Skip to content
Login with Google Start free trial
Blog

SEO audit checklist

An SEO audit checklist is a fixed list of checks you run against a website, in the same order every time, so nothing gets missed between audits. This one has 55 checks grouped into six areas, each with a severity, a reason it matters and a free way to test it. It is the list behind a full SEO audit.

By The RankZap team Published Sep 9, 2026 Updated Sep 9, 2026 13 min read
RankZap site audit dashboard showing site health, crawl coverage and page-level issue categories with simulated data
Product demonstration · Fictional, simulated data. Not customer results.

Key takeaways

  • An SEO audit checklist is a fixed list of checks run in the same order on every site, so audits are repeatable and comparable.
  • The 55 checks here cover crawlability, indexing, on-page, content, links, images, performance, mobile, schema, security, URLs and AI readiness.
  • Each check carries a severity: 14 errors that block crawling, indexing or security, 24 warnings that degrade rankings, and 17 notices worth knowing.
  • Every item can be tested free with Search Console, PageSpeed Insights, the Rich Results Test, robots.txt or view source.
  • Run the full list quarterly and the error tier monthly; RankZap runs all 55 automatically on every crawl.

An SEO audit checklist is a structured list of technical, on-page and content checks that a reviewer works through in a fixed order to find the issues holding a website back in search. A useful checklist groups its checks by area, because the fixes for each area belong to different people: crawlability and indexing problems go to the developer, title and description problems go to the content editor, and link problems go to whoever owns the site structure. Each check should state what to look for, why it matters and how to test it, so a second reviewer can confirm a finding without guessing. Most checklists sort findings into three severities. Errors stop pages being crawled, indexed or served securely, warnings lower rankings or user experience, and notices are worth knowing but rarely urgent. The full list is best run once a quarter, with the error tier checked monthly, and the results recorded so the next audit can be compared with the last.

How the 55 checks break down

The checks below are the exact rules an automated crawl applies, written out so you can run them by hand. Each is a yes or no test with a fixed threshold, which is what makes the list repeatable: two people auditing the same site on the same day should tick the same boxes. An error breaks crawling, indexing or security, a warning degrades ranking or user experience, and a notice is worth knowing but rarely urgent.

AreaChecksErrorsWarningsNotices
Crawlability and indexing10424
On-page elements and content14491
Links and images10136
Performance and mobile6330
Structured data, security, URLs and markup14275
AI readiness1001
Total55142417

Clear the errors first regardless of area, then the warnings, then the notices. When two errors compete for the same developer hour, the one affecting more pages wins; the scoring model in how to prioritize SEO issues covers the tie-breaks. Record each finding, the pages affected and the date in an SEO audit template so the next audit has a baseline.

Crawlability and indexing

If a crawler cannot reach a page, or is told not to index it, nothing else on this list matters for that page. These ten checks come first for that reason.

Crawlability

  • No 5xx server errors (error). A server that fails repeatedly on a URL tells Google the page is unreliable and it is dropped from the index. In Search Console, open Pages and filter for "Server error (5xx)".
  • No 4xx errors (error). Not-found and forbidden pages waste crawl budget and dead-end every link pointing at them. Search Console lists them under Pages as "Not found (404)"; fix or 301 each one.
  • Every URL can be opened (error). A DNS failure, timeout or refused connection makes the page unreachable to crawlers as well as visitors. Open the URL in a fresh browser session and retry from a second network if it hangs.
  • Sitemap declared in robots.txt (warning). A Sitemap line in robots.txt lets every crawler find the sitemap without being told. Open /robots.txt and look for a line beginning "Sitemap:".
  • XML sitemap exists (warning). Without a sitemap, deep or new pages depend on internal links alone to be discovered. Try /sitemap.xml and /sitemap_index.xml, then check Search Console's Sitemaps report shows status Success.
  • robots.txt exists (notice). A robots.txt is expected at the root even when it allows everything, and a missing one hands every crawler a 404. Open /robots.txt and confirm it returns plain text, not an error page.
  • No unnecessary redirected URLs (notice). Every redirect hop costs a request and a little link value, and long chains get abandoned. Open a handful of internal links from view source and confirm each resolves in one request.

Indexability

  • Canonical URLs resolve (error). A canonical pointing at a URL that errors is discarded, and the page loses the consolidation signal it meant to send. Find rel="canonical" in view source and open that URL; it should return 200.
  • No accidental X-Robots-Tag noindex (notice). A noindex sent in an HTTP header hides a page from search with nothing visible in the HTML. Run the URL through Search Console's URL Inspection tool and read "Indexing allowed?".
  • No accidental meta robots noindex (notice). A meta robots noindex tag is the most common reason a finished page never ranks. View source, search for "noindex", and confirm any match was deliberate.

On-page elements and content

These fourteen checks cover what a search engine reads first: the title, the description, the headings and the body text. They are the cheapest fixes on the list and usually the most numerous.

Titles and meta descriptions

  • Title tag present (error). Every indexable page needs a title; without one Google invents a headline from whatever text it finds. View source and confirm a title element sits inside the head.
  • No duplicate title tags (error). Pages sharing a title compete for the same query and look templated. Export titles from a free crawler, sort them, and look for repeats.
  • No duplicate meta descriptions (error). Duplicate descriptions waste the snippet and signal thin templating. Sort an export of descriptions the same way and flag any value used on more than one page.
  • Title at least 30 characters (warning). Titles under 30 characters leave result width unused and usually miss a qualifying phrase. Count the title from view source.
  • Title no longer than 60 characters (warning). Titles over 60 characters are truncated in results, often mid-word. Count the title from view source and trim to 60 or fewer.
  • Meta description present (warning). Without a description Google composes a snippet from arbitrary page text. View source and look for a meta tag with name="description".
  • Meta description at least 120 characters (warning). Descriptions under 120 characters under-use the snippet space. Count the description from view source.
  • Meta description no longer than 160 characters (warning). Descriptions over 160 characters are cut off before the call to action. Count it from view source and trim to the 150 to 160 range.

Headings

  • H1 present (warning). The H1 is the strongest on-page signal of what the page is about. View source and search for an h1 tag.
  • H1 differs from the title (warning). An identical H1 and title wastes the chance to cover a second phrasing. Compare the two in view source; the H1 should be shorter and in sentence case.
  • Only one H1 (notice). Multiple H1s are not harmful, but a single one keeps the topic signal unambiguous. Count h1 tags in view source; templates often hide one in the header.

Content

  • No duplicate content (error). Pages sharing near-identical body text cancel each other out and one is usually filtered from results. Search Google for the first paragraph in quotes and see which URLs return.
  • At least 300 words (warning). Pages under 300 words rarely satisfy an informational query and are the first candidates for a thin-content review. Paste the main content into a word counter.
  • Healthy text-to-HTML ratio (warning). When most of the page is markup, the visible text is a small fraction of what the crawler downloads. Compare the word count with the document size under Network in developer tools.

Links are how crawlers find pages and how authority moves between them. Nine of these ten checks are about links; the tenth is the one image check on the list.

  • No broken internal links (error). Links to URLs that return an error waste crawl budget and frustrate whoever clicks them. Search Console's Pages report shows 404s with the referring page; a free crawler lists them per URL.
  • No more than 100 links per page (warning). Over 100 links on a page dilutes the value passed by each and usually means a bloated navigation. Count links in view source or with a free crawler.
  • No nofollow on internal links (warning). Nofollowing your own pages blocks the link equity you meant to pass. Search the source for rel="nofollow" and check whether any match points at your own domain.
  • Nofollow on external links is deliberate (notice). Nofollow on outbound links is often right for sponsored or user-generated content, but should be a decision, not a template default. Review each rel="nofollow" on an external link.
  • No links without anchor text (notice). A link with no anchor text passes no topical signal about its destination. Search the source for anchor tags that contain only an image or nothing at all.
  • No non-descriptive anchor text (notice). "Click here" and "read more" describe nothing to a search engine. Search the page for those phrases and rewrite the anchors to name the destination.
  • No orphaned pages (notice). A page in the sitemap that no crawled page links to cannot be reached by users or by a crawler following links. Compare the sitemap URL list with a crawl export.
  • No page deeper than 3 clicks (notice). Pages more than three clicks from the home page are crawled less often and receive less authority. A free crawler reports depth per URL; sort descending.
  • No page with only one internal link (notice). A single inbound link tells a crawler the page has low internal importance. In a crawl export, sort by inbound links and review everything at 1.

Images

  • Alt attributes on every image (warning). Alt text drives image search and is what a screen reader announces in place of the picture. Search the source for img tags with no alt attribute.

Performance and mobile

These six checks are measured at the HTML response, not in the browser, so they catch server and template problems before rendering starts. Pair them with PageSpeed Insights, where Google's field thresholds are LCP under 2.5 s, INP under 200 ms and CLS under 0.1.

Page speed

  • HTML under 2 MB (error). HTML over 2 MB slows the first render badly, because nothing paints until the document is parsed. Check the document size under Network in developer tools.
  • HTML response under 3 seconds (error). A server that takes over 3 seconds to return HTML fails before a single asset loads. Read the time-to-first-byte figure in PageSpeed Insights.
  • Compression enabled (warning). Gzip or Brotli typically cuts transfer size by 60 to 80 percent. Look for a Content-Encoding response header in developer tools.
  • Cache-Control header set (warning). Without a Cache-Control header every repeat visit refetches the whole page. Check the document's response headers in developer tools.
  • No more than 30 JavaScript and CSS files (warning). Over 30 render-blocking files delays first paint on every visit. Count script and stylesheet requests under Network, or read the render-blocking section of a PageSpeed Insights report.

Mobile

  • Viewport meta tag configured (error). Without a viewport meta tag the page renders at desktop width on phones and every tap target shrinks. View source and confirm a meta tag with name="viewport".

Structured data, security, URLs and markup

These fourteen checks are the ones developers own: two on structured data, three on HTTPS, three on URL shape and six on the basic markup that decides how a browser and a crawler parse the page.

Structured data

  • Structured data parses (error). A JSON-LD block that fails to parse is ignored entirely, so one broken comma removes every rich result on the page. Paste the URL into Google's Rich Results Test and read the errors.
  • Schema markup present (notice). Structured data feeds rich results and gives AI engines a machine-readable statement of what the page is. Run the URL through the Rich Results Test or search the source for ld+json.

Security

  • Pages served over HTTPS (error). Pages served over HTTP are marked "Not secure" in the browser and lose the ranking signal HTTPS carries. Check the padlock on a sample of pages, including old ones linked from deep in the site.
  • HTTP redirects to HTTPS (warning). The HTTP origin should 301 to HTTPS so there is one canonical scheme rather than two copies of the site. Type the address with http:// and confirm the browser lands on https://.
  • HSTS header present (notice). Strict-Transport-Security forces HTTPS on repeat visits without a redirect round trip. Look for that response header in developer tools.

URLs

  • No more than 2 URL parameters (warning). Parameter-heavy URLs create crawl traps and endless duplicates of the same page. Check Search Console's Pages report for "Duplicate without user-selected canonical" and read the URLs it lists.
  • No underscores in URLs (warning). Google treats hyphens as word separators and underscores as joining characters, so an underscored slug reads as one long word. Scan the sitemap for underscores.
  • URLs under 200 characters (notice). Long URLs are hard to share and get truncated in results. Sort the sitemap URL list by length and review the longest.

Technical markup and language

  • Character encoding declared (warning). Without a charset the browser guesses, which mangles accented characters and symbols. View source and confirm a meta charset tag near the top of the head.
  • Doctype declared (warning). A missing doctype triggers quirks mode, which renders CSS inconsistently across browsers. The first line of the source should be a doctype declaration.
  • No framesets (warning). Framesets are obsolete and their content is poorly indexed because each frame is a separate document. Search the source for frameset or frame tags.
  • Language declared (warning). A lang attribute on the html element, or hreflang tags on multilingual sites, tells search engines and screen readers which language to expect. Check the opening html tag in view source.
  • No inline style attributes (notice). Inline style attributes bloat the HTML on every page and bypass CSS caching. Search the source for style= and count the matches.
  • No iframes carrying key content (notice). Content inside an iframe is attributed to the framed document, not to your page. Search the source for iframe tags and confirm nothing important lives only inside one.

AI readiness

One check is about AI crawlers rather than search engines. It is a notice because Google has said it ignores llms.txt and no major AI engine has confirmed reading it. It takes minutes and does no harm, so publish one and move on.

AI crawlers

  • llms.txt present (notice). An llms.txt file at the root points AI crawlers to the pages you most want cited, in plain text they can read without rendering. Open /llms.txt and confirm it lists the site's key pages.

Check the client's homepage before you start the list

Full first result on the page. No email, no account.

SEO audit checklist questions

What should an SEO audit checklist include?

It should cover every area a search engine evaluates: crawlability and indexing, on-page elements and content, links and images, performance and mobile, structured data, security and URLs, and AI readiness. Each item needs a severity and a way to test it, otherwise the list is a wish list. The 55 items above map one to one onto the checks an automated crawl runs, so the list and the tool agree.

What is the difference between an SEO checklist and a technical SEO checklist?

A technical SEO checklist stops at what a crawler can measure: status codes, robots directives, canonicals, speed, markup and security. A full SEO audit checklist adds the content and link items a person judges, such as thin pages, weak anchors and titles that do not match intent. Of the 55 checks here, roughly two thirds are technical and the rest are on-page and content.

How many checks does an SEO audit need?

Enough to cover each area at least once and no more than a team will act on. This list has 55 because that is what a crawl can verify without guessing; a longer list mostly repeats the same finding under different names. Fewer than about 20 leaves gaps in links, performance or structured data that show up later as ranking problems.

Which checks should be fixed first?

Errors first, then warnings, then notices, and within a tier the check that affects the most pages. A 5xx on a template hits every page built from it, so it outranks a missing meta description on one post. Note the effort next to anything over a day of development so the client can weigh it against other work.

Final thoughts

Start with the ten crawlability and indexing checks, because a page that cannot be reached or indexed makes every other item irrelevant. Then clear the errors across the remaining areas before touching a single warning. If you would rather not tick 55 boxes by hand, the free SEO checker runs every one of them on any URL, and the SEO Audit feature repeats the crawl on a schedule so each client's checklist is re-run without anyone remembering to.

Keep learning

Plan your next SEO action with your own data

3-day trial · No card required · Managed AI included

Get started free ↗

Put the audit into practice