heap.io

.io crawl

First seen 2026-04-11 · Last seen 2026-05-18 · ok HTTP/1.1 200 2819 ms crawled 2026-05-18

US · 15.197.167.90 · AS16509 Amazon.com, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
Heap - Better Insights. Faster. | Heap
Description
Heap by Contentsquare is the only digital insights platform that shows everything users do on your site, revealing the "unknown unknowns" that stay invisible with other tools.
Language
en
Canonical
https://www.heap.io/

Open Graph

url
https://www.heap.io/
title
Heap - Better Insights. Faster.
site name
Heap
description
Heap by Contentsquare is the only digital insights platform that shows everything users do on your site, revealing the "unknown unknowns" that stay invisible with other tools.

Technology

CDN
Netlify
CMS
Next.js
Analytics
  • Google Tag Manager
Cookie consent
  • OneTrust

Third-party hosts loaded (4)

  • images.ctfassets.net×23
  • cdn.cookielaw.org×2
  • fast.wistia.net×1
  • www.googletagmanager.com×1

Social

Contact

Address
st DemoHelp CenterContact UsPricingSocialTwitterFacebookLinkedInYouTube©2026

DNS records live

NS
  • ns-1471.awsdns-55.org
  • ns-1905.awsdns-46.co.uk
  • ns-337.awsdns-42.com
  • ns-650.awsdns-17.net
MX
  • 1 aspmx.l.google.com
  • 10 alt3.aspmx.l.google.com
  • 10 alt4.aspmx.l.google.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
TXT
Show 13 TXT records
  • google-site-verification=SQciY5rQ5Ndp8bPV4MpMnnhWvrtb6st-g6QplMNBmuI
  • google-site-verification=fQRlWK5ZippL6i3YeMTL5JTtamOpxlMEaHYsRtmBbcc
  • google-site-verification=mQwmF0SV1aElSY2kzZVkhnxONGIEgUpdKbQs9mNn_PQ
  • google-site-verification=tQjSKbUPEW4UI-U5fA0zhskF_lYCsT9QNm05TAlwJuI
  • google-site-verification=xzr5Kxxb0ergfNDmtuTv16IdkYmPxkqXKhlIeWXPsl8
  • status-page-domain-verification=ggq0xfsy0530
  • zapier-domain-verification-challenge=ddac77e6-055c-46a3-86d8-a61e749b6482
  • 5E0FF5D237
  • OSSRH-85467
  • _globalsign-domain-verification=KCw5NluX1BTxRHpl1yZ3THAO0rgjicaMe3WovZmaEnd1wyv6d7zlixrd.cloudfront.net
  • atlassian-domain-verification=wRDAm6Aok+nKIeZJ4itJ4Gipk615silynNzJYEZFjV0EfXtCv5CNIA6/oGyxdjM6
  • google-site-verification=9UBATzQUZdTLBa0jJXHzEarYp4ruLZEXoyfBUZpXv88
  • google-site-verification=IPoogigyckCqNT514ybBkYOozxd1VoESAzKJZjVlRMA

Email authentication strong

SPF
v=spf1 include:sendgrid.net include:_spf.google.com include:stspg-customer.com include:mktomail.com include:mail.zendesk.com -all
strict (-all)
DMARC
v=DMARC1; p=quarantine; rua=mailto:ipm2ls4@ar.glockapps.com,mailto:re+tg5jazih7if@dmarc.postmarkapp.com,mailto:postmaster@heap.io; ruf=mailto:ipm2ls4@fr.glockapps.com; fo=1; pct=100;
policy: quarantine
DKIM
  • google: v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCz+4bT8uXouw1VNR4d1HpBZq95r6KCS1Ttzp0dNFVXqLW8AjgIG4C75fmoUTTbS0UjFjA0l1janROFdcA73S…
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA30UYgrpxnHzAshzYzW1Ej4hZakZHb8/8SvCMERCC6hneGuv6SR6+Rw1Mpx9NGJ7VP5WZF3Ek8zihTRGDw9…
  • s2: k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCiQCz6PUf5aeCt86Ilq2W6J7ucajEnfzJHJzaLWM83i7y5zt87WUFfk8fKW5Cy3h9QMJ63Mh1tS8F/EOv1RnaMuV…
selectors probed

Certificate (current)

E7
from 2026-05-01 to 2026-07-30
Expires in 72 days

HTTP security headers

Header hygiene 75/100 Checked live page: https://www.heap.io/

present
  • strict-transport-security
  • content-security-policy-report-only
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • missing Content Security Policy
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
strict-transport-security
max-age=31536000; includeSubDomains
content-security-policy-report-only
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.cookielaw.org https://optly.heap.io https://www.googleoptimize.com https://www.googletagmanager.com https://cdn.us.heap-api.com https://marketo.clearbit.com https://*.wistia.net https://js.chilipiper.com https://js.driftt.com https://*.clearbit.com https://app-ab33.marketo.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.cookielaw.org https://*.ctfassets.net; img-src 'self' data: https://*.ctfassets.net https://www.google-analytics.com https://www.googletagmanager.com https://*.wistia.net https://heapanalytics.com https://*.clearbit.com https://*.doubleclick.net; connect-src 'self' https://*.contentful.com https://*.heap-api.com https://heapanalytics.com https://www.google-analytics.com https://*.wistia.net https://*.doubleclick.net https://*.cookielaw.org https://app-ab33.marketo.com; font-src 'self' data: https://fonts.gstatic.com; frame-src 'self' https://*.wistia.net https:

Links to (7)

Linked from (7)