Guides

Straight answers to
the questions people ask.

100 guides, each one taking a single real question — why an assistant will not cite your site, why a page never appeared on Google, what a security header actually does — and answering it without padding. Every claim here is one this tool can measure on your own site.

100 guides

AI agents and automation

How agents inspect the web, why they get it wrong, and how to check their work.

How do AI agents inspect websites?

What actually happens when you ask an assistant about a website — and why the answer is usually inferred rather than observed.

Read

Why do LLMs hallucinate website audits?

The specific reason a model invents plausible findings about your site, and the two design choices that stop it.

Read

Can I trust what ChatGPT says about my website?

A practical guide to which parts of an AI answer about your site are reliable, which are guesses, and how to tell them apart in seconds.

Read

What is MCP and why does it matter for websites?

The Model Context Protocol in plain terms, and what changes when an assistant can measure a site instead of describing one.

Read

How do I give an AI agent a website tool?

Two ways to let an assistant measure websites — connect an MCP server, or define a tool yourself — with working code for both.

Read

What data does an AI agent need before recommending website changes?

The minimum an agent must have in hand before its advice is worth acting on — and what each missing piece causes it to get wrong.

Read

What should an AI agent do when it cannot determine something?

Why "not checked" and "passed" must never be the same answer, and how a well-built tool keeps them apart.

Read

Why is AI-generated SEO advice usually wrong?

Four reasons an assistant gives you outdated, generic or inapplicable SEO advice — and the one change that fixes most of it.

Read

How do I check an AI agent's claims about a website?

Verifying an assistant's findings yourself, in a browser or one terminal command, without taking anything on trust.

Read

Can an AI agent fix my website for me?

What agents can genuinely do unattended, what still needs a person, and how to set up the loop so mistakes are caught.

Read

How do I audit a website from the command line?

Getting a complete, machine-readable audit with one curl command — and pulling out just the parts you need with jq.

Read

How do I monitor a website for regressions automatically?

Catching the silent breakages — an expired certificate, a stripped header, a robots.txt that started blocking Google — before anyone reports them.

Read

How do I add a website check to my CI pipeline?

Blocking a deploy when it would break your headers, certificate, indexability or accessibility — with copy-paste config for GitHub Actions and GitLab.

Read

What is a deterministic website audit?

Why running the same audit twice should give the same answer, what breaks that property, and why it matters more than accuracy.

Read

Why do two SEO tools give my site different scores?

Different checks, different weights, different definitions of failure — and why comparing scores across tools is meaningless.

Read

What does a website score actually mean?

How a score out of 100 is built, what it can honestly tell you, and the four things it cannot.

Read

Why did my website score change when I did not change anything?

The four causes of an unexplained score movement, and how to tell which one you are looking at in under a minute.

Read

How do I track website changes over time?

Building a history of what your site actually served, so you can answer "when did this break" instead of guessing.

Read

How do I compare two websites objectively?

Benchmarking against a competitor without fooling yourself — what is fair to compare, and what is not comparable at all.

Read

How do I audit hundreds of websites at once?

Running a portfolio, a client list or a research sample through a measurement API without abusing anyone — including the sites you are measuring.

Read

AI visibility and answer engines

Why assistants do or do not cite your site, and what actually controls it.

Why is my website not showing on ChatGPT?

The four things that decide whether ChatGPT can find, read and cite your site — and how to tell which one is stopping you.

Read

Why can't Claude see my website?

Anthropic runs three separate crawlers with three separate purposes. Blocking the wrong one is the usual reason a site is invisible.

Read

Why doesn't Grok recommend my site?

Grok leans heavily on real-time social signals and live web fetches, which makes it behave differently from other assistants — and rewards different things.

Read

Why doesn't Perplexity cite my website?

Perplexity cites sources on every answer, which makes it the easiest assistant to diagnose — and the most demanding about page structure.

Read

How do I get my site cited by AI assistants?

The mechanics that must be right, then the content decisions that actually earn the citation — in the order worth doing them.

Read

Should I block AI crawlers from my site?

An honest look at what you gain and what you give up, and why the answer is usually "block some, allow others".

Read

Does blocking GPTBot hurt my traffic?

Blocking GPTBot alone costs you almost nothing. The damage comes from the other rules people add at the same time.

Read

How do I check if AI crawlers can read my site?

Four tests you can run yourself in about ten minutes, in the order that finds the problem fastest.

Read

Does JavaScript hurt AI crawlers?

Yes, more than it hurts search engines. If your content only exists after JavaScript runs, most AI crawlers see an empty page.

Read

What is llms.txt and do I need it?

A proposed convention for pointing language models at your best content. Cheap to add, unproven, and no substitute for the things that do work.

Read

What is generative engine optimization (GEO)?

Optimising to be quoted inside an AI answer rather than ranked in a list of links — what genuinely differs from SEO, and what is the same work under a new name.

Read

How does Google AI Overviews pick sources?

What is known about how AI Overviews selects what it quotes, what follows from it, and what nobody outside Google actually knows.

Read

Which AI crawlers have visited my site?

Finding GPTBot, ClaudeBot, PerplexityBot and the rest in your own logs — and what their presence or absence actually tells you.

Read

How do I know if AI assistants are sending me traffic?

Identifying referrals from ChatGPT, Perplexity and Claude in your analytics — and why most AI-driven visits are invisible.

Read

What is Google-Extended and should I block it?

What this token actually controls, what it does not affect, and the mistake that removes you from Google search entirely.

Read

How do I allow AI search but block AI training?

A robots.txt that keeps you visible in AI answers while opting out of training corpora — with the precedence rules that make it work.

Read

What is the difference between crawling, indexing and citing?

Three separate stages, each with its own failure mode — and why fixing the wrong one wastes months.

Read

Why is my site in Google but not in AI answers?

The four differences between ranking in search and being cited by an assistant — and why the first does not lead to the second.

Read

How do answer engines choose between two similar pages?

When two pages cover the same ground, the tiebreakers are extractability, specificity, corroboration and attribution — in roughly that order.

Read

How do I make a page quotable by AI?

The structural changes that make a passage extractable — most of them a rearrangement of what you have already written.

Read

Does schema markup help with AI search?

What structured data actually does for answer engines — and why it is worth adding for a reason other than the one usually given.

Read

Will AI replace search traffic to my site?

An honest look at what changes when answers appear without clicks, which content is most exposed, and what actually holds up.

Read

Web observability and evidence

Reading DNS, certificates, headers and third parties as measurements rather than opinions.

What do my DNS records actually say?

Reading your own DNS from first principles — which records exist, what each one decides, and the four commands that show you all of them.

Read

How do I read a TLS certificate?

What each field in a certificate means, which ones actually matter, and how to inspect any site's certificate in one command.

Read

What is DNSSEC and do I need it?

What DNSSEC protects against, what it does not, and an honest account of when it is worth the operational risk.

Read

What is an MX record and why is my email failing?

How mail routing actually works, the six configuration faults that cause almost every delivery problem, and how to check each one.

Read

How do I find out what a website is built with?

Identifying a site's stack from what it discloses — and understanding why disclosure is itself a finding.

Read

What third parties does my website load?

Finding every external origin your pages pull in, and why the list is almost always longer than you think.

Read

How do I find every page on a website?

Enumerating a site's URLs from sitemaps, crawling and internal links — and why no method gives you a complete list.

Read

What is web provenance and why does it matter?

Knowing where a claim about a website came from — and why "measured", "derived" and "inferred" must never be presented as the same thing.

Read

What is a web property graph?

Seeing a domain as a connected set of observations — hosts, certificates, records and dependencies — rather than as a single page.

Read

How can I tell if a website is real or a scam?

The signals that genuinely distinguish a legitimate site from a fraudulent one — and the ones everybody cites that mean nothing at all.

Read

What is evidence-based website analysis?

The difference between a tool that tells you a verdict and one that shows you what it saw — and why the second is worth insisting on.

Read

How do I prove my website is secure?

What you can honestly demonstrate about your site's security, what nobody can prove, and how to make the claim checkable.

Read

What HTTP headers should every website send?

A prioritised list of response headers, what each one prevents, and which are safe to add without testing.

Read

What does my Server header reveal about me?

What version disclosure gives an attacker, why it is worth removing, and why removing it is not by itself a security measure.

Read

What can't be measured without a browser?

The honest boundary of server-side analysis — what needs JavaScript execution, and why saying so beats guessing.

Read

Why does my audit score disagree with Lighthouse?

Two tools measuring genuinely different things — and why expecting them to agree is the actual mistake.

Read

How do I tell if a website is down or just blocking me?

Distinguishing a real outage from bot protection, geoblocking or a network problem — and what each failure mode looks like.

Read

What is a CDN and how do I tell if I am behind one?

How to detect a CDN from response headers, and why it changes what an audit of your site is actually measuring.

Read

How do I audit a website I don't own?

What is legitimate to measure on someone else's site, where the line is, and how to do it without being a nuisance.

Read

How do I verify a website's security badge is real?

Why most trust seals are decorative images, and the one property that separates a verifiable badge from a picture.

Read

Search engine optimisation

The mechanics that decide whether a page can rank at all.

How can I improve my SEO?

The work that actually moves rankings, ordered by effect per hour spent — and the popular tasks that do almost nothing.

Read

Why is my website not showing on Google?

Work through it in order — not indexed, indexed but not ranking, or ranking but not for anything you noticed.

Read

What is a good meta description length?

Around 150–160 characters, and length is the least interesting thing about it.

Read

Why does my site have no title tag?

The commonest causes, and why a missing title costs more than almost any other single fault.

Read

How do I fix duplicate title tags?

Why the same title on many pages holds all of them back, and how to generate distinct ones without writing hundreds by hand.

Read

What is a canonical URL and why does it matter?

It tells search engines which version of a page is the real one. Get it wrong and you can de-index your own site.

Read

Do I need a sitemap.xml?

Not strictly. It helps discovery on larger or poorly-linked sites, and it costs nothing — but it will not fix a site that cannot be crawled.

Read

How do I fix robots.txt blocking Google?

How to read the file correctly, what the precedence rules actually are, and the three mistakes that cause almost every accidental block.

Read

What is structured data and do I need it?

Machine-readable facts about your page. Worth adding where it genuinely describes the content, worthless — and occasionally harmful — everywhere else.

Read

Why are my images missing alt text and does it matter?

It matters for people using screen readers, for image search, and for anything trying to understand your page. The fix is small and the excuses are usually wrong.

Read

How many words should a page have?

There is no target. Word count is not a ranking factor, and chasing one reliably makes pages worse.

Read

Does page speed affect SEO?

Yes, modestly and as a tie-breaker. It affects whether people stay far more than it affects where you rank.

Read

Security and email authentication

Headers, certificates, exposure, and stopping people forging your domain.

Is my website secure? How do I check?

What you can verify yourself in twenty minutes, what needs tooling, and what "secure" does and does not mean.

Read

What are security headers and which do I need?

Six headers, what each actually prevents, and a configuration you can paste and adjust.

Read

What is a Content Security Policy?

A list of where your page is allowed to load things from. The strongest defence against script injection, and the easiest header to get wrong.

Read

Why does my site say "Not Secure"?

Either you are not on HTTPS at all, or you are and something on the page is not. The second is harder to spot.

Read

How do I check if my SSL certificate is valid?

Five things to verify, how to check each from the command line, and the failure that only shows up on mobile.

Read

What is HSTS and should I enable it?

It forces browsers to use HTTPS for your domain. Almost always worth it — with two decisions that are genuinely hard to reverse.

Read

I found an API key in my HTML. What now?

Rotate first, investigate second. Then work out whether the key ever needed to be in the browser at all.

Read

How do I stop people sending email that looks like it came from my domain?

Three DNS records. Without them anyone can forge your address, including to your own customers — and this applies even if you never send email.

Read

What are SPF, DKIM and DMARC?

Three DNS records that together decide whether your email arrives and whether anyone can forge it. What each one does, in plain terms.

Read

What is a CAA record and do I need one?

A DNS record naming which certificate authorities may issue certificates for your domain. One line, and it closes a real gap.

Read

Trust, privacy and content quality

What makes a site read as credible to a person and to a machine.

Accessibility, mobile and presentation

Whether everyone can use the site, and how it looks when shared.

Rather have it measured than read about it?

Every guide here describes something this tool checks directly. Paste a URL and get the answer for your own site — 216 checks across 20 categories, each one explained where it appears.