Skip to content
Login with Google Start free trial
Guides

How to do an SEO audit

An SEO audit is a structured review of a website that finds the technical, content and link problems stopping it from being crawled, indexed and ranked, then ranks those problems by how much they matter. We run one on every client site we manage, and this guide walks through the same steps in the same order.

By The RankZap team Published Sep 7, 2026 Updated Sep 9, 2026 18 min read

Key takeaways

  • An SEO audit is a structured review of a site's indexing, content, links, performance and AI readiness, each finding tied to a URL and a fix.
  • Start with a full crawl and a Search Console export, because everything after that is checking the crawl against what Google reports.
  • Work through the five areas in order: indexing first, because a page that cannot be indexed makes every other fix on it pointless.
  • Prioritize by severity, pages affected and effort, then write the findings up so the client can act without you in the room.
  • A small site takes about a day to audit; we re-run RankZap's 55 automated checks weekly and do a full audit twice a year.

An SEO audit is a structured review of a website's ability to be crawled, indexed, understood and ranked by search engines. A complete audit works through five areas in order: indexing (can search engines reach and index the pages), content (do titles, descriptions, headings and body text describe each page), links and structure (can every important page be reached through internal links), performance (does the page load and respond quickly on mobile) and AI readiness (can AI crawlers read the site and its structured data). Each finding is recorded with the URL it affects, a severity and a fix. Automated crawlers handle the mechanical checks across hundreds of pages in minutes; a person then judges intent, quality and business context. Most sites should be fully audited twice a year, with the automated checks re-run after every significant release to catch regressions.

If you want the same steps as a tick list, the SEO audit checklist covers all 55 checks by area. This guide explains why each step exists and what to do with what you find.

What is an SEO audit?

An SEO audit answers one question: what is stopping this site from being found, read and ranked? It is not a report on rankings or traffic. Those are outcomes. The audit looks at causes: pages that return errors, titles that repeat, links that go nowhere, pages that take four seconds to arrive, structured data that does not parse.

The output is a list of findings. Each finding names the check that failed, the URLs it affects, how serious it is and what to change. That list is the whole product. A score at the top is a convenience for the client; the list is what gets fixed.

We split the work into five areas and run them in the same order every time. Indexing comes first because a page Google cannot index makes every content or speed fix on it wasted effort. Content and links come next because they decide what a page is about and whether it can be reached. Performance follows, and AI readiness comes last because it depends on the four areas before it.

You need three things before you start: crawl access to the site (no login wall, no IP block on your crawler), a Search Console property you can read, and a place to write findings down.

How to do an SEO audit

The 15 steps below follow the five areas in order. Each one says what to check, the free way to check it, the equivalent view in RankZap, and what to do with the result. The first two steps set up everything else.

1. Crawl the whole site

Everything in an audit starts with a crawl: a program that opens the homepage, follows every internal link, and records what it finds on each page. Doing this by hand on a 200-page site is not realistic, and doing it on a 20-page site by hand is how things get missed. Googlebot works the same way, so a crawl predicts what Google will see.

Free route: put the homepage through the free SEO checker. It grades that one page on about 105 checks without asking for an email, which tells you within a minute whether the basics (title, meta description, HTTPS, speed, structured data) are in place before you spend a day on the full audit.

In RankZap, open the SEO audit tool, enter the domain and start the crawl. The Errors, Warnings and Notices tabs then list every failed check with the pages it affects.

Keep the crawl open. Every step from here on is either reading a row in it or checking that row against Google.

2. Connect Search Console and export the last three months

A crawl shows what the site looks like today. Search Console shows what Google actually did with it: which pages it indexed, which it refused and why, and which queries sent clicks. Google documents each status in the Page indexing report help page, so an unfamiliar status can be looked up rather than guessed at.

Free route: in Search Console, open Pages under Indexing and note every reason under "Why pages aren't indexed". Then open Performance, set the range to the last three months, and export queries and pages.

In RankZap, open Connections, choose Google connections, and connect the Search Console property so the audit shows indexing status and clicks next to each flagged page.

Now you have two sources that should agree. Where they disagree is usually where the first real finding is.

3. Check robots.txt and the XML sitemap

robots.txt tells crawlers which paths they may fetch; the XML sitemap tells them which URLs you want indexed. A disallow rule on the wrong folder hides a whole section, and a missing or undeclared sitemap slows discovery. Google's robots.txt introduction and sitemaps overview describe what each file should contain.

Free route: open yourdomain.com/robots.txt and read every Disallow line. Then open the sitemap (usually /sitemap.xml), confirm it lists live URLs, and check that robots.txt has a Sitemap line.

In RankZap, the crawl flags robots.txt not found (notice), sitemap.xml not found (warning) and sitemap.xml not specified in robots.txt (warning).

Record any Disallow rule that covers a page you want ranked. That is the first fix, before anything else in this guide.

4. Find pages that return errors

A page that returns a 404, a 403 or a 5xx cannot be indexed, and a page that times out or fails DNS is invisible to every crawler. Google's Page indexing report lists persistent 5xx URLs as unindexed, so a 5xx that has been live for weeks is already costing rankings.

Free route: in Search Console, the Pages report lists "Not found (404)" and "Server error (5xx)" as separate reasons with example URLs. A free crawl gives the full list rather than a sample.

In RankZap, open the Errors tab. The three crawlability errors are 5xx server errors, 4xx errors and "Couldn't open the page's URL", each with the affected URLs.

For each URL decide one of three things: restore it, redirect it to the closest live page, or let it stay gone and remove the links pointing at it.

5. Review indexing status and noindex directives

A page can be reachable and still be kept out of the index by a meta robots noindex tag or an X-Robots-Tag header. That is often deliberate (thank-you pages, internal search results) and sometimes a leftover from staging. Google explains both in Block Search indexing with noindex.

Free route: in Search Console, the Pages report has an "Excluded by 'noindex' tag" reason. Use URL inspection on any page you expected to rank.

In RankZap, the Notices tab lists "Blocked from crawling (meta robots noindex)" and "Blocked by X-Robots-Tag: noindex HTTP header" separately, so you can confirm each one is intended.

Compare the noindex list to the sitemap. Any URL in both is a contradiction to resolve.

6. Check canonicals, redirects and URL structure

The canonical tag tells Google which URL is the master copy when several show the same content. A canonical pointing at a URL that errors is discarded, redirect chains waste crawl budget, and parameter-heavy or underscore URLs create duplicate versions of one page. Google covers these in Consolidate duplicate URLs, Redirects and Google Search and URL structure best practices.

Free route: view the source of key pages and confirm the canonical URL returns a 200. In Search Console, look for "Page with redirect" and "Duplicate, Google chose different canonical than user". Sort the crawl by URL length and scan for question marks and underscores.

In RankZap, "Broken canonical URLs" is an error; "Too many URL parameters" (more than 2) and "Underscores in URL" are warnings; "Redirected URLs" and "URLs longer than 200 characters" are notices.

Fix broken canonicals first, then point internal links at final destinations. Only rewrite URLs that duplicate content or trap the crawler.

7. Confirm HTTPS everywhere

Every page should be served over HTTPS, the HTTP version should 301 to it, and the server should send an HSTS header so browsers stop trying HTTP on repeat visits. Google has used HTTPS as a ranking signal since 2014 and documents the setup in Secure your site with HTTPS.

Free route: type the http:// homepage into a browser and watch where it lands. Then run a page through any free header checker for Strict-Transport-Security.

In RankZap, "Non-secure pages" is an error, "HTTP does not redirect to HTTPS" is a site-level warning, and "No HSTS support" is a notice.

If any page is still served over HTTP, or the redirect is missing, it goes to the top of the fix list.

8. Audit titles, meta descriptions, headings and alt text

The title tag is the strongest on-page signal of what a page is about and usually becomes the blue link in results; the meta description is often the snippet; the H1 confirms the topic on the page; alt text describes images to screen readers and image search. Missing, duplicate or badly sized versions of any of them cost clicks. Google's title link, snippet and image SEO docs explain what it uses.

Free route: export the crawl and sort by title, then by H1 count, then filter images for missing alt. The common working range is 30 to 60 characters for titles and 120 to 160 for descriptions.

In RankZap, missing and duplicate titles and duplicate descriptions are errors; short or long titles, missing, short or long descriptions, missing H1, an H1 that copies the title, and missing alt attributes are warnings; multiple H1s is a notice.

Write unique titles for the pages that earn traffic first, then work through the rest by template.

9. Find thin and duplicate content

Search engines have to decide whether a page is worth indexing and, if several pages say the same thing, which one to show. Pages with very little text, pages that are mostly markup, and pages whose body copy matches another page lose that decision. Google's spam policies describe scaled and duplicated content as the pattern to avoid.

Free route: sort the crawl by word count and read the bottom 10 percent. Then search Google for a distinctive sentence from a key page in quotation marks; more than one result from your domain means duplication.

In RankZap, "Duplicate content" is an error, and "Low word count" (under 300 words) and "Low text to HTML ratio" are warnings.

Decide per page: expand it, merge it into the stronger version with a redirect, or noindex it if it exists for users but not for search.

Internal links are how crawlers and users move through a site. A link to a 404 wastes both; a page in the sitemap but not linked from anywhere is an orphan; a page more than three clicks from the homepage usually receives fewer internal links and less crawl attention; and "click here" anchors tell search engines nothing about the destination. Google's link best practices page is the reference.

Free route: any free crawler lists links that returned an error. For orphans, compare the sitemap URL list with the crawl URL list. Filter anchors for empty strings and generic phrases.

In RankZap, "Broken internal links" is an error; "Too many on-page links" (over 100) and nofollow on internal links are warnings; orphaned pages, crawl depth over 3, single-inbound-link pages, and empty or non-descriptive anchors are notices. The link-graph notices run only on a complete crawl, because a partial graph would be wrong.

Fix broken links first, then add at least two internal links to any orphan you want ranked.

11. Check mobile rendering and page basics

Google indexes the mobile version of a page, so a page without a viewport meta tag renders at desktop width on a phone and is judged on that. A missing doctype, charset or lang attribute makes the browser guess, and framesets are barely indexed at all. Google's mobile-first indexing page explains the mobile part.

Free route: open the page on a phone, or use the device toolbar in browser developer tools. View source and confirm a doctype on the first line and a charset and viewport in the head.

In RankZap, "Viewport not configured" is an error; "Doctype not declared", "Encoding not declared", "Missing hreflang and lang attributes" and "Frames used" are warnings; "Inline styles used" and "iFrames used" are notices.

These are almost always template-level fixes: one change in the layout file clears the finding on every page.

12. Measure Core Web Vitals and server response

Core Web Vitals are Google's three user-experience metrics: Largest Contentful Paint (good is 2.5 seconds or less), Interaction to Next Paint (200 milliseconds or less) and Cumulative Layout Shift (0.1 or less), published at web.dev/vitals. Before the browser can start on those, the server has to return HTML, and a server that takes over three seconds fails everything downstream.

Free route: run key pages through PageSpeed Insights and read the field data (real users) before the lab score. In Search Console, the Core Web Vitals report groups URLs by status.

In RankZap, the performance checks are server-side: "Slow page (HTML) load speed" (over 3,000 ms) and "Large HTML page size" (over 2 MB) are errors; "Uncompressed pages", "Uncached pages" and "Too many JavaScript and CSS files" (over 30) are warnings. Use PageSpeed Insights for the three vitals themselves.

Pass the slow-server list to the developer or host first; compression and caching are usually a one-line configuration change with the biggest payoff.

13. Validate structured data

Structured data (JSON-LD in the page head) lets search engines and AI engines understand what a page represents: an article, a product, a local business. A block that fails to parse is ignored entirely, and a page with none is harder to cite. Google's structured data guidelines list what is allowed.

Free route: paste a URL into the Rich Results Test and read the errors. For types with no rich result, the Schema Markup Validator checks syntax.

In RankZap, "Invalid structured data items" is an error and "Pages with no schema markup" is a notice.

Fix parse errors first, since a broken block is worse than none. Then add Article or Product markup to the page types that lack it.

14. Check AI crawler access and llms.txt

AI engines cite pages their crawlers can fetch. GPTBot, ClaudeBot, PerplexityBot, OAI-SearchBot and Google-Extended each follow robots.txt, so a blanket disallow written years ago can keep a site out of AI answers entirely. Google lists its own tokens in the crawler overview. An llms.txt file at the root is an emerging convention that points AI crawlers at key content; Google Search ignores it, but it costs little.

Free route: read robots.txt again, this time looking for user-agent lines that name AI crawlers. Then open yourdomain.com/llms.txt to see whether one exists.

In RankZap, open AI and then Bots to see what the last crawl recorded in robots.txt and llms.txt for each AI crawler. "Llms.txt not found" is also a notice in the audit.

Decide deliberately which AI crawlers to allow, write it down, and make sure the rule matches the decision.

15. Document your findings

An audit nobody reads changes nothing. Each finding needs the check, the affected URLs, the severity, the fix and who owns it, in a document the client or developer can work from without you in the room. Lead with the two or three findings that matter most, not with the longest list.

Free route: use the SEO audit template, which has a section per area and a findings table with those five columns laid out.

In RankZap, open Reports to build the audit into a PDF and schedule the send, or open the action queue, which turns audit, Search Console and indexing findings into one ordered list ranked by estimated impressions at stake.

Send the document, then book the review call. The next section explains how to order the findings before you do.

Check the client's homepage for the basics first

Full first result on the page. No email, no account.

How do you prioritize what an audit finds?

Prioritize by three things in order: severity, the number of pages affected, and the effort to fix. A single error on a template that touches 400 pages outranks a warning on one page, and a warning that takes one line of configuration to clear is worth doing before an error that needs a rebuild.

The severity tiers below are the ones the audit uses, and they match the convention most auditors already recognize: an error breaks crawling, indexing or security; a warning degrades ranking or user experience; a notice is worth knowing and rarely urgent.

SeverityWhat it meansCount in the auditExamples from the checks
ErrorBreaks crawling, indexing or security. Fix first.145xx server errors, missing or duplicate title tags, duplicate content, broken internal links, broken canonical URLs, non-secure pages, viewport not configured, slow HTML response
WarningDegrades ranking or user experience. Fix in the next sprint.24Missing meta description, missing H1, low word count, missing alt attributes, uncompressed or uncached pages, sitemap not found, HTTP not redirecting to HTTPS
NoticeWorth knowing, rarely urgent. Batch into template work.17Multiple H1 tags, orphaned pages, non-descriptive anchor text, no schema markup, no HSTS, llms.txt not found, redirected URLs

Within a tier, sort by pages affected, and note the effort next to anything that will take more than a day of development so the client can trade it off against other work. A fuller scoring model, with pages affected, expected lift and effort as columns, is covered in how to prioritise SEO issues.

One more rule: a finding on a page that already earns clicks is worth more than the same finding on a page nobody visits. Keep the Search Console export from step 2 beside the findings and let the clicks column break ties.

How long does an SEO audit take?

A small site of up to 100 pages takes about a day to audit properly: an hour for the crawl and exports, four to five hours working through the 15 steps, and the rest writing it up. A site of a few thousand pages takes two to three days, most of the extra time spent grouping findings by template so the report lists causes rather than thousands of symptoms.

The automated part is quick. A crawl and the 55 checks finish in minutes on a small site. What takes the time is judgment: deciding which thin pages to merge, which noindex tags were deliberate, and which of the 400 pages sharing a duplicate description matter. That part does not compress, and it is also the part a client is paying for.

If you are quoting the work, quote it in days and say what is included. An audit that stops at the crawl output is a different product from one that ends with a prioritized document and a review call.

How often should you do an SEO audit?

Do a full audit twice a year, and re-run the automated checks after every significant release. Most of the errors in the table above are introduced by changes: a template edit that drops the viewport tag, a migration that leaves redirects chained, a new section published with placeholder titles. Catching those within a week is cheap; discovering them at the next six-month audit, after Google has re-evaluated the pages, is not.

The cadence also depends on how much the site changes. A brochure site that publishes twice a year can go a year between full audits as long as the automated checks run. A publisher or an e-commerce site adding pages every day should treat a weekly automated run as the floor and a quarterly full audit as normal.

Agencies managing several client sites usually schedule the automated run weekly and look only at what changed since the last run. That keeps the review to minutes per site and means the semi-annual full audit starts from a known state.

Check the client's homepage for the basics first

Full first result on the page. No email, no account.

SEO audit questions

What are the steps of an SEO audit?

The steps are: crawl the site, connect Search Console, check robots.txt and the sitemap, find error pages, review indexing status, check canonicals and redirects, confirm HTTPS, audit titles and headings, find thin and duplicate content, fix internal links, check mobile rendering, measure Core Web Vitals, validate structured data, check AI crawler access, and document the findings. That is the 15-step order used in this guide, and it runs indexing first because nothing else matters on a page Google cannot index.

How much does an SEO audit cost?

A professional SEO audit typically costs from a few hundred dollars for a small site to several thousand for a large one, because the price tracks the days of judgment involved rather than the crawl. The automated checks cost nothing on a free checker. What you pay for is a person reading the output, deciding what matters for that business, and writing it up so it gets fixed.

Can I do an SEO audit for free?

Yes. Search Console, PageSpeed Insights, the Rich Results Test and a free site crawler cover every check in this guide at no cost, and the free route in each step above uses only those tools. What you cannot get for free is the time: working through the steps, reading the output and writing the findings up takes most of a day for a small site, whoever does it.

What is the difference between an SEO audit and an SEO report?

An SEO audit is a one-off diagnosis of what is wrong with a site; an SEO report is a recurring account of how the site is performing. The audit produces a list of findings with severities and fixes. The report tracks clicks, impressions, rankings and the fixes completed, usually monthly. Agencies typically run the audit at the start of an engagement and the report every month after.

Final thoughts

Start with the crawl and the Search Console export, because every other step in this guide is a comparison between the two. Work through indexing before content, content before links, and links before performance, so you never polish a page that Google cannot see. Then write the findings up in severity order and send them.

If you want the 55 site-wide checks run for you and the findings sorted by severity and pages affected, that is what the SEO audit tool in the free trial does; the free SEO checker grades the homepage first, in a minute, with no account.

Keep learning

Plan your next SEO action with your own data

3-day trial · No card required · Managed AI included

Get started free ↗

Put the audit into practice