Technical SEO audit checklist
Go through the site step by step: mark what is fine and where the issues are, leave notes and get a ready list of fixes sorted by priority.
- OK
- 0
- Issues
- 0
- N/A
- 0
- Left
- 126
01 Crawling and indexing
0 / 10
-
robots.txt exists, returns 200 and does not block important sections
Open /robots.txt. Make sure there is no accidental "Disallow: /" and that CSS, JS and images are not blocked.
Critical -
sitemap.xml is valid, up to date and listed in robots.txt
Only canonical pages with code 200 belong in the sitemap: no redirects, 404s, noindex pages or parameters.
Critical -
The site is verified in Google Search Console, the sitemap is submitted
Use a Domain property so that all protocols and subdomains are covered. Check that the sitemap status is "Success".
Critical -
The "Pages" report in GSC has no critical indexing errors
Review the reasons: "Crawled — currently not indexed", "Duplicate without user-selected canonical", "Soft 404", server errors 5xx.
Critical -
Important pages are not closed by noindex or X-Robots-Tag
Crawl the site (Screaming Frog, Sitebulb) and filter by "noindex". A typical mistake is a noindex left over from the staging version.
Critical -
The number of indexed pages matches the real number of useful pages
Compare: pages in the sitemap, pages found by the crawler and pages indexed in GSC. A big gap means junk in the index or lost pages.
Important -
Service and junk pages are closed from indexing
Site search, cart, checkout, account, sorting, UTM and session parameters, print versions.
Important -
Test and dev versions of the site are closed from search engines
The best protection is HTTP authorisation. Check with the query site:dev.example.com and by subdomains in GSC.
Critical -
Server logs are analysed: Googlebot spends the crawl budget on important pages
Relevant for sites with 10,000+ URLs. Look at which sections the bot visits most often and which it never reaches.
Recommended -
All subdomains are accounted for: no forgotten ones that duplicate the main site or sit in the index
Query site:example.com -inurl:www plus a subdomain search (crt.sh, Ahrefs). Old m., shop., dev. and promo versions are redirected, closed from indexing or kept on purpose.
Important
02 Mirrors, redirects and response codes
0 / 9
-
One main mirror: http → https and www ↔ non-www with a single 301
Check all four variants of the home page and an inner page. Each must lead to the main version in one step.
Critical -
Trailing slash, letter case and /index.php (.html) are brought to one format
/page and /page/, /Page and /page, /index.php must not open as separate pages with code 200.
Important -
Multiple slashes (//, ///) in the URL are redirected or return 404
Open example.com///page — the address must not respond with 200 as a duplicate.
Recommended -
No redirect chains or loops
Every redirect leads to the final URL in one hop. Chains of 3+ steps waste crawl budget and slow the page down.
Important -
Permanent moves use 301 (308), not 302 or JavaScript / meta refresh
Temporary 302 redirects that have been in place for months should be replaced with 301.
Important -
A non-existent page returns a real 404 (410), not 200 or a redirect to the home page
Open a random address like /qwerty-12345 and look at the response code. The 404 page should have navigation and a link to the home page.
Critical -
No internal links to 404 pages and to redirects
In the crawler report: Response Codes → Client Error (4xx) and Redirection (3xx) → Inlinks. Replace the links with the final URLs.
Critical -
No 5xx server errors during the crawl and in GSC
GSC → Settings → Crawl stats → By response. Frequent 5xx reduce the crawl rate and drop pages from the index.
Critical -
The 404 page is in the site design: navigation, search and links to the main sections
It helps the visitor stay on the site instead of leaving. The response code must still be 404.
Recommended
03 Duplicates and canonical
0 / 8
-
Every indexable page has a self-referencing rel=canonical with an absolute URL
One canonical tag per page, in <head>, in the initial HTML (not added by JavaScript).
Critical -
Canonical points to a page with code 200 that is open for indexing
Canonical to a redirect, 404 or noindex page is ignored by Google. Do not combine canonical to another page with noindex.
Critical -
URLs with parameters (sorting, UTM, gclid, session) do not create duplicates
Such addresses must have a canonical to the clean URL. Internal links should not contain tracking parameters.
Critical -
No duplicate title and description across pages
Crawler report: Page Titles → Duplicate, Meta Description → Duplicate. Most often these are pagination, filters and product variants.
Important -
No full or near duplicates of content on different URLs
One product in several categories with different addresses, identical category texts, copies of pages for different cities with one word changed.
Important -
Pagination pages are indexable, have their own canonical and unique title
Do not put a canonical from page 2, 3… to the first page — Google will stop seeing the products from deeper pages. Add "— page N" to the title.
Important -
The canonical chosen by Google matches the one declared on the site
GSC → URL Inspection → "Google-selected canonical", and the Pages report → "Duplicate, Google chose different canonical than user". A mismatch means Google treats the pages as duplicates.
Important -
The first pagination page has no duplicate (?page=1, /page/1), and the category text is not repeated on pages 2, 3…
?page=1 should 301 to the category URL. Show the SEO text and the FAQ block on the first page only.
Important
04 URLs and site structure
0 / 6
-
URLs are human-readable: short, lowercase, hyphens, no IDs and junk
The address shows what the page is about. No underscores, spaces, Cyrillic or parameters where a static URL is possible.
Important -
Important pages are no deeper than 3 clicks from the home page
Crawler report: Crawl Depth. Pages at depth 5+ are crawled rarely and rank worse.
Important -
No orphan pages (pages without internal links)
Compare the sitemap and GSC data with the list of pages the crawler found by links.
Important -
Breadcrumbs are on all inner pages and reflect the real structure
Every level is a link, the last element is the current page without a link. Marked up with BreadcrumbList.
Important -
Navigation is built with regular <a href> links available in HTML
Menus on onclick, buttons or links that appear only after an interaction are not followed by search bots.
Critical -
Each group of queries has its own landing page, there is no cannibalisation
In GSC check queries for which two or more URLs alternate in search results.
Recommended
05 Meta tags and headings
0 / 7
-
Every page has a unique, non-empty title up to ~60 characters
The main query is closer to the beginning. Check: missing, duplicate, too long and too short titles.
Critical -
Meta description is filled in, unique, up to ~155 characters
It does not affect rankings directly, but it affects the snippet CTR. Add a benefit and a call to action.
Important -
Exactly one H1 per page, and it differs from the title
Check pages without H1 and with several H1. The logo and the site name in the header must not be an H1.
Critical -
H2–H6 hierarchy is logical, headings are not used for design
No headings in the menu, footer and sidebars. Levels are not skipped (H2 → H4).
Recommended -
Open Graph and Twitter Card tags are set
og:title, og:description, og:image (1200×630), og:url. Check how the link looks in Telegram and LinkedIn.
Recommended -
HTML is valid in critical places: one <head>, lang, UTF-8 charset, viewport
A broken <head> (for example, a <div> or <img> inside it) makes Google ignore everything below — including canonical and hreflang.
Recommended -
Favicon is available to Googlebot and is a multiple of 48 px
Otherwise Google shows a default globe in the search results instead of your icon.
Recommended
06 Speed and Core Web Vitals
0 / 9
-
Core Web Vitals are "Good" on field data: LCP ≤ 2.5 s, INP ≤ 200 ms, CLS ≤ 0.1
Look at real user data: the "Core Web Vitals" report in GSC and the CrUX block in PageSpeed Insights, not only the lab score.
Critical -
Server response time (TTFB) is under 0.8 s
Check several page types: home, category, product, article. Slow TTFB is fixed with caching, a CDN and query optimisation.
Critical -
Text compression (Brotli or gzip) and HTTP/2 or HTTP/3 are enabled
In DevTools → Network look at the content-encoding header and the Protocol column.
Important -
Static files are cached in the browser for a long time (Cache-Control)
Images, CSS, JS and fonts — max-age of a year with a version in the file name or in a parameter.
Important -
No render-blocking CSS and JS in <head>; scripts are loaded with defer / async
Critical CSS is inline or in one small file. Third-party widgets, chats and trackers are loaded after the main content.
Important -
The LCP element (main image or heading) loads first: preload, fetchpriority="high", no lazy-load
PageSpeed Insights shows which element is the LCP. A common mistake is loading="lazy" on the first-screen image.
Important -
No layout shifts: images and banners have width / height, fonts use font-display: swap
Space is reserved for ads, cookie bars and dynamically inserted blocks.
Important -
Fonts are in WOFF2, self-hosted, only the needed weights and subsets
The main text font is preloaded. Each extra weight is another 20–40 KB.
Recommended -
A CDN is used for static files (for large or international projects)
Compare TTFB from different countries (WebPageTest, KeyCDN Performance Test). If the audience and the server are in the same country, a CDN is not required.
Recommended
07 Mobile version
0 / 4
-
Responsive layout, meta viewport is set, no horizontal scrolling
Check on a real phone and in DevTools at a width of 360 px.
Critical -
The mobile version has the same content, links, meta tags and markup as the desktop one
Google indexes the mobile version (mobile-first). Text, menu items or structured data hidden on mobile are lost for search.
Critical -
Buttons and links are easy to tap (at least 44×44 px), text is 16 px or larger
Elements are not too close to each other; forms do not zoom the page on focus.
Important -
No intrusive pop-ups covering the content on the first screen
Full-screen banners right after a visit from search are a reason for demotion (intrusive interstitials).
Important
08 JavaScript and rendering
0 / 5
-
The main content, links and meta tags are present in the source HTML (SSR / prerender)
Compare "View source" with the rendered DOM. Disable JavaScript and see what remains on the page.
Critical -
Google renders the page correctly: URL Inspection → "View tested page"
Look at the screenshot, the HTML and the list of resources that failed to load.
Critical -
Links work without JavaScript: <a href>, not onclick or #hash routes
In SPAs, every state that should rank needs its own URL through the History API.
Critical -
Lazy-loaded content and "Show more" lists are available to the bot
Googlebot does not scroll or click. Infinite scroll needs paginated URLs with regular links.
Important -
No JavaScript errors in the console that break the content or navigation
DevTools → Console on the main page templates.
Recommended
09 Structured data
0 / 13
-
Structured data passes the Rich Results Test without errors
Also look at the "Enhancements" reports in GSC — errors and warnings for each markup type.
Important -
Organization / LocalBusiness / Person and WebSite are on the home page
Name, logo, contacts, sameAs with links to social profiles. This helps both the knowledge panel and AI answers.
Important -
BreadcrumbList is on inner pages
The markup matches the visible breadcrumbs.
Important -
Key templates have the right type: Product + Offer, Article, FAQPage, Service, Review
For products: price, currency, availability, rating. For articles: author, publication and modification dates.
Important -
The markup matches the visible content of the page
Ratings, prices and reviews that the user does not see on the page lead to a manual action.
Critical -
Blog posts and news have Article / BlogPosting (NewsArticle) markup
Fields: headline, image, datePublished, dateModified, author, publisher. The dates match the ones visible on the page.
Important -
The article author is marked up as Person and linked to an author page
In Article.author: name, url of the author page, jobTitle, sameAs (LinkedIn and other profiles). The author page itself has ProfilePage + Person. This is a direct E-E-A-T signal.
Important -
Product pages have Product + Offer, and AggregateRating + Review when there are reviews
In Offer: price, priceCurrency, availability; plus name, image, sku / gtin, brand. Mark up only real reviews that are visible on the page. Add shippingDetails and hasMerchantReturnPolicy for merchant listings.
Critical -
Categories and listings have CollectionPage + ItemList
ItemList contains the items of the current page with position and url. On pagination pages — only the items of that page.
Important -
Pages with a question-and-answer block have FAQPage
Only the questions and answers that are visible on the page. Google now shows the FAQ rich result for few sites, but the markup still helps AI answers parse the content.
Recommended -
Service pages have a specific type: AboutPage, ContactPage, WebPage
About, Contacts, Delivery and payment. Link the page to the site through isPartOf → WebSite and to the company through about / publisher.
Recommended -
Self-hosted videos have VideoObject
Fields: name, description, thumbnailUrl, uploadDate, contentUrl or embedUrl. For YouTube embeds the markup is optional.
Recommended -
Key images are marked up: ImageObject or the image property in Article / Product
Fields: url, width, height, caption. For your own photos add license and creator — they give the "Licensable" badge in Google Images.
Recommended
10 Language versions and hreflang
0 / 5
-
Each language version has its own URL (folder, subdomain or domain)
Switching the language through cookies or a parameter without a separate address is not indexed.
Critical -
hreflang is reciprocal, includes a self-reference and x-default
If page A points to B, then B must point to A. Codes follow ISO: uk — the Ukrainian language, ua is not a language code.
Critical -
hreflang points to canonical pages with code 200
No links to redirects, 404 and noindex pages. The canonical of every version points to itself, not to another language.
Important -
No forced redirect by IP or browser language
Googlebot crawls mostly from the USA — with a forced redirect it will never see other versions. Offer the version with a banner instead.
Important -
Everything is translated: title, description, H1, alt, URL, interface elements
The lang attribute of the <html> tag matches the language of the page. No mixed-language pages.
Important
11 Images and media
0 / 5
-
Images are in WebP / AVIF and compressed
Crawler report: Images → Over 100 KB. Heavy PNG and JPEG files are the most common cause of a poor LCP.
Important -
Image dimensions match the display size, srcset is used for different screens
A 3000 px photo in a 400 px block wastes traffic and time.
Important -
Meaningful images have a descriptive alt
Describe what is in the picture, without a list of keywords. Decorative images have an empty alt="".
Important -
Images below the first screen have loading="lazy"
Use the native attribute, not a JS library that replaces src with data-src — the bot may not see such images.
Important -
No broken images and images blocked in robots.txt
Crawler report: Images → Response Codes 4xx. Files are served from your domain or a CDN available to bots.
Important
12 Security and server
0 / 10
-
A valid SSL certificate, the whole site works over HTTPS
Check the expiry date and automatic renewal. The certificate covers www and all subdomains in use.
Critical -
No mixed content: all resources and internal links use https
Crawler report: Security → Mixed Content, HTTP URLs. Also check canonical, hreflang and the sitemap.
Important -
Security headers are set: HSTS, X-Content-Type-Options, Referrer-Policy, CSP
A quick check — securityheaders.com. HSTS additionally removes the http → https redirect for returning visitors.
Recommended -
No manual actions or security issues in GSC
GSC → Security & Manual Actions. Also check the domain in Google Safe Browsing.
Critical -
No signs of hacking: foreign pages in the index, hidden links, redirects for mobile users
Check the query site:example.com with words like casino, viagra, and Japanese or Chinese characters.
Critical -
Uptime is 99.9% or higher, monitoring and backups are set up
UptimeRobot or a similar service with notifications. Check that a backup can actually be restored.
Important -
Users and search bots receive the same content
Compare the page with a regular User-Agent and with Googlebot. Make sure the firewall, CDN or anti-bot protection does not block real Googlebot.
Critical -
The domain and IP are not on blacklists: Google Safe Browsing, antivirus databases, spam lists
Check the Google Safe Browsing site status (transparencyreport.google.com), VirusTotal and Sucuri SiteCheck, and Spamhaus / MXToolbox for the IP and the mail domain.
Critical -
Forms are protected from spam and bots: reCAPTCHA, Turnstile or a honeypot
Without protection spam leads clog the CRM, and open comment and search forms are used to generate spam pages and links. Load the protection script only when the form is used, so that it does not slow the page down.
Important -
The domain history is checked: past content, sanctions, spammy backlinks
The Web Archive (web.archive.org) shows what used to be on the domain; Ahrefs or Serpstat show the backlink profile and traffic drops. Especially important for a purchased or dropped domain.
Important
13 Internal linking
0 / 5
-
Priority pages get the most internal links
Crawler report: Inlinks / Link Score. Money pages should not have fewer links than the privacy policy.
Important -
Anchors are descriptive, not "here", "more", "read"
The link text tells the user and the bot what is on the target page. One page — different but relevant anchors.
Important -
Internal links are not closed with rel="nofollow"
nofollow inside the site does not "save weight" — it simply throws it away.
Important -
External links are alive; advertising and user links have rel="sponsored" / "ugc"
Crawler report: External → Client Error (4xx). Comments and profiles are moderated.
Recommended -
There are contextual links between related pages: articles ↔ categories ↔ products
Blocks like "Related articles", "Similar products", links from blog articles to commercial pages.
Recommended
14 E-commerce: filters, catalogue, products
0 / 6
-
Filters are under control: useful combinations are landing pages, the rest are closed
Filter pages with demand have a static URL, unique title, H1 and are in the sitemap. Combinations of 2–3+ filters are closed from indexing.
Critical -
Sorting, view type and items-per-page do not create indexable pages
Canonical to the page without parameters, or the parameters are closed in robots.txt.
Important -
Out-of-stock products are handled correctly
Temporarily unavailable — code 200 with the status and alternatives. Gone forever — 301 to an analogue or the category, or 410.
Important -
Product variants (colour, size) do not create duplicates
Either one page with a selector, or separate pages with unique content and a canonical to the main variant.
Important -
No empty categories and thin pages with 1–2 products in the index
Empty listings are treated by Google as Soft 404 and lower the overall quality assessment of the site.
Important -
Product markup and the Merchant Center feed contain the same prices and availability
A mismatch leads to disapproved products and the loss of free product listings.
Recommended
15 AI search and GEO
0 / 5
-
AI crawlers are not blocked by accident: GPTBot, OAI-SearchBot, ClaudeBot, PerplexityBot, Google-Extended
Check robots.txt and the firewall / CDN rules (Cloudflare blocks AI bots by default on some plans). Decide deliberately which bots you allow.
Important -
Key content is available without JavaScript — most AI bots do not render it
Prices, characteristics, answers to questions and contacts must be in the source HTML.
Important -
Content is structured for citation: a direct answer first, lists, tables, FAQ
Question-style headings and short self-contained paragraphs are quoted by AI answers more often.
Recommended -
Authorship and expertise are visible: author, dates, sources, "About" page
Person and Organization markup with sameAs links the site with profiles and mentions on other platforms.
Recommended -
llms.txt with a short description of the site and links to key pages is added
It is not a standard yet and gives no guarantees, but it takes ten minutes and does no harm.
Recommended
16 Analytics and monitoring
0 / 7
-
GA4 (or another analytics system) is installed on all pages and counts conversions
Crawler → Custom Search for the tag ID: find pages without the code. Check that key events fire (form, purchase, call).
Critical -
GSC is linked with GA4; a Bing Webmaster Tools account is created
Bing data is also used by ChatGPT search and Copilot — the sitemap is worth submitting there too.
Recommended -
Position and visibility tracking is set up for the main queries
Without a "before" snapshot it is impossible to evaluate the effect of the fixes after the audit.
Important -
Alerts are set up: traffic drop, growth of 404 / 5xx, changes in robots.txt and noindex
Email alerts from GSC are on; a scheduled crawl compares the site with the previous version.
Recommended -
A repeat audit is scheduled after the fixes and after every release
Technical errors come back with new features, redesigns and CMS updates. Check monthly, and for large sites — weekly.
Recommended -
The GA4 / GTM code is installed once, with no duplicates
Two tags double the page views and distort engagement and conversion rates. Check with Tag Assistant and in the page source: one GTM container, and GA4 is not installed both directly and through GTM.
Critical -
E-commerce and key events are tracked: purchase, add_to_cart, begin_checkout, forms, clicks
purchase sends transaction_id, value, currency and items with item_id. Place a test order and check it in DebugView; compare the number of orders in GA4 and in the CRM.
Important
17 Content and page quality
0 / 4
-
No empty pages, stubs or "under construction" pages on the site and in the index
Crawler → filter by word count (Low Content Pages). Lorem ipsum, test products, empty tag and category pages: fill them in, close with noindex or remove.
Critical -
Texts are unique: not copied from other sites or from the manufacturer
Check key pages with a plagiarism checker (Copyscape) or search for a sentence in quotes. Also check whether other sites have copied your texts.
Important -
No hidden text or links: display:none, text in the background colour, off-screen positioning
Content in tabs and accordions is fine. Text that is hidden from users but left for bots violates the Google spam policies.
Important -
No affiliate sites: several sites of one owner with the same products, contacts and content
Google may show only one of them or treat them as doorways. Look for matching phone numbers, addresses, company details and WHOIS. Merge the sites with 301 redirects or make them really different.
Important
18 Site functionality
0 / 4
-
All forms, buttons, links and calculators work, and the leads actually arrive
Send a test request from every form on desktop and on a phone. Check that it reaches the email, CRM or messenger and that the user sees a confirmation.
Critical -
The path to a purchase or sign-up is walked through to the end without errors
Product → cart → checkout → payment → confirmation email. Check in different browsers, on a phone, and both as a guest and as a logged-in user.
Critical -
Site search, filters and sorting work correctly
Search finds products by name, by SKU and with typos; an empty result offers alternatives. Filters do not lead to empty pages and do not reset each other.
Important -
The CMS lets you edit the SEO fields on every page type
Title, description, H1, text, URL, canonical, robots, alt and redirects — for the home page, categories, products, articles and filter pages, plus templates for bulk generation. Without this the audit fixes cannot be implemented.
Important
19 Regional targeting and local SEO
0 / 4
-
The target country and region are clear to Google: domain or folder, hreflang, currency, address, phone
A country domain (.ua, .pl) or a country folder with hreflang, the local currency and phone format, the address in the footer and on the contact page. The server location hardly matters.
Important -
A Google Business Profile is created, verified and filled in (for a business with an address or a service area)
The right category, opening hours, photos, a link to the site with a UTM tag. Reviews get answers.
Important -
Name, address and phone (NAP) are identical on the site, in LocalBusiness markup, in the Business Profile and in directories
Different spellings of the address and old phone numbers lower trust in the data. In LocalBusiness: address, geo, openingHoursSpecification, telephone.
Important -
Each city or branch has its own page with unique content
Address, map, local phone, prices and reviews of that branch. Pages that differ only in the city name are doorways.
Recommended
Found issues and not sure where to start?
Send me the report — I will tell you what really affects traffic and what can wait.
From the first check to a list of fixes
- 01
Crawl the site
Run a crawler and open Google Search Console — most of the checks rely on their reports.
- 02
Mark the status
For each item choose: OK, issue or not applicable. Add a note with example URLs to the issues.
- 03
Take the report
Copy the list of issues sorted by priority, download a CSV for a task tracker or print it to PDF.
Questions about the checklist
Missing an important check? Write to me — I will add it.
Where is my progress saved?
In your browser (localStorage), on this device only. Nothing is sent to the server and no sign-up is needed. To hand the result over, use "Copy the report", CSV export or print to PDF.
What tools do I need for the audit?
Google Search Console, a crawler (Screaming Frog SEO Spider, Sitebulb or Netpeak Spider), PageSpeed Insights, the Rich Results Test and browser DevTools. This is enough for 90% of the checks.
In what order should I fix the issues?
Start with the "Critical" ones: they prevent pages from being crawled and indexed at all. Then "Important" — duplicates, speed, structure. "Recommended" items give a smaller effect and are done last. The report sorts the issues in this order.
How often should a technical audit be done?
A full audit — once every 6–12 months and always before and after a redesign, migration or CMS change. A short check of the critical items — monthly, for large e-commerce sites — weekly.