Post-Update SEO Audit Checklist: 60 Checks in Diagnostic Order
A post-update SEO audit checks data integrity, technical health, manual actions, content composition, trust signals, links and the SERP itself, in that order. The sequence matters more than the checks. Two of the seven sections exist purely to rule out drops that are not drops, and running them first saves weeks. Work through all 60 below, marking each pass, fail or not applicable. Your failures produce a verdict on which area is most likely responsible.
Free tool
Post-update SEO audit checklist
Sixty checks in the order I run them, from cheapest to most expensive. Mark each one pass, fail or not applicable. The sections are sequenced deliberately: the first two rule out the most common false alarms before you spend time on content or links. Your failures determine the verdict at the bottom.
0 of 60 answered
Data integrity and baseline 8 checks
Run this first. Two of the most common traffic drops are not drops at all.
The drop date is the first day clicks fell, not the day you noticed criticalSet Search Console to daily granularity over 16 months and find where the line breaks from its weekly rhythm. Most people are three to seven days out.
Clicks fell, not only impressions criticalIf impressions fell while clicks held and average position improved, this is a reporting change rather than a ranking loss.
The drop is not explained by seasonality highCompare against the same weeks last year, not the previous period. Travel, retail, education and tax queries all move annually.
The drop is a step, not a slope highAlgorithm events produce a visible step on one date. A gradual slope over months is content decay, lost links or competitors.
No tracking or analytics change coincided with the drop mediumA GA4 property change, consent banner or tag migration can look exactly like a traffic loss.
Search Console data has been exported and saved mediumExport by date, query, page and country. The 16 month window rolls, so this evidence expires.
A pre-drop baseline has been recorded mediumThe 28 days before the drop is the number recovery gets measured against. Agree it now.
Brand and non-brand traffic have been separated lowA fall in brand searches is a marketing problem, not an algorithm one.
Technical and indexing 12 checks
Cheapest to check, fastest to fix, and the only section where acting immediately is correct.
Indexed page count did not fall in the same week criticalCheck Indexing then Pages. A fall in indexed pages alongside clicks means technical, not algorithmic.
No accidental noindex on important templates criticalStaging settings pushed to production is the classic version of this and can remove a whole section within days.
robots.txt does not block anything important criticalFetch it and read it. A single disallow line can cost an entire directory.
Canonical tags point where they should highA plugin or theme update that points every page at the homepage collapses a template while the site looks intact.
No server errors or downtime during the drop week highSustained 5xx responses during a crawl cause real ranking loss that resolves once stability returns.
No site migration, redesign or CMS change within three days of the drop highCorrelation with a deploy is stronger evidence than any algorithm theory and faster to test.
Redirects resolve in one hop and return 301 highChains and 302s during a migration lose signals gradually and look algorithmic.
XML sitemap is current and returns only indexable URLs mediumA sitemap full of redirects and 404s wastes crawl budget and slows reassessment.
Core Web Vitals have not regressed mediumRarely the cause on its own, but a regression caps how well improvements can be assessed.
Mobile rendering matches desktop content mediumGoogle indexes mobile first. Content hidden or dropped on mobile is content Google does not see.
Structured data validates without errors mediumBroken schema loses rich results, which reads as a click loss without a ranking change.
Hreflang, if used, is reciprocal and correct lowBroken hreflang causes the wrong regional version to rank, which looks like a country-specific drop.
Manual actions and spam policies 7 checks
A manual action overrides everything else and has its own fix path.
The Manual Actions report is empty criticalTen seconds to check and it changes everything if it is not. A manual action needs a reconsideration request.
The Security Issues report is empty criticalA hacked site produces sudden severe losses and must be cleaned before anything else matters.
No scaled content: pages produced mainly to rank rather than to help highThis is the most common spam policy finding in audits, and it applies whether pages were written by people or AI.
No third-party content hosted to borrow the domain reputation highCoupon, casino or loan sections placed on an otherwise credible site are site reputation abuse.
No expired domains repurposed for unrelated content highBuying an aged domain to reuse its authority is an explicit policy violation since March 2024.
No cloaking, doorway pages or sneaky redirects mediumSometimes inherited from a previous agency or a compromised plugin rather than done deliberately.
No attempts to manipulate AI Overviews or AI Mode output mediumGoogle extended the spam policies to cover this in May 2026.
Content quality and site composition 13 checks
Where core update and helpful content demotions actually live.
You know whether the loss is site-wide or confined to one template criticalGroup pages by template and compare click loss per group. This single step determines the entire remediation plan.
Less than a third of indexed pages earn effectively no impressions highOn most demoted sites this figure is 40 to 70 percent. That ratio is itself the signal.
No large set of near-duplicate pages sharing most of their text highCity variants, tag archives and thin product pages are the usual offenders.
Pages that dropped contain information not already in the top ten results highIf the page only rephrases what already ranks, there is no reason for Google to prefer it.
Content is produced when there is something to say, not to a publishing schedule highCalendar-driven volume is the defining pattern of a helpful content demotion.
The site covers a defined subject rather than everything mediumTopical sprawl reads as content production. Focus reads as expertise.
Pages answer the question fully so the reader does not search again mediumRead your biggest losers as a reader rather than as the publisher.
Comparison and review content shows the product was actually used mediumThe experience component added in December 2022 targets exactly this gap.
Titles and headings match what the page delivers mediumOverpromising headlines were a stated target of the February 2026 Discover update.
Content is genuinely updated when revised, not just re-dated mediumA script bumping dates weekly without changing anything is a trust failure.
Thin tag, category and archive pages are not indexed lowThese inflate the index with pages nobody searches for and nobody would miss.
Pagination and faceted URLs are controlled lowUncontrolled parameters can multiply a small site into tens of thousands of thin URLs.
No auto-generated pages published without review lowProgrammatic pages are fine when each one is useful. They are scaled content abuse when they are not.
Trust and expertise signals 10 checks
Weighted heaviest in the quality rater guidelines.
Real contact details and a business address are published highA contact form alone is weak. Anonymous sites carry the lowest trust rating in the rater guidelines.
An About page explains who runs the site and how it makes money highOwnership, funding and purpose. This is a trust check, not a marketing page.
Every substantive page has a named, verifiable author highNot Admin, not the brand name, and not an invented persona with a stock photo.
Statistics and claims link to the original source highLinking to another blog repeating a study is not sourcing.
Author bios state credentials relevant to the subject mediumQualification, years of practice or a track record that matches what they are writing about.
Affiliate, sponsorship and commercial relationships are disclosed mediumUndisclosed monetisation on advice content is a direct trust failure.
YMYL claims carry a qualified reviewer credit mediumMedical, legal and financial content is judged against the highest standard.
Ads and interstitials do not obstruct the content mediumIf the reader works around the layout to read, trust and page experience both suffer.
Corrections are handled openly rather than silently lowA visible correction note builds more trust than a quiet edit.
The brand or author has a reputation findable off your own site lowSearch your brand name. If nothing exists beyond your own properties, authoritativeness is thin.
Links 5 checks
Check last. Most drops attributed to links turn out to be something else.
No links were bought, exchanged or placed at scale highWhat you built is what matters, not what a toxicity tool flagged.
Anchor text distribution looks natural mediumA large share of exact-match commercial anchors is the classic manipulated profile.
Referring domains have not fallen sharply over twelve months mediumSteady link loss produces a gradual decline that is often misread as an algorithm event.
No disavow file was uploaded without confirming links were the cause mediumDisavowing good links removes real value and takes weeks to reverse.
Internal links still point at your priority pages lowRedesigns quietly remove navigation links, and internal link equity moves with them.
SERP and competition 5 checks
Your rankings can be fine while your clicks are not.
Impressions and average position did not stay flat while clicks fell criticalThat pattern is click displacement, usually an AI Overview. It is not a ranking penalty and needs a different fix.
The queries that lost clicks do not show an AI Overview highSearch five or six of your biggest losers in an incognito window and look at what sits above your result.
New competitors have not taken your former positions highIf a genuinely better page now ranks, that is competitive work, not recovery work.
You have not lost a featured snippet you previously held mediumLosing a snippet cuts clicks sharply while your ranking position stays the same.
SERP layout for your queries has not changed mediumNew ad formats and expanded features compress organic visibility without touching rankings.
Why the order is the method
Most audit checklists are organised by discipline: technical here, content there, links at the end. That is fine for a health check and wrong for a drop. After a traffic loss you are not surveying the site, you are eliminating suspects, and suspects should be eliminated cheapest first.
The first two sections take under an hour between them and resolve a large share of cases. The content and trust sections take days and only become worth running once the cheap explanations are gone. Running them in the wrong order is how a site ends up three months into a content project for a problem that was a canonical tag.
Order
Section
Checks
Measurement (what a failure means)
1
Data integrity and baseline
8
The loss may be a reporting change, seasonality or tracking, not a ranking event
2
Technical and indexing
12
Fix immediately. This is the only section where acting fast is correct
3
Manual actions and spam policies
7
Overrides every other diagnosis and has its own fix path
4
Content quality and composition
13
Core update or helpful content territory, reassessed only at core updates
5
Trust and expertise signals
10
Weighted heaviest in the rater guidelines, usually quick to close
6
Links
5
Rarely the cause. Confirm before disavowing anything
7
SERP and competition
5
Rankings may be intact while clicks are not
How severity is assigned
Each check carries a severity that weights the verdict. It reflects how likely a failure is to be the actual cause of a drop, not how bad the issue is in general terms.
Critical, 9 checks. Why: A failure here usually is the cause or invalidates the whole diagnosis. An empty Manual Actions report and a correct drop date are worth more than any amount of content work.
High, 20 checks. Why: Common primary causes. Several failing together in one section is a strong signal.
Medium, 23 checks. Why: Contributing factors. Rarely the sole cause, but they cap how well a recovery performs.
Low, 8 checks. Why: Worth fixing, not worth prioritising during an active recovery.
Be careful with the not applicable option. It is there for genuine cases, such as hreflang on a single-language site. Using it to skip something you have not checked is how a self-audit produces a confident wrong answer.
Before you start
Three things make the audit far more accurate and take about twenty minutes to prepare.
Export 16 months of Search Console data by date, query, page and country. Why: Half the checks reference this data, and the 16 month window rolls forward, so the evidence expires.
Identify your exact drop date and run it through the date checker. Why: Knowing whether a confirmed update was rolling out changes how you read every content and trust failure below.
Crawl the site as it currently stands. Why: This is the version Google judged. Once you start fixing things, you lose the ability to prove what the state was.
If the drop happened in the last two days, read the first 48 hours checklist before this one. It covers what to preserve and, more importantly, what not to change while you are still diagnosing.
What to do with the verdict
The verdict names the section carrying the most weighted failures. It is a strong lead, not a diagnosis, and two situations deserve extra caution.
Two sections score closely. Why: Overlapping causes are common and each needs its own fix and its own reassessment cycle. That is when a recovery takes six months instead of two, as explained in how long recovery takes.
The verdict points at content but the drop date matches nothing. Why: Content failures exist on almost every site. Without a matching update they may be background noise rather than the cause. Work through the seven causes of a drop with no update instead.
Once you know the area, the depth tools take over: the E-E-A-T rubric for trust and expertise gaps, the disavow builder if links are genuinely implicated, and the volatility sensor if no confirmed update matches your date. All of them are on the tools page.
Frequently asked questions
How long does this audit take?
The first three sections take about an hour if you have Search Console access. Content and trust take a day or more on a large site because they require sampling pages rather than checking settings. Links and SERP take under an hour.
Do I need to answer all 60 checks?
The verdict works from whatever you answer, but it sharpens as you complete more. At minimum finish the data integrity, technical and spam sections, because those three rule out the causes that make everything else irrelevant.
Is my data saved anywhere?
No. The checklist runs entirely in your browser and nothing is transmitted or stored. Use the copy button to keep your results, because refreshing the page clears them.
What if everything passes but traffic still fell?
The most likely explanations are competitive displacement, where a better page took your position, or click loss to an AI Overview. Neither is a fault on your site. Re-read anything you marked not applicable, because that is where self-audits usually hide the answer.
Can this replace a professional audit?
For a single clear cause on a site you know well, often yes. It cannot analyse your Search Console exports, separate overlapping causes, or compare your pages against the competitors that replaced them, which is where most of the value in a paid audit sits.
Two sections scored close and you cannot separate them?
That is the hardest case to self-diagnose and the most expensive to get wrong. Send your Search Console access and your copied results. Within 48 hours I will tell you which cause is primary and what order to fix them in. Free, no obligation.