SEO Audit Checklist

A full SEO audit checklist covering technical, on-page, content, and off-page factors — what to check, what tools to use, and how to prioritize findings into an action plan.

First published: Jun 27, 2026 · Last updated: Jul 25, 2026 · Advanced
demand #3 in Tools#45 in Technical SEO#61 on the site

A full SEO audit reviews four things — technical health, on-page elements, content quality, and off-page authority — and turns them into a short, prioritized action plan, not a 100–200 item report. The core skill isn't checking more; it's checking what matters and ordering it by impact vs. effort. Start from the pain point, fix crawling/indexing gatekeepers first, then spend most of your time on content unless something technical is genuinely broken. Ship 5–10 findings people will actually implement. This is the broad, full-site version; for the technical-only deep dive, use the Technical SEO Checklist.

TL;DR — A full SEO audit spans technical, on-page, content, and off-page — plus an emerging AI-visibility layer — but its output is a prioritized plan, not an inventory. Start from the pain point, scope so it’s manageable, gather data with a crawlerA crawler — also called a spider or bot — is an automated program that fetches web pages, extracts their links, and queues new URLs to visit. Search engines use crawlers to discover and download content for their index. + Search ConsoleA free Google service that reports how a site performs in Google Search and surfaces problems with how Google crawls, indexes, and serves it. It's first-party data straight from Google — but you don't need it to appear in results. + analytics, then triage by impact vs. effort. Fix crawlingCrawling is how search engines use automated bots (like Googlebot and Bingbot) to discover URLs and download pages. A page has to be crawlable to be indexed, but crawling on its own isn't a ranking factor./indexingStoring a crawled page in the search index so it can appear in results. Crawled is not the same as indexed — Google selects what to keep, and indexing isn't guaranteed. gatekeepers first, but spend most of your time on content unless something technical is genuinely broken. Ship 5–10 findings in a format people will actually implement. For the technical-only deep dive, use the sibling Technical SEOTechnical SEO is the practice of making a site easy for search engines to crawl, render, index, and (now) be eligible for AI answers. It's the foundation that lets your content and links rank — not a ranking trick of its own. Checklist; for very large sites, the Enterprise SEO AuditAn enterprise SEO audit is a systematic evaluation of a large-scale website — usually millions of URLs across multiple CMS platforms, teams, and regions — to find the technical, indexing, content, and link issues that limit organic visibility. Unlike a standard audit, it must account for organizational complexity and ruthless prioritization, because technical perfection at scale is neither possible nor worth paying for..

Evidence for this claim Google Search Console provides performance and indexing reports that can inform an SEO audit. Scope: Google-owned search data; supplement with crawl and business data. Confidence: high · Verified: Google Search Console: Get started Evidence for this claim Google's SEO Starter Guide organizes the core work around crawlability, useful content, links, and search appearance. Scope: Baseline Google guidance, not a complete audit methodology. Confidence: high · Verified: Google Search Central: SEO Starter Guide

What this audit is — and what it isn’t

This is the broad, full-site audit. It’s deliberately wider than the Technical SEO ChecklistA technical SEO checklist is a prioritized list of the technical conditions a site must satisfy — crawlable, indexable, understandable, renderable — so search engines and AI answer engines can access and serve its pages. It's the technical-only slice of a full SEO audit., which is the technical-only floor — crawlabilityCrawlability is how well search engine crawlers can discover, access, and fetch a site's pages. A crawlability issue is any technical condition — blocked access, broken links, server failures, or bloated URL inventory — that stops pages from reaching the index., indexingStoring a crawled page in the search index so it can appear in results. Crawled is not the same as indexed — Google selects what to keep, and indexing isn't guaranteed., HTTPSHTTPS is the encrypted version of HTTP — it uses TLS to authenticate the server and protect data in transit between a browser and a website. Google announced it as a lightweight ranking signal in 2014 and today conditionally prefers HTTPS pages as canonical; Chrome marks plain HTTP pages 'Not Secure.', Core Web VitalsGoogle's three real-user UX metrics — LCP (loading), INP (responsiveness), and CLS (visual stability) — used by Google's ranking systems, with no official weight attached, measured on field data., structured data, sitemapsA sitemap is a file that lists the pages, images, videos, and other files on your site so search engines can discover them. It helps discovery, but submitting a sitemap doesn't guarantee crawling or indexing., robots.txtA plain-text file at the root of a host that tells crawlers which URLs they may and may not request. It controls crawling, not indexing — a blocked URL can still be indexed if it's linked from elsewhere., canonicalizationHow search engines pick one canonical URL among duplicates and consolidate signals onto it., mobile. When you need the deep technical diagnosis, go there. This article covers all of that plus on-page, content, and authority, and — more than anything — how to prioritize across all of it.

It’s also distinct from the size- and vertical-specific audits. Auditing a huge multi-team, multi-CMSA content management system (CMS) is software that lets users create, manage, and publish digital content — like blog posts and pages — without writing raw code. WordPress, Drupal, and Joomla are the most common open-source CMS platforms. site is a genuinely different job (you scope by template, not by page) — that’s the Enterprise SEO AuditAn enterprise SEO audit is a systematic evaluation of a large-scale website — usually millions of URLs across multiple CMS platforms, teams, and regions — to find the technical, indexing, content, and link issues that limit organic visibility. Unlike a standard audit, it must account for organizational complexity and ruthless prioritization, because technical perfection at scale is neither possible nor worth paying for.. Storefronts have their own faceted-nav and variant problems (the Ecommerce SEO AuditAn ecommerce SEO audit is a systematic review of an online store's crawlability, indexation, duplicate content, on-page, technical, and link health — designed to surface the small set of issues that actually hold rankings and revenue back, not to produce a 500-point checklist.), and multi-region sites add hreflangHreflang is an annotation (in HTML, HTTP headers, or XML sitemaps) that tells search engines which language and optional region a page targets, and which alternate versions exist. It only works when every page in the cluster references all the others. and geotargetingConfiguring a site or URL to target users in a specific country. (the International SEO Audit). This general audit is the baseline the enterprise version explicitly departs from.

The philosophy: prioritize, don’t enumerate

The differentiating thesis of a good audit is that exhaustiveness is not rigor. The 1-million-domain site audit study I ran at Ahrefs makes the point in the “What should you fix?” section: “Sometimes, the best course of action is to do nothing because the costs outweigh the benefits.” Not every flag is a problem worth your time.

On the Voices of Search podcast I put the ordering heuristic plainly: “Most of your time is better spent fixing your content unless you have some huge issues with crawlingCrawling is how search engines use automated bots (like Googlebot and Bingbot) to discover URLs and download pages. A page has to be crawlable to be indexed, but crawling on its own isn't a ranking factor. or indexing or something.” That’s the whole prioritization logic in one sentence — technical gatekeepers first if they’re broken, otherwise content is usually where the return is.

And when you deliver, keep it short. In the enterprise-audit context I’ve written that “SEO checklists are impractical at scale” and — the line that generalizes to any site — “I’ve seen several hundred-page documents detailing everything you checked, but no one is going to read those.” The output that gets implemented is “reporting on 5-10 main issues or opportunities.”

The audit process (not just the checklist)

A checklist is what you look at. A process is how you turn it into results. Scaled down from the enterprise version, the shape is:

  1. Start from the pain point. Even for a solo site owner, ask “what’s actually wrong?” before you crawl anything. As I’ve said about client work: “If clients are coming to you asking for an audit, they already have a pain point. Talk to them. Solve that one thing and they’ll be happy with the audit.”
  2. Set scope, in writing. Decide what you’re auditing (whole site? one section? which templates, markets, or subdomains?) and write it down in a line or two — the properties/sections in scope and who owns each one. That short scope note is what keeps a large or multi-template site from turning into an unscoped crawl of everything.
  3. Gather data — and label it. Crawl the site, and pull Search ConsoleGoogle's free tool for monitoring crawling, indexing, and search performance. + analytics. Keep straight what kind of data each source gives you: Search Console’s Performance and Page Indexing reportThe Google Search Console report (formerly Index Coverage) showing how many of your URLs are indexed vs. not indexed, and grouping the not-indexed ones by reason. totals are observed, first-party numbers, but the example URLs GSC lists under an indexing reason are a sample, not a complete inventory of every affected page — don’t treat a handful of examples as the whole picture. On a large or template-driven site, don’t crawl a few convenient URLs and call the result representative; group findings by template, section, or market and sample enough pages from each cohort to say whether an issue is isolated or sitewide.
  4. Prioritize. Score findings by impact vs. effort (below). Discard the low-impact noise.
  5. Deliver a short report. 5–10 findings, in whatever format your implementers actually use — ideally developer-ticket style, tied to business outcomes.
  6. Track implementation, then verify it — don’t assume it. Once something ships, log the release date. A ranking or traffic change after that date isn’t proof the fix worked: Google’s own traffic-drop framework lists concurrent causes — algorithm updates, demand/seasonality shifts, other site changes — that move the same numbers. Watch the specific cohort the fix targeted against a dated baseline for a few weeks before crediting (or blaming) it.

When to run an audit (the triggers)

An audit isn’t a one-time project. Run one when:

  • Traffic or rankings drop. Google’s official guide to debugging search traffic drops is your checklist here. Its first move: “Check the Crawl stats reportA Google Search Console report (under Settings) that shows how Google has crawled your site over the last 90 days — total requests, download size, and average response time, broken down by response code, file type, Googlebot type, and purpose. It's only available for root-level properties (a Domain property or a URL-prefix property verified at the site's root). and Page indexing report to find if there’s a corresponding spike in issues detected.” Then “Check the Manual Actions report on Search Console to see if any have been issued to your website”, “Check the Security Issues reportA Google Search Console report that flags signs your site was hacked or hosts content that could harm visitors — phishing, malware, or unwanted software. It's a user-safety flag, not a spam-policy penalty, and you clear it by fixing the problem and requesting a security review. to find if Google detected a security threat on your website”, and remember that “core updates and other smaller updates may change how some pages perform in Google Search results.” Crucially, Google also flags demand: “Sometimes changes in user behavior will change the demand for certain queries, either due to a new trend, or seasonality throughout the year.” Check Search Console Performance and Google Trends before assuming something broke.
  • Before/after a migration or redesign — the highest-risk moments for SEO.
  • After an algorithm update — to see what moved and why.
  • Before a big content push — to fix the foundation first.
  • On a recurring cadence — quarterly for most sites, monthly for large or fast-changing ones. (That’s common practice, not an official Google/Bing cadence — no such official guidance exists.)

The checklist, by category

Technical & crawlability/indexing

Keep this section short here and go deep in the Technical SEO ChecklistA technical SEO checklist is a prioritized list of the technical conditions a site must satisfy — crawlable, indexable, understandable, renderable — so search engines and AI answer engines can access and serve its pages. It's the technical-only slice of a full SEO audit.. The gatekeeping questions: Is the site crawlable (robots.txt not blocking anything important)? Are your important pages actually indexed (Page Indexing report)? Are sitemaps submitted and clean? Is canonicalization consolidating duplicates correctly? Is HTTPSHTTPS is the encrypted version of HTTP — it uses TLS to authenticate the server and protect data in transit between a browser and a website. Google announced it as a lightweight ranking signal in 2014 and today conditionally prefers HTTPS pages as canonical; Chrome marks plain HTTP pages 'Not Secure.' in place and is the site mobile-friendly? If any of these are broken, they jump to the top of the priority list — nothing downstream matters if pages can’t be crawled or indexed.

One official nuance worth checking during the technical pass: renderingTurning HTML, CSS, and JavaScript into the final visual page and DOM.. Google warns that “if your site is hiding important components that make up your website (like CSS and JavaScript), Google might not be able to understand your pages.”

On-page

This is where audits find the most, and where the volume can trick you into over-reporting. My 1-million-domain study quantified exactly how common these are — the top of the list:

Issue% of sites
3XX redirectsA redirect sends browsers and crawlers from a requested URL to a different one. An HTTP redirect specifically is a 3xx status code paired with a Location header; meta refresh and JavaScript redirects achieve a similar navigation without being a 3xx response themselves. Permanent redirects (301/308) are Google's signal the target should be canonical; temporary ones (302/303/307) aren't.95.2%
HTTP→HTTPS redirects88%
Missing alt attributes80.4%
Missing/empty meta descriptionsThe meta description is an HTML head tag — `<meta name=\"description\" content=\"…\">` — that suggests a short summary of the page for the search snippet. It's not a Google ranking factor, and Google rewrites it the majority of the time, but a good one can still lift click-through.72.9%
Slow pages72.3%
Page and SERP title mismatch68.5%
Only a single dofollow internal linkAn internal link is a hyperlink from one page on a website to another page on the same website. Internal links help search engines discover your pages and pass ranking signals (PageRank and anchor-text context) between them.66.2%
Title too long63.2%
Links to redirects62.7%
Missing/empty H1 tagsAn H1 tag is the HTML `<h1>` element that marks a page's primary heading — the big visible headline at the top of the content. It helps users, search engines, and screen readers understand what the page is about.59.5%

The catch: common is not the same as important. On meta descriptions specifically, my take from that study is candid: “I don’t focus much on meta descriptions. If it’s a page that’s important to you and you can write a better meta description that fits, go for it.” Fix the on-page issues on pages that matter; don’t burn a week normalizing alt text sitewide because a tool turned 80% of your pages red.

Content

For most sites this is where the real return lives. Audit for:

  • Quality. Google’s guidance is that good content is “easy-to-read and well organized,” “unique,” kept up to date, and “helpful, reliable, and people-first.” Assess depth relative to search intent — not word count. (Word count isn’t a ranking factor; don’t flag “thin” pages by a number alone.)
  • Gaps. What topics should you cover for your audience that you don’t yet?
  • Outdated pages. Updating strong old content usually beats publishing new content. I keep pushing this in talks and podcasts because it’s underrated.
  • Pruning candidates. Pages that get no traffic, no links, and serve no purpose.

One myth to kill here: E-E-A-T is not a ranking factor you should score. Google’s own SEO starter guide has a section literally titled “Thinking E-E-A-T is a ranking factor” and answers it “No, it’s not.” It’s content-creation guidance, not an audit metric.

Off-page / authority

  • Backlink profile — do you have links from relevant, credible sites, and how do you compare to competitors?
  • Dead pages with backlinks — one of the highest-ROI checks. If a page that other sites link to now 404s, you’re leaking authority; redirect it to a relevant live page.
  • Brand mentions — unlinked mentions and general brand presence.

A caution on the flip side: don’t over-disavow. Aggressively disavowing “toxic” links is a known industry over-correction. Most sites should not disavow without clear evidence of a manual action or genuine spam impact.

AI / answer-engine visibility (forward-looking)

Newer, and honestly not fully proven yet — keep it principle-level. Can AI crawlersAI crawlers are bots from AI companies that fetch web pages to train language models, build AI-search indexes, or answer live user questions. They come in three categories, each with its own user-agent tokens and its own robots.txt controls. access your content? Is your structured dataStructured data is a standardized way of labeling page content (using the schema.org vocabulary in JSON-LD, Microdata, or RDFa) so search engines can understand its meaning. It's not a direct ranking factor — its value is rich results and entity understanding. in place so engines can parse entities? Is your brand showing up (and cited correctly) in AI answers? Worth a look on modern audits; not worth fabricating a scoring rubric around.

Prioritization: the impact/effort framework

This is the section most competitor checklists skip, and it’s the one that makes an audit useful. Score every finding on two axes — impact (how much will fixing it help) and effort (how hard/expensive is the fix) — and plot a 2×2:

Low effortHigh effort
High impactDo first — quick winsPlan it — big projects worth scheduling
Low impactBatch it — fill-in workSkip it — often the right call

Two framings I lean on hard:

  • “Sometimes, the best course of action is to do nothing because the costs outweigh the benefits.” The bottom-right quadrant is real. Not fixing something is a valid, often correct, audit recommendation.
  • Equate fixes to money. “You should try to equate fixes to cash. This is what businesses care about.” Reframing a fix from “301 these old URLs” to “recover the link equity on pages worth six figures in traffic value” is what gets it prioritized and shipped.

The 2×2 is the mental model, but a finding needs more than an impact/effort guess to survive scrutiny. For each one, record: what you observed, the affected cohort (a template, section, or market — not just “the site”), the evidence behind it, your confidence in it, the effort to fix, the risk of the fix (or of leaving it), any dependencies (a dev sprint, a CMS change, another team), and who owns it. That’s what turns “raise the priority” from a gut call into something a stakeholder can act on — and it’s worth saying plainly: a finding earning a spot on this list is an observation and a recommendation, not implementation approval. That’s a separate call for whoever owns the page or the budget.

TIP Start the technical slice with a scoped crawl, not a mystery score

A broad SEO audit still needs content, authority, Search Console, and business analysis. This crawl is the technical baseline, with its coverage and blind spots stated.

Get a fast raw-HTML baseline with my free Scout Site Audit Free Free

  1. Run the whole site or a representative section and record discovered versus crawled coverage.
  2. Group recurring findings by template and map them to impact, affected scale, and effort.
  3. Verify the priority patterns in Search Console and rendered pages before turning them into recommendations.
The score is secondary; scope, repeatable findings, and declared blind spots make the output usable in an audit.

The sample report has an 82 out of 100 raw-HTML score. It crawled 24 of 31 discovered URLs, labels the crawl partial, reports two missing-title warnings across 24 checked pages, and says rendered JavaScript and AI checks were not evaluated.

Common myths this audit debunks

  • More items = more thorough. No — 13 focused items beat 200 unread ones.
  • E-E-A-T is a ranking factor to score. Google says it isn’t.
  • Bounce rate / word count are ranking factors to flag. Neither is a direct ranking factor; assess content against intent, not metrics.
  • An audit is a one-time project. It’s triggered and recurring.
  • SEO studies tell you what to fix. They tell you what’s common — including my own 1M-domain study. Common isn’t causal, and it isn’t always worth fixing on your site.

Where to go next

For the technical-only depth this article intentionally skips, use the Technical SEO ChecklistA technical SEO checklist is a prioritized list of the technical conditions a site must satisfy — crawlable, indexable, understandable, renderable — so search engines and AI answer engines can access and serve its pages. It's the technical-only slice of a full SEO audit.. For scaling the process to massive sites, the Enterprise SEO AuditAn enterprise SEO audit is a systematic evaluation of a large-scale website — usually millions of URLs across multiple CMS platforms, teams, and regions — to find the technical, indexing, content, and link issues that limit organic visibility. Unlike a standard audit, it must account for organizational complexity and ruthless prioritization, because technical perfection at scale is neither possible nor worth paying for.; for stores and international sites, the EcommerceAn ecommerce SEO audit is a systematic review of an online store's crawlability, indexation, duplicate content, on-page, technical, and link health — designed to surface the small set of issues that actually hold rankings and revenue back, not to produce a 500-point checklist. and International audit guides.

Add an expert note

Pin an expert quote

New person? Create their unclaimed profile at /admin/experts/ → Pin a quote first.