Complete guideSEO audits
SEO Audit: The Complete Step-by-Step Guide
by the AEO GEO Labs team17 min read
An SEO audit is a structured review of a website that finds what stops search engines from crawling, indexing, understanding and ranking its pages, then ranks the fixes by business impact. A complete audit covers technical health, on-page content, internal and external links, page experience and, as of 2026, how the site shows up in AI answers. Most sites need one every 6 to 12 months.
tl;dr
- 1An SEO audit has three outputs: a list of problems, evidence for each, and a ranked fix plan. A list without a ranking is a crawl export, not an audit.
- 2Start with Google Search Console, not a crawler. Google's own data tells you what is actually indexed and what actually gets clicks.
- 3Indexing problems come first, because a page that is not indexed cannot rank, and it cannot be cited by Google AI Overviews either.
- 4Most findings in a typical crawl report do not matter. Prioritize by pages affected multiplied by how much those pages earn.
- 5Add an AI search pass: check that AI crawlers can reach your pages and that your key pages answer questions in quotable sentences.
AEO GEO Labs (aeogeolabs.com) is an answer engine optimization, generative engine optimization and SEO agency. This guide is the hub for our audit series. For the deep technical layer, read the technical SEO audit guide. For a ready document to fill in, use the SEO audit template and report sample. If you want a fast automated pass first, start with the free SEO audit tool roundup.
What is an SEO audit?
An SEO audit is a diagnosis: it compares how a website works today against what search engines need to find, read and trust it, and it records every gap with evidence. The word "audit" matters. A good audit is repeatable, evidence-based and ends with decisions, the same way a financial audit ends with findings and recommendations rather than a pile of receipts.
An SEO website audit usually covers five layers. Each layer depends on the one before it, which is why the order matters.
| Layer | The question it answers | Typical evidence |
|---|---|---|
| Crawlability | Can search engine bots reach the pages? | robots.txt, server logs, crawl reports, status codes |
| Indexability | Are the right pages in the index, and only those? | Search Console Page indexing report, canonicals, noindex tags |
| Relevance | Does each page clearly answer one search intent? | Titles, headings, body copy, keyword-to-page mapping |
| Authority | Do other sites and your own links signal that the page matters? | Internal links, referring domains, brand mentions |
| Experience | Is the page fast, stable and usable on a phone? | Core Web Vitals, mobile rendering, intrusive interstitials |
A website SEO audit is not the same as a rank report or a site health score. Rank reports describe outcomes. Health scores from crawling tools count issues without weighing them. An audit explains why outcomes look the way they do and what to change first.
SEO audit vs technical audit vs content audit
These three terms overlap, and agencies use them loosely. The table shows how we use them across this series.
| Audit type | Scope | Best for |
|---|---|---|
| Full SEO audit (this guide) | All five layers, plus AI search visibility | A first engagement, a traffic drop, a yearly review |
| Technical SEO audit | Crawling, indexing, rendering, speed, structured data | Large sites, migrations, JavaScript frameworks |
| On-page SEO audit | Page-level titles, headings, copy, intent match | Pages that are indexed but stuck on page two |
| SEO content audit | Every URL's traffic and value: keep, refresh, merge, prune | Content-heavy sites with years of posts |
When to run an SEO website audit, and how long it takes
You should run a full SEO audit when you take over a site, before and after a migration, after an unexplained traffic drop, and at least once a year as routine maintenance. Smaller checks, such as reviewing the Search Console Page indexing report, belong in a monthly routine rather than a yearly project.
Common triggers, in rough order of urgency:
- A sudden traffic drop. Check for a technical cause first (robots.txt change, noindex pushed to production, broken canonicals, server errors) before assuming an algorithm update.
- A site migration or redesign. Audit before launch to build a redirect map, and again within two weeks of launch to catch what broke.
- New ownership of the site. A new marketing lead, agency or in-house SEO needs a baseline to measure against.
- Plateaued growth. Rankings stuck on page two usually point to relevance or authority problems rather than technical ones.
- Routine review. Every 6 to 12 months for most sites, quarterly for large or fast-changing ones.
How long an audit takes depends on site size and access. A 50-page brochure site can be audited properly in a day. A 50,000-URL ecommerce site with faceted navigation can take two to four weeks, mostly spent on crawl analysis and prioritization rather than on running tools.
Expect results to lag the fixes. Google's SEO starter guide says some changes "might take effect in a few hours, others could take several months," and suggests waiting a few weeks before judging whether a change helped.
The 10-step SEO audit process
The SEO audit process below runs from the most fundamental question (can Google reach the page?) to the most strategic (does the page deserve to rank and be cited?). Do the steps in order. Fixing title tags on pages that are not indexed is wasted effort.
Step 1: Set the scope and collect access
An audit starts with access, a goal and a baseline, not with a crawler. Write down what the site is for, which pages make money, and what "better" means: more organic sign-ups, more product page traffic, or recovery of lost rankings.
Collect access to:
- Google Search Console, with every property (domain property preferred).
- Google Analytics or your analytics tool, to tie pages to conversions.
- Bing Webmaster Tools, which also matters for AI search because several assistants draw on Bing's index.
- The CMS, the hosting or CDN dashboard, and ideally server logs.
Export a 12-month baseline: clicks, impressions, indexed pages and conversions by landing page. Without a baseline, you cannot prove the audit did anything.
Step 2: Check what Google has indexed
Indexing is the first real check, because a page that is not indexed cannot rank. Open the Page indexing report in Google Search Console and read the reasons pages are not indexed.
The reasons that usually matter most:
- Crawled, currently not indexed. Google fetched the page and chose not to index it. This is usually a quality or duplication signal, not a technical bug.
- Discovered, currently not indexed. Google knows the URL but has not crawled it. On large sites this can point to crawl budget or weak internal linking.
- Duplicate, Google chose different canonical than user. Your canonical tag says one thing; Google decided another. Find out why.
- Excluded by noindex tag. Confirm every noindexed URL is meant to be noindexed.
- Blocked by robots.txt. Confirm nothing important sits behind a disallow rule.
Then compare. Count the URLs in your XML sitemap, the URLs a crawler finds, and the URLs Google reports as indexed. Large gaps between those three numbers are where most audit findings live.
For individual pages, the URL Inspection tool shows whether a URL is on Google, which canonical Google selected, and how the page rendered. Use the live test to confirm a fix before you request reindexing.
Step 3: Crawl the site like a search engine
A crawl shows you the site the way a bot sees it: every URL, status code, title, canonical, directive and internal link. Run a crawler such as Screaming Frog, Sitebulb, Ahrefs Webmaster Tools or Semrush Site Audit. The free SEO audit tool guide covers which free tiers are enough for which site sizes.
In the crawl, look for:
- Status codes. 4xx errors on internally linked pages, 5xx errors, and redirect chains longer than one hop.
- Orphan pages. URLs in the sitemap or analytics that no internal link points to.
- Click depth. Important pages more than three or four clicks from the homepage get crawled less and tend to rank worse.
- Duplicate content. Near-identical pages, parameter URLs, HTTP and HTTPS or www and non-www versions both resolving.
- Directives that contradict each other. A page that is canonicalized to another URL and also noindexed, or a noindexed page listed in the sitemap.
Crawl with a JavaScript rendering mode as well as a plain HTML mode if the site uses a JavaScript framework, then compare the two. Content that only appears after rendering is a risk, covered in step 5.
Step 4: Review robots.txt, sitemaps and canonicals
These three files and tags tell search engines what to crawl, what exists and which version of a page counts. Small errors here cause large losses, so read them line by line.
robots.txt. Confirm the file returns a 200 status, does not block CSS or JavaScript that pages need to render, and does not block whole sections by accident. Remember that robots.txt controls crawling, not indexing. A blocked URL can still be indexed if other pages link to it. To keep a page out of the index, use a noindex tag on a crawlable page.
XML sitemaps. Google's sitemap documentation limits a single sitemap to 50MB uncompressed or 50,000 URLs. It also says Google ignores the priority and changefreq values and uses lastmod only when it is consistently accurate. So the audit checks are simple: only canonical, indexable, 200-status URLs belong in the sitemap, and lastmod should change only when the content really does.
Canonical tags. Every indexable page should carry a self-referencing canonical, and duplicates should point to the preferred version. Check that canonicals use absolute URLs, point to 200-status pages, and agree with your internal links, redirects and sitemap. When signals disagree, Google picks its own canonical, which is what the "Google chose different canonical" status in step 2 is telling you.
Step 5: Test rendering and JavaScript
Rendering is the step where many modern sites quietly fail. If your main content, links or meta tags are injected by client-side JavaScript, Google has to render the page before it can index that content, and Google's JavaScript SEO basics note that a page can sit in the render queue for longer than a few seconds. The same guide recommends server-side rendering or pre-rendering because "not all bots can run JavaScript."
That last point matters more in 2026 than it did five years ago. Many AI crawlers fetch raw HTML and do not execute JavaScript. A page that looks complete in a browser can look empty to them.
How to test:
- View the page source (not the inspected DOM) and search for a sentence from your main content.
- Run the URL Inspection live test and open "View crawled page" to see Google's rendered HTML.
- Compare a JavaScript-rendering crawl with an HTML-only crawl and diff the word counts and link counts.
If key content only exists after rendering, move it into the server response. That is a developer task, so write the finding with the exact template and component affected.
Step 6: Measure page experience and Core Web Vitals
Page experience is a confirmed but modest ranking factor. Treat it as a tiebreaker and a conversion issue rather than the centre of the audit. Google's Core Web Vitals documentation sets the "good" thresholds as:
| Metric | Measures | Good |
|---|---|---|
| Largest Contentful Paint (LCP) | Loading | Within 2.5 seconds |
| Interaction to Next Paint (INP) | Responsiveness | Under 200 milliseconds |
| Cumulative Layout Shift (CLS) | Visual stability | Under 0.1 |
Use field data first. The Core Web Vitals report in Search Console groups URLs by template, which tells you which page type to fix. Lab tools like Lighthouse are for diagnosing why a template is slow, not for deciding whether it is slow.
Also check the mobile version. Google uses the mobile version of a page for indexing and ranking, so content, structured data, titles and meta descriptions must match between mobile and desktop. Hidden-on-mobile content is a classic audit finding.
Step 7: Audit on-page relevance
On-page relevance asks whether each important page clearly matches one search intent. The on-page SEO audit goes page by page; at the site level, check these patterns:
- Keyword-to-page mapping. Every target topic should have exactly one primary page. Two pages chasing the same query (cannibalization) usually means both rank worse.
- Title tags. Unique, descriptive, primary topic near the front. Missing, duplicated or boilerplate titles are a site-wide finding.
- Headings. One clear H1 per page, and H2s that describe the sections. Headings are also how AI engines segment a page into answerable chunks.
- Meta descriptions. Not a ranking factor, but they shape the click. Write them for the searcher.
- Body content. Does the page answer the query in its first paragraph? Is it thin, outdated or written for a different intent than the one ranking pages serve?
- Structured data. Valid schema on the page types that support it: Organization, Article, Product, FAQPage where it genuinely applies. Test with Google's Rich Results Test.
Note that Google states it does not use the meta keywords tag. If an old audit tells you to fill it in, ignore that line.
Step 8: Audit internal and external links
Links are how search engines discover pages and judge which ones matter. Internal links are fully in your control, so audit them first.
Internal links. Check that money pages receive links from relevant, high-traffic pages, that anchor text describes the destination, and that no important page is orphaned or buried. Fix internal links that point at redirects or 404s. They waste crawl effort and leak signals.
Backlinks. Use Search Console's Links report and a backlink tool to see referring domains, top linked pages and anchor text. You are looking for three things: pages that earn links but have broken (404 pages with backlinks are worth redirecting), a profile far weaker than the competitors who outrank you, and obvious manipulation that matches Google's spam policies on link spam. Disavowing is rarely needed. Do it only when you know of manipulative links pointing at the site, such as those from a past link scheme.
Brand mentions. Count unlinked mentions too. They matter for AI search, as step 10 explains.
Step 9: Check content quality and site-wide trust signals
Content quality is a site-wide signal, not only a page-level one. A site with hundreds of thin, near-duplicate or stale pages can drag down its good pages. This is the job of a content audit: sort every URL into keep, refresh, merge or remove, based on traffic, links and business value.
At the same time, check the trust basics:
- A clear About page, named authors with real credentials on advice content, and a contact route.
- Accurate, dated content on topics where facts change.
- No pages that look mass-produced. Google's spam policies define scaled content abuse as "when many pages are generated for the primary purpose of manipulating search rankings and not helping users," whether a person or a model wrote them.
- HTTPS everywhere, a privacy policy, and no intrusive interstitials on mobile.
Step 10: Audit AI search visibility
An AI search audit checks whether answer engines can reach, read and cite your pages. As of October 2026, Google's AI features documentation says that to appear as a supporting link in AI Overviews or AI Mode, a page must be indexed and eligible to show with a snippet, and that "there are no additional technical requirements." So steps 1 to 9 are also your AI Overviews audit.
Other engines add a few checks of their own:
- AI crawler access. Check robots.txt rules and CDN or firewall settings for OAI-SearchBot, GPTBot, PerplexityBot, ClaudeBot and Google-Extended. Blocking a search bot can remove you from that engine's answers. Our free AI crawler checker tests this in one pass.
- Raw HTML content. Confirm your key content is in the server response (step 5), since many AI crawlers do not render JavaScript.
- Quotable structure. Key pages should open with a direct, self-contained answer, define terms in full sentences and use tables for comparisons. The GEO research paper from Princeton and others found that adding citations, quotations and statistics improved visibility in generative engine responses by up to 40% in its tests.
- Brand presence off-site. Run 20 to 50 real buyer questions through ChatGPT, Perplexity, Gemini and Google AI Overviews. Record whether you are mentioned, whether you are cited, and which sources are cited instead.
Our view: an SEO audit that skips this step in 2026 is incomplete, but the AI layer is additive. It sits on top of crawlability, indexing and content quality. It does not replace them.
How to prioritize SEO audit findings
Prioritizing is the step that separates a useful audit from a long one. A crawler will report hundreds of issues; most will not move traffic. Score each finding on impact and effort, then fix in this order.
| Priority | Rule | Examples |
|---|---|---|
| P0: fix this week | Blocks indexing or revenue pages | Noindex on templates, robots.txt blocking a section, 5xx errors, broken checkout redirects |
| P1: fix this month | High impact, affects many or valuable pages | Wrong canonicals on a template, content missing from raw HTML, orphaned money pages, cannibalization on top queries |
| P2: fix this quarter | Moderate impact or high effort | Core Web Vitals on a slow template, internal link restructuring, thin content consolidation |
| P3: backlog | Low impact, nice to have | Missing alt text on decorative images, meta descriptions on low-traffic pages, single redirect hops |
For each finding, write five things: what is wrong, the evidence (a URL list or screenshot), why it matters, the fix, and who owns it. "Duplicate title tags (214 URLs)" is a finding. "Duplicate title tags on 214 filtered category URLs because the template ignores the filter value; fix the template to append the filter name; owner: front-end dev" is an audit.
Our view: if an audit hands a developer more than 15 tickets at once, most of them will never ship. Batch the work by template and by owner, and lead with the three changes that matter most.
SEO audit checklist
This SEO audit checklist condenses the 10 steps into the checks we would run on any site. For the full technical version, use the downloadable technical SEO checklist.
| Area | Check | Pass looks like |
|---|---|---|
| Access | Search Console, analytics, Bing Webmaster Tools connected | All properties verified, 12-month baseline exported |
| Indexing | Page indexing report reviewed | Every "not indexed" reason explained or fixed |
| Indexing | Sitemap vs crawl vs index counts | Within a small, explained gap |
| Crawling | 4xx, 5xx and redirect chains | No internal links to errors; chains collapsed to one hop |
| Crawling | Orphan pages and click depth | Key pages within three clicks, none orphaned |
| Directives | robots.txt | 200 status, no accidental blocks, CSS and JS crawlable |
| Directives | Canonicals | Self-referencing on indexable pages, consistent with sitemap |
| Rendering | Main content in raw HTML | Key text visible in page source |
| Experience | Core Web Vitals field data | LCP 2.5s or less, INP under 200ms, CLS under 0.1 |
| Experience | Mobile parity | Same content, titles and structured data on mobile |
| On-page | Titles and H1s | Unique, descriptive, one H1 per page |
| On-page | Keyword mapping | One primary page per topic, no cannibalization |
| On-page | Structured data | Valid, matches visible content |
| Links | Internal links to money pages | Linked from relevant, high-traffic pages |
| Links | Backlinks to 404s | Redirected to the closest live page |
| Content | Thin and outdated pages | Each assigned keep, refresh, merge or remove |
| Trust | About, authors, contact, HTTPS | Present and accurate |
| AI search | AI crawler access | Search bots allowed in robots.txt and at the CDN |
| AI search | Answer-first structure | Key pages open with a direct answer |
| AI search | Buyer-question test | Mentions and citations recorded across engines |
To turn the findings into a document a client or boss will read, copy the SEO audit template. It includes an executive summary, a findings table and a 90-day roadmap.
Frequently asked questions
What is an SEO audit?
An SEO audit is a structured review of a website that identifies what prevents search engines from crawling, indexing, understanding and ranking its pages. It covers technical health, on-page content, links, page experience and, increasingly, visibility in AI answers. A good audit ends with a prioritized fix plan, with evidence and an owner for each finding, rather than a raw list of issues exported from a tool.
How often should you do an SEO audit?
Most sites should run a full SEO audit every 6 to 12 months, and large or fast-changing sites should run one quarterly. You should also audit before and after any migration or redesign, and immediately after an unexplained traffic drop. Between full audits, a monthly check of the Search Console Page indexing report and Core Web Vitals report catches most problems before they become expensive.
How long does an SEO audit take?
A small site of under 100 pages can be audited properly in one to two days. A mid-size site of a few thousand pages usually takes one to two weeks. Large ecommerce or publishing sites with tens of thousands of URLs can take two to four weeks, because most of the time goes into analyzing the crawl, explaining index gaps and prioritizing fixes, not into running tools.
Can I do an SEO audit myself for free?
Yes. Google Search Console, Bing Webmaster Tools and PageSpeed Insights are free, and several crawlers have free tiers: Screaming Frog crawls up to 500 URLs free, and Ahrefs Webmaster Tools audits verified sites at no cost. Free tools find the issues. The skill is in prioritizing them, so follow the 10 steps in order and fix indexing problems before anything cosmetic.
What is the most important part of an SEO audit?
Indexing is the most important part, because a page that is not indexed cannot rank in Google or be cited in Google AI Overviews. After indexing, the biggest wins usually come from fixing content that does not match search intent and from internal linking to revenue pages. Speed and minor technical warnings matter far less than most automated audit scores suggest.
Does an SEO audit cover AI search engines like ChatGPT?
A modern SEO audit should. As of October 2026, Google says AI Overviews draw on pages that are indexed and snippet-eligible, so a standard audit covers that engine. For ChatGPT, Perplexity and others, add checks for AI crawler access in robots.txt, content present in raw HTML, answer-first page structure, and a test of real buyer questions to see who gets cited.
If you want an audit done for your site, including the AI search layer, AEO GEO Labs runs fixed-fee audits and ongoing GEO, AEO and SEO programs for B2B and SaaS teams. See our services.