The full list
Every check we run, and why
107 checks across 7 areas. Each one has its own page explaining what it looks for, why it costs you something, and how to fix it — whether or not you ever run a scan.
Run them all on your siteSearch
48 checks- Canonical tags point somewhere validA canonical tag tells Google which address is the real one for a page. When it points somewhere wrong — another domain, a dead page, or the wrong protocol — Google follows it anyway, and the page you wanted indexed can be dropped in favour of one that does not exist.seo.canonical-problems
- Content has been updated recentlySome content is meant to sit still, and age alone is not a fault. But prices, opening hours and staff pages that have not been touched in over a year are usually wrong by now — and a visitor who acts on the wrong opening hours does not come back to check whether the rest was right.seo.stale-content
- Descriptions are a sensible lengthLong descriptions get truncated mid-sentence; very short ones waste the space you are given.seo.meta-description-length
- Each page has exactly one title tagA page can only have one title. When there are several, the browser and Google each pick one — and they do not always pick the same one, so what you see in the tab may not be what appears in search.seo.multiple-title-tags
- Each page has one main headingSeveral top-level headings makes the structure of the page ambiguous. Worth checking rather than urgent — modern HTML permits it, and Google handles it, but it usually signals that headings are being chosen for their size.seo.multiple-h1
- Every page has a main headingThe h1 is the headline of the page. Without one, both visitors skimming and search engines parsing the page have nothing telling them what it is about.seo.missing-h1
- Every page has a search descriptionThe description is the grey summary under your link in Google. Without one, Google pulls an arbitrary sentence from the page, which often reads as nonsense out of context and gives people no reason to click.seo.missing-meta-description
- Every page has a titleThe title is the blue clickable line in a Google result and the text in the browser tab. Without one, Google invents something from the page content — usually badly.seo.missing-title
- Every page is linked from somewhereA page listed in your sitemap that nothing on the site links to cannot be reached by anybody browsing normally. Search engines read the absence of internal links as a statement that the page does not matter, and treat it accordingly.seo.orphaned-pages
- Google agrees with the canonical URL your pages declareWhen several URLs show the same content, a page can declare which one is the real one — the canonical. Google treats that as a strong hint and not as an instruction, and where it disagrees it indexes the URL it chose instead. That matters because everything the page earns is credited to Google's choice rather than yours: the URL you link to, share and measure may not be the one collecting the value.seo.gsc-canonical-mismatch
- Google can fetch the pages it tries to crawlGoogle reports separately on whether it could fetch a page at all, as opposed to whether it decided to index it. A fetch that fails — a server error, a redirect loop, a page returning 'not found' — means Google has nothing to work with, and repeated failures cause it to try less often. This is worth knowing precisely because it is intermittent: the page may load perfectly when you check it.seo.gsc-fetch-failed
- Google has fetched every sitemap it has been given, without errorsA sitemap is how a site tells Google which pages exist and when they changed. Search Console records what it has been given, when it last managed to fetch each one, and how many errors it found — and that record regularly disagrees with what the site is actually serving. A sitemap submitted years ago and never fetched since, or one full of URLs that no longer resolve, is worse than none: it is a source Google has learnt to distrust.seo.gsc-sitemap-problems
- Google indexes the pages it has looked atGoogle crawls far more pages than it indexes, and a page it has crawled and declined to index will never appear in a search result. It is not a penalty and there is usually no message about it — the page simply earns nothing. The common causes are pages that duplicate each other closely, pages with very little of their own content, and pages Google reached but judged not worth storing. Only Search Console knows this has happened; it is invisible from the outside.seo.gsc-not-indexed
- Images have alt text across the whole siteScreen readers announce nothing where these images are, and search engines have no idea what they show. This covers every page we crawled, not just the home page we loaded in a browser.seo.images-missing-alt
- Internal links are not blocked from search enginesA nofollow on a link to one of your own pages tells search engines not to follow it. The practice comes from an old technique for steering how importance flowed around a site, which has not worked that way for years. Today it mostly just stops the pages on the other end being found.seo.nofollow-internal-links
- Language tags are valid and reciprocalYou are telling search engines which version of a page to show people in different countries. Where the codes are wrong or the pages do not point back at each other, that instruction is discarded and visitors can be sent to the wrong version — or the pages compete with each other.seo.hreflang-problems
- Link text describes where it goesLinks reading “click here” or “read more” tell a visitor nothing until they read the surrounding sentence, and tell a search engine nothing at all. Someone using a screen reader often navigates by jumping between links, and hears only the link text.seo.vague-anchor-text
- Links to other sites still workA link to a page on another site that no longer exists sends anyone who follows it to an error page. That reflects on you rather than on whoever moved the page, and it is the sort of small decay that makes a site feel unmaintained.seo.broken-outbound-links
- No internal links are brokenVisitors clicking these get an error page instead of what they wanted. Search engines following them waste effort on dead ends, and any value from links pointing at those pages is lost.seo.broken-internal-links
- No page has lost a significant share of its search trafficA page quietly losing the traffic it used to get is the hardest kind of problem to notice, because nothing breaks and no error appears anywhere. Comparing two equal periods against each other is the only way it shows up. The causes are usually external — a competitor moving above you, a change in what Google shows for that query — or a change you made and did not connect to the outcome.seo.gsc-declining-pages
- No page is accidentally hidden from searchA noindex instruction tells Google to keep a page out of search results entirely. That is exactly right for a thank-you page or a checkout step, and catastrophic on a page you want found — it is invisible, and no amount of other work will change that until the instruction is removed. It is worth checking because it is usually left behind by accident after a redesign.seo.noindex-pages
- No page returns a server errorA page returning a server error is failing outright rather than merely missing. Visitors see an error instead of your site, and repeated server errors cause search engines to slow their crawling or stop altogether — which affects pages that are working perfectly well.seo.server-errors
- No page you want indexed is blocked from being indexedA page can be kept out of Google deliberately — by a rule in robots.txt, or by a noindex instruction in the page or its headers. That is a legitimate thing to do for a checkout or a staging area, and a disaster when it happens to a page that is meant to earn traffic. It is one of the few site problems that is completely invisible from the front end: the page looks perfect to a visitor and does not exist to a search engine.seo.gsc-blocked-from-indexing
- No two pages share the same contentWhen the same text is reachable at more than one address, Google picks one to show and ignores the rest. It does not always pick the one you would have chosen, and the versions compete with each other rather than one ranking properly.seo.duplicate-content
- Page titles are uniqueWhen several pages share a title, Google has to guess which one to show for a search — and they compete with each other rather than each ranking for what it is actually about.seo.duplicate-titles
- Pages are reachable within a few clicksHow many clicks a page is from the home page is read as a signal of how important you consider it — by visitors and by search engines alike. Pages buried more than four clicks down are rarely found by either.seo.crawl-depth
- Pages are set up for phone screensWithout a viewport tag, phones render the page at desktop width and shrink it, so text is unreadably small and visitors have to pinch and scroll sideways. Most people will simply leave.seo.missing-viewport
- Pages declare their canonical addressA canonical tag tells Google which address is the real one for a page. Without it, the same page reachable with a tracking parameter or a trailing slash can be treated as several competing pages.seo.missing-canonical
- Pages have enough content to rankA page with very little text gives a search engine almost nothing to work with, so it rarely ranks for anything. This is worth checking rather than assuming: a contact page or a gallery is legitimately short, and padding it out would make it worse for the person reading it.seo.thin-content
- Pages preview correctly when sharedWhen someone shares these pages on Facebook, LinkedIn or WhatsApp, there is no image or headline — just a bare link. Shared links with a picture get noticeably more attention than ones without.seo.missing-social-tags
- Pages preview properly on X and elsewhereSharing these pages produces a bare address with no picture or headline. A shared link with an image gets noticeably more attention than one without.seo.missing-twitter-card
- Redirects go straight to their destinationEach redirect is another round trip before the visitor sees anything, which is most noticeable on a phone. Search engines also give up after a few hops.seo.redirect-chains
- robots.txt is not blocking pages you want foundA page disallowed in robots.txt is a page search engines will not read. That is often deliberate — admin screens, carts, internal search results — but it is worth confirming none of them matter. The serious case is a page that appears in your sitemap and is blocked at the same time: the sitemap says index this, robots.txt says do not look, the block wins, and the contradiction usually means one of the two files is out of date.seo.blocked-by-robots
- robots.txt is present and validrobots.txt is the first file a search engine asks for. Mistakes in it are quiet — a typo'd rule is simply ignored, so you think a page is blocked when it is not, or the reverse.seo.robots-txt
- Search descriptions are uniqueSeveral of your pages show the same summary underneath them in Google. Someone scanning the results cannot tell them apart, and Google often discards a description it has seen elsewhere and writes its own instead.seo.duplicate-meta-descriptions
- Search engines are told who runs the siteNothing on a site says, in a form a machine can read, which organisation it belongs to unless somebody puts it there. That block is what connects a website to a business: it is what a knowledge panel is built from, what ties a company to its social accounts, and increasingly what an AI assistant reads when deciding whether a site is a business it can name. It is one block, written once, and it goes on every page.seo.missing-business-schema
- Search terms close to the first page have been identifiedAlmost nobody goes to the second page of results, so a search term ranking eleventh earns close to nothing while a term ranking ninth earns steadily. Terms sitting just off the first page are the cheapest improvement available to most sites, because the work needed to move a page from eleventh to eighth is a fraction of what it took to get to eleventh in the first place.seo.gsc-striking-distance
- Sitemap lists only live, indexable pagesA sitemap is a list of pages you are telling Google are worth indexing. Including broken pages, redirects or pages marked noindex sends a contradictory signal and wastes the effort Google spends on your site.seo.sitemap-contains-bad-urls
- Structured data has everything Google needsMarkup that parses perfectly is still discarded if it is missing a property Google treats as mandatory — a product with no price, an offer that never says which currency, a recipe with no picture. Nothing warns the site owner. The block is there, it looks right in the source, and no rich result ever appears. It is a more common failure than broken markup and a harder one to notice, because everything about it looks correct.seo.structured-data-missing-required
- Structured data is complete enough to be worth havingBeyond the properties Google insists on, there are ones it uses when they are there and quietly does without when they are not. An article with no author or date, a business with no phone number, a product with no picture — each still works, and each gives a thinner result than the same page would get with the field filled in. It also matters more than it used to, because the systems that summarise pages for AI answers read the same markup.seo.structured-data-incomplete
- Structured data parses correctlyThe markup that produces star ratings, prices and FAQ dropdowns in search results is invalid on these pages, so it is silently ignored. You get none of the benefit and no warning that anything is wrong.seo.invalid-structured-data
- Structured data types are spelled the way schema.org spells themA type name that is not one schema.org defines means nothing to a search engine, and the whole block is ignored. British spelling is the usual cause: the vocabulary is American, so it is Organization rather than Organisation, and a site that writes it the British way has invisible markup and no indication of why. Nothing in a browser or a page source shows it up.seo.structured-data-type-typo
- The picture shown when your links are shared actually loadsA page can name the image to use when somebody shares it, and that image can quietly stop existing — renamed in a redesign, deleted with an old media library, moved when the site changed platform. The tag stays behind pointing at nothing. Every share after that is a bare grey link with no picture, and the owner is the last person on earth to find out, because they look at their own site rather than at what their link looks like when somebody else posts it.seo.social-image-broken
- Titles are a sensible lengthGoogle cuts titles off at roughly 600 pixels — about 60 characters — so the end of a long title never gets read. Very short titles waste the most valuable line of text you get in a search result.seo.title-length
- XML sitemap is present and validA sitemap is how you tell Google which pages exist and are worth looking at. Without one, pages that are not well linked internally may never be found at all.seo.sitemap
- Your pages get clicked about as often as their ranking suggestsA page can rank well and still be ignored. What somebody sees before deciding whether to click is the title and the description Google shows, and a page whose click-through rate is far below what your own other results at the same position achieve is being passed over for a reason that has nothing to do with its ranking. This is the cheapest traffic there is to recover, because the page is already winning the hard part.seo.gsc-low-ctr
- Your sharing image is big enough to be shownSocial platforms have a floor below which they will not show a picture at all, and a second one below which they show a small square thumbnail rather than a banner across the width of the post. An image under either is not a smaller version of the same result — it is a visibly worse-looking link. Vector images are refused outright whatever their size, which catches sites that point the tag at their logo.seo.social-image-too-small
- Your site has an icon for the browser tabThe small icon beside a page's name identifies a site in a row of twenty open tabs, in a bookmark list, and — since Google started showing it — beside every mobile search result. Without one, a browser draws a blank sheet of paper, which is the visual equivalent of an unbranded envelope. It is among the cheapest things on any audit to put right and among the most consistently overlooked, because the person who built the site has it cached and sees an icon that nobody else does.seo.missing-favicon
Speed
19 checks- Every page gets the files it asks forA file that is missing on one template is missing on every page built from it, which is usually hundreds of pages rather than one. It is also the hardest kind to notice from the inside: a browser that has an older copy of the file will carry on showing it long after the file itself has gone, so the site looks correct to whoever built it and broken to everybody arriving fresh.performance.failed-requests-sitewide
- Every page responds promptlyWhen one part of a site responds noticeably slower than the rest, it usually points at one specific thing rather than at the hosting in general — a heavy search query, an unindexed database lookup, or a page rebuilding something on every request. That makes it one of the more fixable speed problems, because there is a single cause to find.performance.slow-pages
- Everything the page asks for loadsYour page requests these and gets nothing back. Depending on what they are, that means a missing image, a stylesheet that never applies, or a script that never runs — and the page may look fine to you if your browser has an older copy cached.performance.failed-requests
- First visit after a quiet spell is not slowSome hosting puts a site to sleep when nothing has visited for a while, and the next request has to wake it. Once warm the site is fine, which is why this is easy to miss — the person testing it has usually just loaded the page. The people who get the slow version are the ones arriving overnight, and Google when it crawls at an odd hour.performance.slow-cold-start
- Google has enough visitor data to report on your siteGoogle publishes real-visitor speed figures for a site only once enough Chrome users have been there to make the numbers meaningful and anonymous. Below that threshold there is nothing to publish, which is the ordinary situation for a small business site and says nothing about how well the site is built. It does mean every speed figure in a report like this one is a simulation rather than a record of what happened to anybody.performance.no-field-data
- Images reserve their space before loadingThe browser cannot tell how tall these images will be until they have downloaded, so it draws the page without them and then pushes everything down when they arrive. That is the jump people experience as a page moving under their thumb.performance.images-missing-dimensions
- Main content appears quickly on a phoneThe largest thing on the page — usually the main image or headline — is what a visitor is waiting for. Until it finishes loading they are looking at a blank or half-built page. This is measured on a mid-range phone on mobile data rather than on a fast desktop connection, because that is the harder case and the one most visitors are actually in.performance.slow-lcp
- Main image is sized for the screenWhen the biggest image on the page is far wider than the space it is shown in, visitors download image data they can never see — and image data grows with the square of the width, so an image at twice the needed width is roughly four times the bytes. It is paid for on the connection least able to afford it.performance.oversized-lcp-image
- No errors on the rest of your pages eitherScripts fail by template rather than by site. A gallery that throws only where there is a gallery, a booking widget that throws only on the booking page — checking the home page finds none of it, and neither does the owner, whose browser has a working version cached from before whatever broke it. It is one of the few faults where the people affected are exactly the people who never mention it, because they assume the site is meant to be like that.performance.console-errors-sitewide
- No errors while the page loadsSomething on the page is failing every time it loads. Often it is a harmless third-party script, but it is also how a broken booking form, a dead tracking tag or a checkout that silently fails shows up — none of which announce themselves to the person running the site.performance.console-errors
- Nothing from another company holds up your first paintA stylesheet or script in the head of a page stops the browser drawing anything until it has finished downloading. When that file is on another company's server, the visitor is looking at a blank screen while a machine you do not control decides how fast to answer — and it needs a fresh connection to be opened before it can even start. A font service or a tag manager loaded this way is the most common cause, and both have a supported way of loading that does not block.performance.third-party-blocking
- Nothing needless blocks first paintThe browser will not draw a single pixel until certain stylesheets and scripts have finished downloading. On a phone that is dead time the visitor spends looking at nothing. It is worse when one of those files is pulled in by an @import inside another stylesheet, because it cannot even start downloading until the first has arrived.performance.render-blocking-resources
- Other companies' code is a small share of your pageAnalytics, chat widgets, advert tags, embedded video players and social buttons all download code from somebody else's servers before your page is finished. Each one arrived for a reason, but they accumulate — nobody ever removes a tag — and they are downloaded over the visitor's connection, not yours. This is one of the few speed problems where the fix is a decision rather than a development project: something on the list is usually a tool the site stopped using and nobody switched off.performance.third-party-weight
- Our measurements match what your visitors actually getA scan loads a site once, on one connection, from one place. Google's figures come from four weeks of real Chrome visitors on whatever devices and connections they happened to have. When the two disagree it is worth knowing which way: a site that tests well and performs badly for real people usually has slow pages beyond the one that was tested, or visitors on worse phones than the test assumes. A site that tests badly and performs well in the field is being judged too harshly by the test, and saying so is more useful than defending the number.performance.lab-and-field-disagree
- Page is light enough for mobile dataSomeone on mobile data pays for every megabyte a page downloads, and waits for them. A heavy page is usually a handful of images that were never resized rather than anything structural, which makes it one of the cheaper speed problems to fix.performance.heavy-page
- Page stays responsive while loadingA phone can only do one thing at a time. While scripts are running, taps and scrolls are queued rather than acted on — which reads to a visitor as the site being frozen, not as it being slow. They tend to tap again, and then leave.performance.blocking-scripts
- Page stays still while loadingContent moves after it first appears, so someone reading or reaching for a button can have it shift under them. This is what causes the mis-taps that make a site feel broken on a phone.performance.layout-shift
- Server responds promptlyThis is how long your hosting takes to begin sending the page at all — before any images, fonts or scripts have started. Every other speed improvement is stacked on top of this delay, so when it is slow it is the one to fix first.performance.slow-ttfb
- Your site reacts quickly when real visitors tap itResponsiveness is how long a page takes to visibly react after somebody taps it — not how fast it loads, but whether it feels stuck once it has. It is the one thing a scan genuinely cannot measure, because there is nobody there to do the tapping, so a synthetic test can only estimate it from how busy the page looks. Where Google has collected the figure from real Chrome visitors, it is a measurement rather than an estimate, and it is usually caused by scripts doing work in response to the tap itself.performance.field-inp-poor
Security
16 checks- A content security policy is in placeA content security policy tells the browser which scripts it may run. Without one, anything that manages to get injected into a page — through a compromised plugin, a hijacked advert, or a comment field — runs with the same trust as your own code.security.missing-csp
- Browsers are told to stay on HTTPSYour site works over HTTPS, but it never tells browsers to remember that. The very first visit of the day can still be sent over an insecure connection before the redirect happens, which is the window an attacker on shared Wi-Fi needs.security.missing-hsts
- Camera, microphone and location access are restrictedAnything embedded in your pages — an advert, a chat widget, a map — can ask the visitor for access to their camera, microphone or location, and the request appears to come from you.security.missing-permissions-policy
- Cookies are only sent over an encrypted connectionA cookie without the Secure flag is sent over a plain, unencrypted connection as readily as over an encrypted one. Anyone sharing a network with the visitor — a café, a hotel, an office guest network — can read it, and a single request to the http version of the site is enough to expose it, even when every page normally redirects to https. The flag costs nothing and there is no reason for a cookie on a secure site to be missing it.security.cookies-not-secure
- File types cannot be second-guessedWithout this header a browser may ignore what your server says a file is and guess instead. An uploaded image that is secretly a script can then be run as one.security.missing-content-type-options
- Folders are not browsableYour server is showing a file listing instead of a page. Anyone can read it and see exactly what is in that folder — backups, spreadsheets, database dumps, anything left there and forgotten.security.directory-listing
- Login cookies are hidden from scripts on the pageA session cookie marked HttpOnly can be sent to the server but cannot be read by JavaScript running on the page. Without that flag, any script that ends up on the site — through a compromised plugin, a hijacked advert, or a comment field that did not escape its input — can read a logged-in session and use it from somewhere else. It is the difference between a script injection being an embarrassment and being an account takeover.security.session-cookie-readable-by-scripts
- Only chosen authorities can issue certificatesA CAA record names which companies are allowed to issue security certificates for you. Without one, any of them can — which is how someone who briefly gains access to your DNS can obtain a valid certificate for your domain and keep it after you lock them out.security.missing-caa
- Only modern encryption is acceptedTLS 1.0 and 1.1 are obsolete encryption standards with known weaknesses. Modern browsers refuse them anyway, so leaving them switched on gains you nothing and leaves a weaker option available to anything that asks for it.security.legacy-tls
- Secure connection is enforcedVisitors who type your address without 'https' stay on an unencrypted connection. Browsers mark those pages 'Not secure' in the address bar, and anything typed into a form on them can be read in transit.security.no-https-redirect
- Secure pages load only secure resourcesA page served over HTTPS that pulls in an image or a script over plain HTTP is only as secure as its weakest request. Browsers either block those outright — leaving a visible gap where the image should be — or drop the padlock, which is the one thing visitors have been taught to look for.security.mixed-content
- Security certificate covers this domainA certificate has to be issued for the domain it is serving, by an authority browsers recognise. One that names a different domain, or that a server issued to itself, is treated exactly like a fake: a full warning page before anybody reaches you, deliberately difficult to click past.security.certificate-name-mismatch
- Security certificate is not close to expiringWhen a certificate expires, every visitor gets a full-page browser warning telling them your site is not safe, and most leave rather than click through it. Search engines stop crawling too. Most certificates renew automatically, so this is worth checking while there is still time rather than discovering it on the day.security.certificate-expiry
- Server software version is not advertisedYour responses include the name and version of the software running your site. When a vulnerability is published for that version, automated scanners find sites like yours by reading this header.security.version-disclosure
- Visitor addresses are not leaked to other sitesBy default, clicking a link out of your site hands the destination the full address of the page they left. If your addresses contain anything private — an order number, a customer reference, a search someone typed — that goes with it.security.missing-referrer-policy
- Your pages cannot be framed by another siteWithout this, someone can load your site inside an invisible frame on their own page and trick visitors into clicking your buttons while thinking they are clicking something else. It is most often used against login and payment forms.security.missing-frame-options
Accessibility
10 checks- Accessibility check completedThe accessibility pass runs inside a real browser, and a few things can stop it: a content security policy that blocks our script, or a page that never finishes loading. When that happens the accessibility section is marked unchecked rather than passed, because finding no problems and being unable to look are not the same result.a11y.not-tested
- Buttons have readable labelsA button with no readable label is announced to a screen reader as nothing more than 'button'. This usually happens when the button contains only an icon. If the unlabelled one is a menu toggle or an Add to Basket, the site becomes unusable rather than merely awkward.a11y.button-name
- Form fields are labelledA form field without a label gives a screen reader user no indication of what to type into it. Placeholder text is not a substitute — it vanishes the moment somebody starts typing. On a contact or checkout form this is the difference between an enquiry and a visitor who leaves.a11y.label
- Headings run in orderScreen reader users navigate by jumping between headings. When levels are skipped, that outline stops matching the page and becomes confusing to move through.a11y.heading-order
- Images have descriptions for screen readersSomeone using a screen reader hears nothing where these images are. If any of them are product photos, logos or buttons, that part of the page simply does not exist for them.a11y.image-alt
- Links have readable textA screen reader announces these as just "link", with nothing to say where they go. Icon-only links, such as social media buttons, are the usual cause.a11y.link-name
- Page declares its languageScreen readers pick their pronunciation from this. Without it, English can be read aloud with the wrong accent and rhythm, which is hard to follow.a11y.html-has-lang
- Page has a title for screen readersThe title is what appears in the browser tab, in bookmarks, and as the headline of your search result. It is also the first thing a screen reader announces on arrival.a11y.document-title
- Remaining WCAG 2.1 AA checksThe bespoke accessibility checks cover the faults we see most often. This one collects everything else axe tests against the Web Content Accessibility Guidelines, grouped into a single finding rather than a wall of rule ids. Each one makes the site harder to use for somebody relying on assistive technology.a11y.other-violations
- Text is readable against its backgroundText has to stand out enough from what is behind it to be readable. Pale grey on white looks refined on a designer's monitor and disappears for anyone with reduced vision, or simply reading on a phone in daylight. It is one of the most common reasons people give up on a page, and one of the easiest to fix.a11y.color-contrast
Trust
8 checks- Browsers are allowed to fill in your formsSetting autocomplete to off tells the browser not to offer a visitor their own saved details. On a phone that turns a form somebody could have completed with one tap into a dozen fields typed with a thumb, and every extra field measurably costs completions. It is almost always inherited from a template or added years ago to stop a browser suggesting the wrong thing, and on a password field it is worse than useless: password managers ignore it, so the only people it stops are the ones typing by hand, who then choose something they can remember.trust.autofill-blocked
- Email cannot be forged from your domain (SPF)There is no record saying which servers are allowed to send email as you. That means someone can email your customers from your address, and it also means your own legitimate email is more likely to land in spam.trust.missing-spf
- Every form field has a labelA field whose only description is grey text inside the box loses that description the moment somebody starts typing. Anybody who is interrupted half way down a form comes back to a column of filled-in boxes with nothing saying what each one held, and a screen reader announces most of them as "edit text" and nothing else. A visible label also gives the field a bigger target, because tapping a label focuses the box it belongs to.trust.unlabelled-form-fields
- Fields tell the browser what they are forAn autocomplete token tells the browser that a box wants an email address or a postcode, so it can offer the visitor the one they have saved. Without it the browser has to guess from the field's name, and it frequently guesses wrong or gives up. It is also a WCAG requirement at AA, because the same information lets assistive software present a field in terms somebody recognises.trust.missing-autocomplete
- Forms submit over a secure connectionA form that posts to a plain HTTP address sends everything typed into it unencrypted, readable by anything between the visitor and your server. Browsers warn about it directly on the field when the form collects a password or payment details. A page can be served over HTTPS and still have a form that submits insecurely, which is why this is checked separately from the connection itself.seo.insecure-forms
- Phone and email fields bring up the right keyboardA box expecting an email address should be marked as one. When it is not, a phone shows the ordinary letter keyboard rather than the one with the @ sign on it, and the browser does not check the address looks plausible before the form is sent. The same goes for a phone number, which should bring up the number pad. It is a single word in the markup and it is the most common reason a mobile enquiry form feels awkward to use.trust.form-field-wrong-type
- You are told when someone forges your email (DMARC)DMARC tells mailbox providers what to do with email that fails your other checks, and sends you a report when someone tries. Without it, impersonation attempts happen silently.trust.missing-dmarc
- Your DMARC policy acts on forged emailA DMARC policy of 'none' asks mailbox providers to report forgeries and then deliver them anyway. That is the right place to begin — the reports are how you find out which services legitimately send mail as you — but on its own it stops nothing. Most domains that publish DMARC never move past it, and monitoring is easily mistaken for protection.trust.dmarc-policy-none
Privacy
4 checks- Cookies the site sets are explained somewhere on itAnyone whose site stores cookies has to tell visitors what is stored, who by and how long it lasts, in language an ordinary person can follow. It is a standing obligation rather than a one-off, and it applies to cookies that needed permission and to the ones that did not. A site with tracking on it and nothing anywhere explaining that tracking is the clearest version of getting this wrong, and it is also the easiest to put right.privacy.no-cookie-policy
- Every company your site shares visitors with is one you know aboutA cookie stored against another company's domain means that company saw the visit — the address of the page, the browser, the address it came from — and can recognise the same person on any other site it is embedded in. Under UK data protection law the site owner is responsible for that sharing and has to tell people it happens, whether or not the cookie itself needed consent. Most owners are unaware of half the list, because the companies arrive attached to a plugin or an embedded video rather than by decision.privacy.third-party-cookies
- Nothing is stored on a visitor's device before they agree to itUK law treats putting anything on a visitor's device — a cookie, or a record kept in the browser's own storage — as something that needs permission first, unless it is genuinely required to deliver what the visitor asked for. Analytics does not count as required, however anonymous it is, and the Information Commissioner's Office has said so repeatedly. This is one of the few things a website audit finds where the risk is a regulator rather than a lost sale.privacy.cookies-before-consent
- Tracking cookies do not outstay the consent behind themA tracking cookie carries the permission it was set under, and permission does not last forever. Regulators across Europe have converged on around thirteen months as the point at which a site should ask again, on the reasoning that somebody who agreed to be measured last year has not agreed to be measured indefinitely. Several popular analytics tools still default to a two-year lifetime, so this is usually a setting nobody chose rather than a decision. Browsers now cap what they will store at a little over a year regardless, which hides the difference between a long setting and an absurd one.privacy.long-lived-cookies
AI readiness
2 checks- You guide AI tools to your best contentAn emerging convention: a plain text file listing what your site is and which pages matter, written for AI assistants rather than search engines. Nobody is penalised for not having one, and support is still patchy — but it is cheap, and it is how you get described accurately rather than guessed at.ai.missing-llms-txt
- You have decided what AI crawlers may doCompanies training AI models and answering questions with your content read your site using crawlers with names like GPTBot and ClaudeBot. Your robots.txt says nothing about them, so by default they are all allowed. That may be exactly what you want — being quoted in an AI answer is visibility — but it is worth being a decision rather than an accident.ai.crawler-directives