@fr.glockapps.com; fo=1; pct=100;policy: quarantine - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCz+4bT8uXouw1VNR4d1HpBZq95r6KCS1Ttzp0dNFVXqLW8AjgIG4C75fmoUTTbS0UjFjA0l1janROFdcA73S… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA30UYgrpxnHzAshzYzW1Ej4hZakZHb8/8SvCMERCC6hneGuv6SR6+Rw1Mpx9NGJ7VP5WZF3Ek8zihTRGDw9… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCiQCz6PUf5aeCt86Ilq2W6J7ucajEnfzJHJzaLWM83i7y5zt87WUFfk8fKW5Cy3h9QMJ63Mh1tS8F/EOv1RnaMuV…
selectors probed - google:
Certificate (current)
E7
Expires in 72 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy-report-only
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- missing Content Security Policy
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- strict-transport-security
max-age=31536000; includeSubDomains- content-security-policy-report-only
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.cookielaw.org https://optly.heap.io https://www.googleoptimize.com https://www.googletagmanager.com https://cdn.us.heap-api.com https://marketo.clearbit.com https://*.wistia.net https://js.chilipiper.com https://js.driftt.com https://*.clearbit.com https://app-ab33.marketo.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.cookielaw.org https://*.ctfassets.net; img-src 'self' data: https://*.ctfassets.net https://www.google-analytics.com https://www.googletagmanager.com https://*.wistia.net https://heapanalytics.com https://*.clearbit.com https://*.doubleclick.net; connect-src 'self' https://*.contentful.com https://*.heap-api.com https://heapanalytics.com https://www.google-analytics.com https://*.wistia.net https://*.doubleclick.net https://*.cookielaw.org https://app-ab33.marketo.com; font-src 'self' data: https://fonts.gstatic.com; frame-src 'self' https://*.wistia.net https: