- Why Google Search Console is the right place to start
- What you need before you open the tool
- Step 1: Start with the Coverage (Pages) report
- Step 2: Move to the Performance report, but filter it
- Step 3: Core Web Vitals and Mobile Usability
- Step 4: Links report
- Step 5: Manual actions and security issues
- A real example from a client audit
- Where this data quietly misleads you
- Turning your findings into a fix list
- How often to repeat this
- Frequently asked questions
- Useful references
The short version: a Google Search Console SEO audit means working through five reports in order: Coverage, Performance, Core Web Vitals, Links, and Mobile Usability, then cross-checking what you find against your actual pages before you touch a single thing. It takes about two hours for a site under 500 pages, longer if you're dealing with an ecommerce catalogue. Most people skip straight to the Performance report because it has the nice graphs, which is exactly backwards.
Why Google Search Console is the right place to start
Search Console is free, it comes straight from Google, and it shows you what Google sees, not what you assume it sees. That last bit matters more than people admit. I've sat in meetings where a client swore blind their new product pages were indexed because they could find them by searching the exact title. That's not proof of indexing, that's Google matching an exact string. Search Console's Coverage report is proof.
It's also the tool that catches problems before rankings drop, not after. Rankings are a lagging indicator. Indexing errors, crawl issues and manual actions show up here first, sometimes weeks before you'd see the damage in traffic.
What you need before you open the tool
- Verified property access (domain property, not just URL prefix, if you can get it)
- Your current sitemap URL
- A spreadsheet or Google Sheet to log findings, don't try to hold it all in your head
- Access to your CMS so you can act on what you find, not just document it
If your Google Analytics setup is patchy, sort that alongside this audit rather than after it. There's no point fixing indexing if you can't measure whether the fix worked. If you're not sure whether you need the tracking code on every single page or how events are being counted, it's worth reading whether every page really needs the analytics code and what counts as an event in GA4 before you start pulling conclusions from either tool.
Step 1: Start with the Coverage (Pages) report
Go to Indexing then Pages. This is where you find out how many of your URLs Google has decided not to bother with, and why. Look for these specific statuses:
- Crawled, currently not indexed, this usually means thin or duplicate content. Google looked, wasn't impressed, moved on.
- Discovered, currently not indexed, Google knows the URL exists but hasn't crawled it yet, often a crawl budget issue on large sites.
- Duplicate without user-selected canonical, you've got two or more URLs saying the same thing and you haven't told Google which one wins.
- Soft 404, the page returns a 200 status but Google thinks it looks empty or broken.
Write down the count for each category and export the URL list. You'll need it later when you're prioritising fixes rather than just admiring the problem.
Step 2: Move to the Performance report, but filter it
This is the report everyone opens first, and it's fine, as long as you don't stop at the headline graph. Set the date range to 16 months if the property has that much history, then compare year on year rather than month on month, because seasonal noise will fool you otherwise.
Then filter by page. Sort by impressions descending and look for pages with high impressions but a click-through rate under 1%. That's usually a title tag or meta description problem, not a rankings problem, the page is showing up, people just aren't clicking it. I'd also filter by query and search for your own brand name to check how much of your "organic traffic" is people typing your company name into Google, which isn't really SEO working, it's brand recognition working.
If you want a slower, more detailed walkthrough of reading this exact report on its own, there's a dedicated guide on how to check your website's performance in Search Console that goes deeper into the filters than I have room for here.
Step 3: Core Web Vitals and Mobile Usability
Under Experience, check Core Web Vitals first. You want to know what percentage of URLs fall into "poor" or "needs improvement" for LCP, INP and CLS. Google has said publicly this is a ranking factor, though a small one, and I've seen it matter most on ecommerce sites where product pages load a dozen third-party scripts for reviews, chat widgets and retargeting pixels.
Mobile Usability sits next to it. If you're seeing errors like "text too small to read" or "clickable elements too close together" on more than a handful of pages, that's a template problem, fix it once in the theme rather than page by page.
Step 4: Links report
Go to Links, and look at both the top linking sites and the top linked pages. Two things to check:
- Are your most-linked pages the pages you want ranking, or is it your old careers page from 2019 that nobody's updated in years?
- Is there a sudden cluster of links from spammy foreign domains you don't recognise? That won't always hurt you, but it's worth a disavow file if the pattern's obvious and growing.
Step 5: Manual actions and security issues
This takes thirty seconds and people skip it constantly. Under Security & Manual Actions, check both tabs. A manual action means a human at Google has penalised the site, and no amount of content strategy fixes that until the penalty is lifted. I've only seen this twice in real client work, both times from a previous agency buying links from a private blog network, and both times the client had no idea it had happened.
A real example from a client audit
A few years back I audited a B2B services site that had lost around 40% of its organic traffic over five months, and the client was convinced it was a Google algorithm update. It wasn't. The Coverage report showed 1,200 URLs marked "duplicate, Google chose different canonical than user." Their developer had launched a filtered version of every blog category page (by month, by author, by tag) without canonical tags, so Google was left to guess which URL to index, and it kept picking the wrong one for around a third of their content.
We fixed the canonical tags, resubmitted the sitemap, and traffic recovered over the following ten weeks, not overnight, Google doesn't work that fast, but it recovered. The algorithm update theory would have led them nowhere. The Coverage report told them exactly what had gone wrong within twenty minutes of opening it.
Want AI doing the heavy lifting in your marketing?
I build the systems that handle the boring 80 percent, so you get your week back. Done properly, with the human kept in.
Where this data quietly misleads you
Here's the bit most guides gloss over. Search Console's numbers are not exact, and Google has never claimed they are. Click and impression counts are rounded, filtered for anonymised low-volume queries, and sampled differently depending on date range. If you export the same 90-day period twice a week apart, the historic numbers can shift slightly because Google reprocesses data retroactively. I've had clients panic over a "17% traffic drop" that turned out to be a reporting lag, not a real drop, confirmed a week later when the numbers settled.
The uncomfortable part is that most audits treat this data as gospel because it's the only free source available. Treat every number as directionally true, not literally true. Big swings, over 20% and sustained for more than two weeks, deserve investigation. A 4% wobble over three days doesn't deserve a panicked Slack message to your developer.
Turning your findings into a fix list
By this point you should have a spreadsheet with real numbers in it. Prioritise like this:
- Fix first: manual actions, security issues, and any page that used to rank and is now returning a soft 404 or has dropped out of the index entirely.
- Fix soon: duplicate content without canonicals, Core Web Vitals failures on your top 20 pages by traffic, and mobile usability errors affecting a template.
- Fix when you have time: low CTR pages that need title tag rewrites, orphaned pages with a handful of impressions, and internal linking gaps.
None of this matters if there's no content strategy sitting behind the fixes. An audit tells you what's broken, it doesn't tell you what to write next. If your content plan is essentially "publish twice a week and hope," it's worth reading how a proper core content strategy improves rankings rather than treating publishing volume as a strategy on its own.
How often to repeat this
I run a light version of this monthly for retained clients, five to ten minutes checking Coverage and manual actions, and a full audit quarterly. Anything that's launched a site migration, a big template change, or a new CMS needs an audit within a week of launch, not three months later when the damage has compounded.
These days I'll also run findings through an AI tool as a second pass before finalising the report, not to replace the manual work but to catch anything I've missed with fresh eyes. I wrote up exactly how that worked when I asked one AI to audit another AI's audit, and it found gaps a human reviewer had also missed. Worth doing as a final check, not as your only step.
If this is more than you want to take on yourself, or you've run the audit and don't trust your own read on the priorities, that's a reasonable point to bring in outside help rather than guessing. A good AI and marketing consultant should be able to sit with your Search Console data for an afternoon and tell you which three fixes will move the needle, rather than handing you a fifty-point checklist you'll never work through.
For anyone who wants the condensed, checklist version of everything above in one place, there's a step by step version of this exact process laid out on the site as well, worth bookmarking alongside this one.
Frequently asked questions
How long does a proper Search Console SEO audit take?
For a site under 500 pages, budget two hours for the full walkthrough: Coverage, Performance, Core Web Vitals, Mobile Usability, Links and Manual Actions. Ecommerce sites with large catalogues, expect half a day, mostly spent categorising duplicate and thin-content URLs.
Do I need Google Analytics as well, or is Search Console enough?
Search Console tells you how Google finds and indexes your site. Google Analytics tells you what visitors do once they arrive. You need both, they answer different questions, and neither replaces the other.
Why do my Search Console traffic numbers not match Google Analytics?
They measure different things by design. Search Console counts clicks from Google's organic search results specifically. Analytics counts sessions from all channels and applies its own attribution rules, sampling and bot filtering. A gap of 10 to 20% between the two is normal, not a sign either tool is broken.
What's the single most common problem this audit uncovers?
Duplicate content without a clear canonical URL, usually caused by filtering, tagging, or pagination features added by a developer without SEO in mind. It's the issue I find most often in client audits, and it's fixable in an afternoon once you've spotted it.