Most articles about the technical SEO audit either sell you a tool or bury you in 172 automated “issues” that nobody will ever fix. This guide does the opposite. Below are the 14 technical checks that genuinely influence whether Google can crawl, render, index and rank your pages, plus the free tool to run each check and, more importantly, how to interpret the result so you can act on it even if you have never touched a line of code.
Work through it in order. The list is sequenced deliberately: there is no point optimising Core Web Vitals on a page that Google cannot index in the first place.
What is a technical SEO audit (in plain English)?
A technical SEO audit is a structured review of your website’s infrastructure to confirm that search engines can find, crawl, render, index and trust your pages. It does not judge whether your content is good. It answers a narrower question: is anything in the plumbing stopping good content from ranking? A step-by-step version exists if you prefer that format.
A useful audit produces three things:
- A list of confirmed problems (not tool-generated noise)
- An estimate of the traffic or revenue at risk for each one
- A single owner and a clear next action per item
The 15-minute triage before you start
Before the full checklist, run this quick sanity check. If any of these fail, fix it first, because it will distort everything else you measure.
| Quick check | Where | Red flag |
|---|---|---|
| Is the homepage indexed? | Google Search Console URL Inspection | “URL is not on Google” |
| Does robots.txt block anything important? | yoursite.com/robots.txt | Disallow: / |
| Is HTTPS working everywhere? | Browser address bar | Certificate warning or mixed content |
| Is there a sudden drop in indexed pages? | GSC > Pages report | Cliff-edge decline in the last 90 days |

The tools you actually need (all free)
You can complete this entire audit on a zero budget. Paid crawlers are faster on large sites, but they find the same things.
| Tool | What it is for | Free limit |
|---|---|---|
| Google Search Console | Indexation, Core Web Vitals, sitemaps, crawl stats | Unlimited, your own sites only |
| Screaming Frog SEO Spider | Site crawl, status codes, canonicals, titles, redirects | 500 URLs per crawl |
| PageSpeed Insights | Core Web Vitals, lab and field data | Unlimited, one URL at a time |
| Chrome DevTools | JavaScript rendering, mixed content, mobile emulation | Built into Chrome |
| Rich Results Test / Schema validator | Structured data validation | Unlimited |
| Bing Webmaster Tools | Second opinion on crawling and indexing | Unlimited, your own sites |

The 14-point technical SEO audit checklist
1. Crawl the site and build your baseline
What to check: a full list of URLs a crawler can reach from your homepage, with status code, title, canonical, indexability and word count for each.
Tool: Screaming Frog (free up to 500 URLs). Enter your domain, crawl, then export the “Internal: All” tab to a spreadsheet.
How to read it: compare the number of crawlable, indexable HTML pages against the number of pages you think you have. If your CMS says 340 published pages and the crawl returns 1,900 URLs, you have a URL bloat problem (usually filters, pagination, session parameters or tag archives). If it returns 90, internal linking is broken somewhere and pages are orphaned.
Action: keep this export. Every other check in this list is easier once you have a single spreadsheet of truth.
2. Indexation: is Google keeping your pages?
What to check: Search Console > Indexing > Pages. Look at the ratio of indexed to not indexed pages and the reasons listed.
How to read it: these are the reasons that matter most and what they usually mean.
| GSC status | Plain meaning | Urgency |
|---|---|---|
| Discovered, currently not indexed | Google knows the URL but has not bothered crawling it. Usually a quality or internal linking signal. | High if money pages |
| Crawled, currently not indexed | Google saw it and chose not to index. Thin, duplicate or low value content. | High |
| Duplicate, Google chose a different canonical | Your canonical hint was overridden. | Medium to high |
| Excluded by noindex tag | Intentional, unless it is not. | Critical if unintentional |
| Blocked by robots.txt | Crawler cannot reach the page at all. | Critical if unintentional |
| Alternate page with proper canonical tag | Working as designed. Ignore. | None |
Action: your target is not 100% indexation. It is 100% of your commercially important pages indexed, and everything else deliberately excluded. Export the “not indexed” list, tag each URL as “should be indexed” or “fine as is”, and only work on the first group.
3. Robots.txt: the one file that can erase your traffic
What to check: visit yoursite.com/robots.txt. Read every Disallow line out loud.
How to read it:
- Disallow: / under User-agent: * blocks the entire site. This is the single most common catastrophic error, usually left over from a staging environment.
- Blocking /wp-content/, /assets/, /css/ or /js/ prevents Google from rendering your pages properly. Allow these.
- Blocking a URL does not remove it from the index. Use noindex for removal, robots.txt for crawl control. Never both on the same URL, because Google cannot see a noindex tag on a page it is not allowed to crawl.
- Check that the sitemap line is present and points to a live sitemap URL.
Action: test any suspicious pattern in Search Console’s robots.txt report, then confirm with URL Inspection on a real page that matches the pattern.
4. XML sitemaps: clean, current and submitted
What to check: GSC > Sitemaps for submission status, then open the sitemap file itself.
How to read it: a healthy sitemap contains only URLs that are 200 status, self-canonical, indexable and final. Common failures:
- Redirected or 404 URLs still listed (wastes crawl budget and reduces trust in the file)
- Noindexed URLs listed (contradictory signals)
- Sitemap not updated when content is published, so new pages take weeks to be discovered
- Fake priority and changefreq values, which Google ignores anyway
- More than 50,000 URLs or 50MB uncompressed in a single file
Action: if “Discovered URLs” in GSC is far higher than your indexed count, your sitemap is probably full of junk. On WordPress, let Yoast, Rank Math or the core sitemap generate it dynamically instead of maintaining a static file. Split large sites into logical sitemaps (products, categories, blog) so you can see which section has an indexing problem.
5. Redirects: chains, loops and soft 404s
What to check: in your Screaming Frog crawl, open Reports > Redirects > Redirect Chains. A comparable breakdown sits on semrush.com.
How to read it:
- 301 means permanent. Use it for anything you have moved for good.
- 302 means temporary. If a 302 has been in place for six months, it should be a 301.
- Chains (A to B to C) are wasteful and slow. Anything over two hops should be flattened so the source points straight at the final destination.
- Loops break pages entirely. Fix immediately.
- Soft 404s return a 200 status while showing a “not found” or empty page. Google reports these separately and they distort your indexation numbers.
Action: update the internal links so they point to the final URL instead of relying on redirects. Keep external-facing redirects in place indefinitely, since backlinks still use the old URLs.
6. Canonical tags: one preferred URL per piece of content
What to check: the Canonicals tab of your crawl. Filter for canonicalised pages, missing canonicals and multiple canonicals.
How to read it: most pages should be self-canonical, meaning the canonical tag points at the page’s own URL. Warning signs:
- Every page canonicalising to the homepage (a classic broken plugin symptom that removes your whole site from the index)
- Canonicals pointing to HTTP, to a non-www version, or to a redirected URL
- Two canonical tags on the same page, which Google may ignore entirely
- Paginated pages canonicalising to page 1, which hides deeper products and articles
Action: if GSC says “Duplicate, Google chose a different canonical”, Google is telling you your signals conflict. Align the canonical, the internal links and the sitemap on the same single URL, and make sure the preferred version is the one you link to everywhere.
7. Status codes and broken links
What to check: the Response Codes tab. Sort by code.
| Code | Meaning | What to do |
|---|---|---|
| 200 | OK | Nothing |
| 301 / 308 | Permanent redirect | Fine, but fix internal links pointing at it |
| 404 / 410 | Not found / gone | Redirect if it had value and traffic, otherwise leave and remove internal links |
| 403 | Forbidden | Check firewall or bot protection blocking Googlebot |
| 5xx | Server error | Escalate to hosting today. Repeated 5xx errors cause deindexing |
Action: do not mass-redirect every 404 to the homepage. Google treats that as a soft 404 and it confuses users. Redirect to the closest genuine equivalent, or let it 404 cleanly with a helpful page that offers search and popular links.
8. Site architecture, click depth and orphan pages
What to check: the Crawl Depth column in your crawl, plus Reports > Orphan Pages if you connect Search Console or Analytics to Screaming Frog.
How to read it: pages more than three or four clicks from the homepage get crawled less often and rank worse, all else being equal. Orphan pages, which have no internal links at all, are usually discovered only via the sitemap and rarely perform.
Action:
- Add internal links from your strongest pages to the important deep pages
- Flatten oversized category structures
- Use descriptive anchor text instead of “read more” or “click here”
- Make sure key hub pages are reachable from the main navigation or footer
9. Duplicate titles, meta descriptions and headings
What to check: the Page Titles and Meta Description tabs, filtered for Duplicate and Missing.
How to read it: duplicates are almost always a template problem, not a copywriting problem. Twenty product pages with the identical title usually means the template is not pulling in the product name or variant. Missing H1s and multiple H1s matter less than people claim, but a page with no clear main heading is a signal of a sloppy template.
Action: fix the template rule once rather than editing pages one by one. Prioritise pages that already receive impressions in GSC, since a better title there produces measurable click-through gains within weeks.
10. Core Web Vitals and real page speed
What to check: GSC > Experience > Core Web Vitals for site-wide field data, then PageSpeed Insights for individual templates (homepage, category, product, article, contact).
How to read it: only the field data section reflects real users, and it is what Google uses. Thresholds for a “good” experience:
| Metric | Good | Usual cause when it fails |
|---|---|---|
| LCP (Largest Contentful Paint) | Under 2.5s | Huge hero images, slow hosting, no caching, render-blocking CSS |
| INP (Interaction to Next Paint) | Under 200ms | Heavy JavaScript, chat widgets, tag manager overload |
| CLS (Cumulative Layout Shift) | Under 0.1 | Images without width and height, injected banners, late-loading fonts |
Action for non-developers: the biggest wins rarely need code. Compress and resize images (serve WebP), enable a caching plugin plus a CDN, remove plugins and third-party scripts you no longer use, set explicit image dimensions, and preload the hero image. That combination alone fixes most failing LCP and CLS scores. Chasing a 100/100 Lighthouse score is a waste of time. Getting out of the red is not.
11. Mobile usability
What to check: Google indexes the mobile version of your site, so audit the mobile experience first. Open Chrome DevTools (F12), toggle the device toolbar, and test each template at 390px width.
How to read it: look for these specific failures.
- Content or navigation hidden on mobile but present on desktop. If it is not in the mobile HTML, treat it as invisible to Google.
- Horizontal scrolling or elements wider than the viewport
- Tap targets smaller than roughly 48px, or buttons too close together
- Body text below 16px
- Interstitials and cookie walls that cover the content
- Different structured data, canonicals or meta robots tags between mobile and desktop
Action: compare mobile and desktop source code for one important page. Any content that exists only on desktop should be added to mobile, in tabs or accordions if space is tight. Collapsed content is fine as long as it is in the HTML. Free SEO Audit Tool is a useful companion to this.
12. JavaScript rendering
What to check: whether your important content exists in the initial HTML or only after JavaScript runs.
The two-minute test:
- Open the page, right click, choose View page source (this is the raw HTML).
- Press Ctrl+F and search for a distinctive sentence from your main content.
- Not found? Now right click and choose Inspect and search the rendered DOM instead.
- If the text appears in the rendered DOM but not in the source, that content depends on JavaScript.
Then confirm with Google: use URL Inspection in Search Console, click Test live URL, then View crawled page > HTML and Screenshot. This shows you what Googlebot actually rendered.
How to read it: Google can render JavaScript, but it costs crawl resources and it is delayed and occasionally incomplete. Other crawlers and AI answer engines are far less capable. Risk is highest when:
- Internal links are JavaScript click handlers instead of real <a href> tags. Googlebot does not click, so those links do not exist.
- Product listings, prices, reviews or filters load only after user interaction
- Titles, canonicals or meta robots tags are injected client-side
- Content is behind infinite scroll with no paginated URLs
Action: ask your developer for server-side rendering or prerendering for indexable templates, and insist that every internal link is a plain anchor tag with a real href. That single request solves the majority of JavaScript SEO problems.
13. HTTPS, mixed content and duplicate domain versions
What to check:
- Type all four variants in the browser: http, https, with www and without. All should end on one canonical version via 301.
- Open DevTools > Console and look for “Mixed Content” warnings, which mean secure pages are loading insecure resources.
- Confirm the SSL certificate expiry date and that it covers all subdomains you use.
- Check whether a staging or dev subdomain is publicly crawlable, which is a very common source of duplicate content.
Action: pick one canonical hostname, redirect the other three, then verify that internal links, sitemaps and canonical tags all use it. Password protect staging environments rather than relying on noindex.
14. Structured data and how search features read your pages
What to check: GSC > Enhancements for site-wide errors, plus Google’s Rich Results Test on one URL per template.
How to read it: the goal is accuracy, not volume. Markup that describes something not visible on the page is a manual action risk. Priorities by site type:
- E-commerce: Product, Offer, AggregateRating, BreadcrumbList
- Publishers and blogs: Article, Author, Organization, FAQPage where genuinely applicable
- Local businesses: LocalBusiness with consistent name, address, phone and opening hours
- Service companies: Organization, Service, BreadcrumbList
Action: fix errors first, then warnings only where the missing field unlocks a feature you care about. Clean Organization and Article markup also helps AI search systems attribute your content correctly, which is increasingly where discovery happens.

Bonus for 2026: audit your visibility to AI crawlers
Classic technical SEO checks still decide whether you rank in Google, but a growing share of traffic now starts inside AI assistants and AI overviews. Two extra checks are worth adding to your audit:
- Are AI crawlers allowed? Check your robots.txt and CDN bot rules for GPTBot, ClaudeBot, PerplexityBot, Google-Extended and similar user agents. Many security plugins and WAF configurations block them by default. Decide deliberately whether you want to be quotable, then implement that decision consistently.
- Is your content readable without JavaScript? Most AI crawlers do not render JavaScript at all. If your key content only appears after scripts execute, you are invisible in AI answers even when you rank in Google. Point 12 above is now doing double duty.
What to ignore in your audit report
Automated tools flag hundreds of “issues” to justify their existence. These rarely deserve engineering time:
- Meta keywords tags (unused by every major search engine)
- Keyword density warnings
- Lighthouse scores under 100 when field data is already green
- “Too many internal links” on a legitimately large navigation
- Missing meta descriptions on pages with zero impressions
- W3C HTML validation errors that do not affect rendering
- Sitemap priority and changefreq values

How to prioritise what you found
A checklist without prioritisation just creates a backlog. Score each confirmed issue on two axes: traffic at risk and effort to fix.
| Priority | Issue type | Timeline |
|---|---|---|
| P0 stop everything | Site-wide noindex, robots.txt blocking everything, 5xx errors, expired SSL, canonicals pointing to the homepage | Same day |
| P1 high | Money pages not indexed, broken redirects on top URLs, mobile content missing, JavaScript-only internal links | Within 2 weeks |
| P2 medium | Failing Core Web Vitals, redirect chains, duplicate titles, sitemap hygiene, orphan pages | Within a quarter |
| P3 low | Structured data warnings, image alt gaps, minor heading structure issues | Ongoing housekeeping |
Turn the audit into a one-page brief
Developers ignore 60-page PDF exports. What gets fixed is a short table with four columns: issue, affected URLs (example plus count), expected fix, owner and deadline. Attach the raw crawl export as evidence and keep the brief to a single page.

How often should you run a technical SEO audit?
- Weekly: glance at GSC Pages and Core Web Vitals reports for sudden changes
- Monthly: crawl the site and compare against last month’s export
- Quarterly: run this full 14-point checklist
- Immediately: after any migration, redesign, replatform, CMS update or hosting change
Most catastrophic SEO losses do not come from algorithm updates. They come from a deployment that shipped a noindex tag or a robots.txt file from staging. Auditing after every release is cheaper than recovering from one.
Frequently asked questions
What is a technical SEO audit?
It is a systematic review of a website’s technical foundations to confirm search engines can crawl, render, index and serve its pages. It covers indexation, robots directives, sitemaps, redirects, canonicals, status codes, site speed, mobile usability, JavaScript rendering, HTTPS and structured data. It does not assess content quality or backlinks, which are separate audits.
What is the difference between an SEO audit and a technical SEO audit?
A full SEO audit has three parts: technical (can search engines access and understand the site), on-page and content (does the site answer the queries people search), and off-page (authority and links). A technical SEO audit is the first of those three and is a prerequisite, because content and links cannot compensate for pages Google cannot index.
What is the best technical SEO audit tool?
There is no single best tool, and the honest answer is that you need at least two: Google Search Console for what Google actually does with your site, and a crawler such as Screaming Frog, Semrush Site Audit, Ahrefs Site Audit, Sitebulb or Seobility for what exists on your site. Search Console shows Google’s verdict, the crawler shows the cause. Free tiers are enough for sites under a few thousand URLs.
Can ChatGPT do an SEO audit?
Partially. AI assistants are excellent at interpreting data you give them: paste a crawl export or a robots.txt file and ask for prioritisation, and you will get a useful answer fast. They can also write redirect maps, schema markup and htaccess rules. What they cannot do reliably is fetch your live site at scale, read your Search Console field data, or verify how Googlebot rendered a specific URL. Use AI as an analyst on top of real crawl data, not as a replacement for the crawl.
How long does a technical SEO audit take?
For a site under 500 pages, a focused audit using this checklist takes four to six hours. Mid-size sites of a few thousand URLs typically take two to three days. Large e-commerce or multilingual sites with log file analysis and internationalisation checks take one to two weeks. Implementation almost always takes longer than the audit itself.
Do free SEO audit tools give reliable results?
Free scanners are good at detecting objective facts such as status codes, missing tags and slow resources. They are poor at judging importance, and they frequently label harmless things as critical errors. Trust the raw data, question the severity labels, and always confirm indexation issues in Search Console before acting.
Next step
Run the 15-minute triage today, then block two hours this week for points 1 to 6. Those six checks catch the issues responsible for most unexplained ranking losses. If you would rather have someone run the full 14-point audit, prioritise the findings and hand your team a one-page implementation brief, that is exactly the kind of work our team at King Content Agency does. Get in touch and we will start with a free look at your indexation data.
