Website Checklist: Technical SEO Audit
A 10-point technical SEO audit checklist for 2026: sitemaps, robots.txt, indexing, internal links, HTTPS, speed and mobile, updated with current Google guidance.
What's on a technical SEO audit checklist? Ten things: your objectives, your sitemap, robots.txt, what's indexable, your internal links, HTTPS, page speed, mobile usability, whether Google can actually re-crawl the result, and what you do with every crawl after that. Get any one of these wrong and it can still cost you: some failures, such as blocking crawling or applying noindex, can keep a page out of Search entirely, while others affect discovery, rendering, performance or signals without making ranking impossible.
We run technical SEO audits on our own site and for clients at Code23, and the checklist below is the one we actually use, updated for how Google's tools and guidance work in 2026, not how they worked when we first wrote this. Work through it in order. Some of it you can fix yourself in an afternoon. Some of it is worth a second pair of eyes, which is exactly what our free SEO snapshot and full audit are for.
What is SEO?
For those of you who are unfamiliar, here’s a quick lesson on SEO. SEO stands for Search Engine Optimisation, which is the process by which a website can be better optimised for exposure online. In layman’s terms, SEO improves your eligibility and relevance for search results, but rankings also depend on intent, content quality, links, competition and Google’s own systems, not technical fixes alone.
One area that affects discovery, rendering and performance, without being the only thing that decides your ranking, is the technical health of your website: speed, crawlability and the overall structure of your site from a technical perspective.
We call this area technical SEO. It’s all the stuff your visitors never see, but are glad you’ve got in place. It covers everything from influencing how Google crawls and indexes your site (technical controls don’t control Google’s ranking decisions) to ensuring your website is performing at its optimal speed.
So, look no further to get clued up on how to perform a website audit to ensure you’re ticking all the boxes and doing all the right things when it comes to your own website.
This 10-point checklist covers the core concerns when running a technical SEO audit and offers insights into improving your SEO performance.
1. Refine your SEO Objectives
"The team at Code23 were extremely professional, patient and proactive with the build of our new website, providing added value through polite suggestions on improvements and an experienced insight into how we could improve our SEO."
As with any process, it’s sensible to begin by checking in with your overall goals.
SEO involves many aspects, and takes time to get right. It’ll involve keyword research, performance reports, content visualisation and an intrinsic understanding of your target audience. Understand what your audience is searching for, and you can tailor your website to meet those needs.
SEO works alongside all other elements of business – PR, eCommerce, visibility, web design, social media – all the important stuff. It makes sense, then, to ensure SEO is considered from the very start.
So, before you do anything else, refine your objectives.
This may include:
- Your budget (this shapes what's realistic, but how well it's spent matters more than the size of it)
- Your target audience
- Your goals for the business
- Your brand identity (how people find you, what they search)
Essentially, what is it that your digital strategy is aiming to do for your business?
2. Review your XML sitemap
Your XML sitemap lists URLs you want search engines to know about. Crawling is fetching; indexing is a separate decision Google makes afterwards.
What is an XML Sitemap?
Simply put, it’s how search engines like Google get to grips with what your site is offering. Your crawlability refers to how Google discovers and moves through your website: internal links remain the main navigation and crawl graph, and your sitemap - you guessed it - is a supplementary list, not the primary map.
A sitemap can improve discovery, especially for large, new or media-heavy sites, but it is only a hint: Google's own sitemap guidance is clear that Google can still find and index pages through links even when a sitemap is incomplete or out of date.
TOP TIP: Clear guidance on what your XML sitemap should look like can be found here.
If your website is lacking an XML sitemap entirely, it’s worth adding one, though a small, comprehensively linked site may not need one at all.
How do you do this?
For one thing, turn to us for web support! We can take care of your WordPress website for you, monitoring your web performance and finding efficient solutions to improve usability & performance.
You can check your own sitemap by heading to your Google Search Console. Open Search Console’s Sitemaps report, under the Index section, to review any submitted sitemaps; a sitemap does not have to be submitted there to exist or be discovered.
A clean, up-to-date sitemap also helps with what Google calls crawl budget: how much of your site Google can and wants to crawl. There's no dial you can turn to set it directly. Crawl budget primarily matters for large or rapidly changing sites and is based on crawl capacity and crawl demand, so the practical levers are the same ones on this checklist: cut duplicate content, block what doesn't need crawling, fix broken pages and keep things fast.
3. Optimising your Robots.txt
Beyond the XML sitemap, use robots.txt to manage crawler access, not indexing. A blocked URL can still appear in results, and Google must be able to crawl a page to see a noindex directive. An essential box to tick on your technical SEO checklist, this determines how robots make their way around your website.
What is robots.txt?
Crawlers consult your robots.txt file for access rules when they arrive at your website, but the file is not an indexing control. It instructs search engines regarding how they get around your site. The primary instruction list is your robots.txt file. It contains directives that supported crawlers interpret.
By using a disallow rule in your robots.txt file, for example, you can close off access to certain pages and, therefore, create some control over which pages do get crawled. Google's own robots.txt guide covers the syntax and the common mistakes.
If you find you have disallowed access to some key pages on your site, you’re doing yourself an injustice and preventing search engines to do what they’re designed to do.
How to find robots.txt
Finding the robots.txt is easy enough. Simply add '/robots.txt' to the end of your domain, not a specific page URL, e.g. yoursite.com/robots.txt.
How to edit robots.txt
Web developers are the way to go if you need to edit your robots.txt for any reason. Reach out to us for more info on this.
We are also able to do a more refined review of how well your website's being crawled. Use Google's Page indexing report and URL Inspection to diagnose Google discovery, crawling and indexing. They do not report every search engine.
This allows us to identify where Google's crawling and indexing is falling short and take actions to fix it. If Google can’t find the information it needs, your customers may not find you under relevant searches from Google either.
4. Make sure everything you want indexed is indexable
Aside from checking all your primary pages are crawlable in your robots.txt, there are several other points to cover on making the robots go where you want them to.
The noindex meta tag tells search engines not to index the whole page it's placed on, while the X-Robots-Tag HTTP header does the same job for non-HTML files like images and PDFs, and it’s worth digging down into such details.
Next, check for Orphan pages
Orphan pages are webpages / URLs with no internal linking, so they receive little internal context. Crawlers may still discover them through sitemaps or external links, but a visitor can’t reach them from your site unless they go straight to the correct URL, and search engines have a harder time working out what the page is about without internal context pointing to it (orphan and dead-end pages). Link useful pages into the architecture, and consolidate, redirect or remove only the ones that no longer serve a purpose.
5. Carry out an internal link audit
This is an area your visitors may well have noticed, even if you haven’t yet.
If you’ve got important webpages that are hidden several clicks in, they can be harder for users and crawlers to discover, though there’s no universal three-click rule that decides rankings. You won’t be making them as easy for the robots to reliably find, and, more to the point, your visitors may get frustrated wandering around your site trying to find them.
So, tighten up those pathways. The number of links needed to reach a page is its click depth. Keep important pages within a clear, useful internal-link structure.
Also, make sure that any broken links are fixed. Link useful orphan pages into the architecture; consolidate, redirect or remove only pages that no longer serve a purpose, if you haven't already.
Crawlers work with the paths you give them, so make it easy for them and remove all unnecessary barriers to their work. Also, while you’re there, check that your site architecture is offering as efficient an SEO experience as possible.
If your website was designed with user experience at the forefront, which is typically the case with a Code23 web design, good UX and information architecture should support clear internal paths, but verify them during the audit rather than assume they are already correct. With clear SEO value in a good site architecture, it’s worth making this part of your SEO audit.
6. Check HTTPS
HTTPS encrypts data in transit and authenticates the connection; it does not make the application itself secure or prove legitimacy on its own. Secure sites matter to visitors and potential customers, who increasingly expect a secure connection as standard.
HTTPS stopped being optional years ago. If any part of your site is still loading over plain HTTP, that's a same-week fix, not a someday one. Even with HTTPS in place, it's worth checking that every element on the page, images, scripts and embeds included, is loading over a secure connection too.
Top Tip: If you operate on WordPress and think your site might need a security overhaul, come to us for web maintenance support!
If your images, videos or JavaScripts load over a less secure HTTP connection, issues can arise. Mixed active content can be blocked by the browser and weakens transport security, so remove HTTP subresources.
Some online tools can check this, and it can be incorporated as part of a technical SEO audit, such as the one we offer at Code 23.
URL Structure
Don't forget to check that your URLs are friendly: short, clear and memorable, while avoiding over-optimisation tactics such as keyword stuffing. Keywords in a URL do not guarantee ranking, and Google's spam enforcement isn't an automatic penalty triggered by a single URL. (See Google's guidance on keyword stuffing.)
7. Test and improve your page speed
Page load speed is something you should be aware of. If you’re not – why not? How many times have you left a website or mobile site because you’re frustrated by its loading speed? Well, exactly the same thing applies to your customers!
Page speed matters on both desktop and mobile, and it's worth testing them separately because field data and bottlenecks can differ.
Common areas to test to improve your page speed include:
- Compressing media
- Reducing ad ‘weight’
- Testing server response and improving hosting only when it is a measured bottleneck
For more information on page speed, and how to measure and improve yours, check out our article on the benefits of having a fast website.
TOP TIP: Use PageSpeed Insights to check your site speed. INP replaced FID as a Core Web Vital on 12 March 2024. PageSpeed Insights can show INP in CrUX field data when available; its Lighthouse lab test does not measure INP directly.
8. Get mobile-friendly
Google finished rolling out mobile-first indexing in October 2023, and retired the standalone Mobile-Friendly Test tool that December. Check mobile issues today through the URL Inspection tool in Search Console, or a Lighthouse audit in Chrome DevTools.
If mobile content or functionality is incomplete, fix it: responsive design is normally the simplest approach, and a separate mobile site isn't required.
Any good technical SEO audit needs to carry out a full audit of your mobile site: mobile rendering, content, structured data and parity with desktop, because Google primarily crawls and indexes with its mobile crawler. You can find more technical guidance in Google's mobile-first indexing best practices.
9. Let search engines recrawl, then monitor
Once you’ve run your technical SEO audit and taken the actions that will improve your SEO performance, search engines will recrawl the changed pages automatically over time.
Use URL Inspection to diagnose an important changed URL and request indexing sparingly when needed. Request indexing is a hint, not a guarantee; keep the sitemap current for broader discovery.
This SEO audit’s over, but your work’s not done yet.
Run audits again after migrations, redesigns and major URL or template changes, then repeat according to your release frequency and any issues you spot in between. Google’s algorithm and other factors that influence the landscape of your technical SEO change too, so keeping a regular check on it matters.
We carry out regular monitoring and full technical SEO audits for our clients to catch problems early. Talk to us about doing the same for you.
10. Make the most of every crawl
However often your website gets crawled, it’s important that you make the most of every opportunity.
Here’s a quick rundown of the ways you can make every robot visit worthwhile:
• Fix or remove broken internal links and important broken outbound links.
Broken links create dead ends for users and crawlers alike, and make for a bad user experience. A broken link is any link on the site that does not work. This may occur due to the page no longer existing, or because there is an error in the URL. Users discovering broken links doesn’t help with user experience. Broken links interrupt journeys and can make useful pages harder to reach, so look out for these.
• Eliminate any keyword cannibalism.
Keyword cannibalisation happens when multiple pages on your site target substantially the same search intent; it is not another name for duplicate content. This can make it harder for Google to work out which page to rank for that intent.
• Use canonical tags to indicate your preferred version of duplicate pages caused by URL parameters. Google's old URL Parameters tool in Search Console was retired in 2022, since Google now handles most parameters automatically. If duplicate parameter pages are still a problem, add rel=canonical tags to point back to the main version; canonical tags indicate a preference, they don't stop Google crawling the duplicate URLs. See Google's canonicalisation guidance.
• Reduce the length of any chains of 301 or 302 redirects.
Redirect chains add extra hops for users and crawlers. Link directly to the final URL and collapse unnecessary chains.
• Write page-specific metadata, especially descriptions.
Your metadata tells search engines and searchers what a page is about, so write titles and descriptions that are specific to each page where it helps users choose the right result. Duplicated metadata across pages isn't an automatic penalty, but page-specific metadata still helps.
• Don't over-invest SEO effort in pages that aren't built to attract search traffic: privacy policy, T&Cs, outdated promotions, etc.
These pages are important to have and shouldn't be noindex'd by default, but they are not going to be what people are searching for. Bearing this in mind, ensure they are good quality without spending time and energy optimising them for keywords.
• Refine your ‘crawl budget’.
Crawl budget isn't something you dial up directly, it's Google's crawl capacity and crawl demand for your site (see the sitemap section above). The practical levers are the same ones on this checklist: keep your server fast and error-free, cut duplicate content, and block what doesn't need crawling.
• Review duplicate or overlapping content.
Duplicate or near-duplicate pages can make it harder for Google to know which one to rank for a given intent. Go through your content and consolidate or canonicalise pages only when they actually serve the same intent, to create one or two strong pages instead of several offering the same thing.
If a technical audit daunts you, you don’t have to go it alone. There are plenty of guides online, or you can start with our free SEO snapshot. We can scope the work your audit identifies, or contact us at Code23 web design. We can handle everything for you.
Related guides: What is SEO?, How much does SEO cost in the UK?, and SEO vs PPC.
Frequently asked questions
What is a technical SEO audit?
It’s a check of barriers to discovery, crawling, indexing, rendering and performance: your sitemap, robots.txt, what’s indexable, internal links, HTTPS, page speed and mobile usability. It doesn’t determine ranking on its own, but content and keywords matter less if the technical side is blocking Google from seeing them in the first place.
How often should you run a technical SEO audit?
Run one after major migrations, redesigns or URL changes, then repeat according to your release frequency and any issues you spot; there’s no universal annual minimum. Google’s own guidance and tools change too, so a checklist or report from a few years ago can be quietly checking things Google no longer measures the same way.
What’s changed in technical SEO for 2026?
Quite a bit of the old toolkit is gone. Google finished mobile-first indexing in October 2023, retired the standalone Mobile-Friendly Test tool that December, and Core Web Vitals now measures Interaction to Next Paint instead of First Input Delay. The old ‘Fetch as Google’ request-indexing feature is gone too, replaced by the URL Inspection tool.
Does a technical SEO audit guarantee higher rankings?
No, and we wouldn’t tell you it does. A technical audit identifies barriers to crawling, indexing and rendering; implementation is what addresses them. Addressing those barriers can improve discovery, indexing and rendering; it does not guarantee a ranking increase, and it doesn’t replace good content, real authority or a plan for what to rank for next. It’s the foundation, not the whole build.
Next step
A technical SEO audit isn’t a one-off box to tick. Google’s guidance changes, tools get retired, and releases or platform changes can introduce new issues over time.
If you want to know where you actually stand, start with our free SEO snapshot: your top ten pages, the keywords you already rank for and the five biggest technical problems, back within 48 hours. If you want the full picture, the Technical SEO & Content Audit is £1,500 + VAT: it crawls every page and gives you a written, prioritised fix list. We’ve delivered 350+ projects since 2005 and have 60+ five-star Google reviews. We don’t hand over a report and disappear.
Plan the next release
Build the next version around the result it needs to produce.
We’ll define the scope, design the journeys and build the systems behind them with one senior UK team.