You commented RANK, so here are all thirty.

Every line below was checked against Google's own documentation — Search Central, the spam policies, or the robots.txt RFC. Nine claims that usually appear on lists like this one didn't survive the check, and they're at the bottom with the reason.

About half of these are things to stop believing. Those are the ones that waste the most time.

The one-paste version

Paste this into Claude at the root of your site, then paste the thirty below it:

Audit this site against the 30-point SEO checklist below. For each item tell me PASS, FAIL or N/A, and show me the file, URL or setting that proves it. Don't mark anything PASS without the evidence. Then fix every FAIL one at a time, and tell me what you changed.

Technical

1. Robots.txt blocks crawling, not indexing.
Blocking a page in robots.txt does not keep it out of Google. The URL can still appear, without a snippet, if something links to it.
"we might still find and index a disallowed URL if it is linked from other places on the web" — Google

2. Noindex only works if crawled.
The classic own-goal: block a page in robots.txt and add noindex, and the noindex never fires, because Googlebot never gets to read it. Pick one.
"For the noindex rule to be effective, the page or resource must not be blocked by a robots.txt file" — Google

3. Robots.txt is voluntary.
It's a sign, not a lock. Well-behaved crawlers honour it; nothing forces them to.
"crawlers are requested to honor... These rules are not a form of access authorization." — RFC 9309

4. Sitemaps don't guarantee crawling.
Submitting a sitemap is a hint, not an instruction.
"submitting a sitemap is merely a hint: it doesn't guarantee that Google will download the sitemap or use the sitemap for crawling URLs on the site" — Google

5. Pages must return 200.
Nothing outside the 2xx family gets indexed. 4xx is never indexed; 5xx gets dropped over time.
"Google only indexes pages that are served with an HTTP 200 (success) status code" — Google

6. No soft 404s.
A missing page that returns 200 with an error message on it is a "soft 404". Return a real 404 or 410 so Google can drop it cleanly.
Google

7. Canonicals are a hint, not a rule.
You express a preference. Google decides.
"indicating a canonical preference is a hint, not a rule" — Google

8. Some duplicate content is fine.
There is no "duplicate content penalty". Keep the word some — this is not a licence to spin or scrape, which are separate, named violations.
"Some duplicate content on a site is normal and it's not a violation of Google's spam policies" — Google

9. Redirect straight to the destination.
Googlebot will follow up to 10 hops, but don't make it.
"Avoid chaining redirects... we advise redirecting to the final destination directly" — Google

10. 301s signal the canonical.
A permanent redirect tells the indexing pipeline which URL should win.
"the indexing pipeline uses the redirect as a signal that the redirect target should be canonical" — Google

Content

11. Unique, concise page titles.
"A good title is unique to the page, clear and concise, and accurately describes the contents of the page" — Google

12. Google may rewrite your title.
It doesn't rewrite every title. It rewrites when it detects a problem — which is a reason to write good ones, not to stop bothering.
"If we've detected an issue on the page, we may try to generate an improved title link from anchors, on-page text, or other sources" — Google

13. Unique meta description per page.
"Create unique descriptions for each page on your site" — Google

14. Descriptions aren't always used.
Snippets come from the page first. Your description is a sometimes-substitute.
"Snippets are primarily created from the page content itself. However, Google sometimes uses the meta description HTML element..." — Google

15. No ideal number of headings.
Google lists this in its own SEO-myths section, next to the duplicate-content penalty.
"There's also no magical, ideal amount of headings a given page should have" — Google

16. Write alt text.
"The most important attribute when it comes to providing more metadata for an image is the alt text" — Google

17. AI Overviews need no extra setup.
There is no AI Overviews checklist, and no way to leave AI Overviews while staying in normal Search. nosnippet and noindex remove you from both.
"a page must be indexed and eligible to be shown in Google Search with a snippet... There are no additional technical requirements" — Google

18. Blocking Google-Extended won't hurt Search.
Google-Extended is the AI-training token. Googlebot is not. Blocking Googlebot removes you from Search entirely, AI Overviews included — so block the right one.
"Google-Extended does not impact a site's inclusion in Google Search nor is it used as a ranking signal in Google Search" — Google

Worth knowing alongside that: training crawlers and retrieval crawlers are separate switches. Blocking GPTBot or ClaudeBot keeps you out of training data. It does nothing to whether ChatGPT or Claude can cite you — that runs on OAI-SearchBot and Claude-SearchBot.

19. Hyphens, not underscores.
"we recommend using hyphens (-) instead of underscores (_) to separate words in your URLs" — Google

20. Don't stuff keywords.
"filling a web page with keywords or numbers in an attempt to manipulate rankings in Google Search results" — Google

21. Use real links, not scripts.
An onclick handler is real, working, clickable code — and Google still can't follow it. It has to be an <a> element with an href.
"Google can only crawl your link if it's an <a> HTML element... with an href attribute" — Google

22. Link every page you value.
"Every page you care about should have a link from at least one other page on your site" — Google

23. External links can build trust.
Linking out doesn't leak anything. Google says it can help.
"using external links can help establish trustworthiness (for example, citing your sources)" — Google

24. Normal links need no special tag.
"For regular links that you expect Google to fetch and parse without any qualifications, you don't need to add a rel attribute" — Google

25. Paid links use sponsored, not nofollow.
True for paid links specifically. For comments and user content, rel="ugc" is still the right one.
"The nofollow attribute was previously recommended for these types of links and is still an acceptable way to flag them, though sponsored is preferred" — Google

26. Add rel="ugc" to comment links.
"We recommend marking user-generated content (UGC) links, such as comments and forum posts, with the ugc value" — Google

27. Don't buy or sell ranking links.
Both verbs. Selling links off your own site is the same named violation as buying them.
"Buying or selling links for ranking purposes" — Google

28. No excessive link exchanges.
Reciprocal linking isn't banned. Doing it at scale as the point is.
"Excessive link exchanges ('Link to me and I'll link to you') or partner pages exclusively for the sake of cross-linking" — Google

29. Don't automate link building.
"Using automated programs or services to create links to your site" — Google

30. Skip low-quality directory links.
"Low-quality directory or bookmark site links" — Google

What didn't make the list, and why

These appear on most SEO checklists. They were cut because they can't be stated as a flat rule without becoming false.

  • LCP, CLS and time-to-first-byte thresholds. Real numbers, but they're targets measured at the 75th percentile, not pass/fail rules. And TTFB isn't a Core Web Vital at all.

  • E-E-A-T as a ranking factor. Google lists this in its own myths section: "While E-E-A-T itself isn't a specific ranking factor, using a mix of factors that can identify content with good E-E-A-T is useful."

  • "Google penalises AI content." It doesn't. "Our focus on the quality of content, rather than how content is produced." Mass-producing low-value pages to game rankings is the violation, whoever or whatever writes them.

  • Domain Authority. A Moz metric. It appears nowhere in Google's ranking-systems documentation.

  • "Submit your site to search engines." "you usually don't even need to do anything except post your site on the web."

  • "Don't require links in contracts." The actual rule is requiring a link without letting the other party qualify it. Sponsorship contracts requiring links are fine.

  • LSI keywords. No Google source exists. The term has never appeared in Google documentation.

  • A word count. "Are you writing to a particular word count because you've heard or read that Google has a preferred word count? (No, we don't.)"

  • One H1 per page. No such rule: "You can use H1 tags as often as you want on a page."

One last thing, on the word "penalty"

Google doesn't use it. Its terms are manual action — a human reviewer, and it shows up in Search Console — and algorithmic action, which doesn't. If someone tells you you've been "penalised", ask which one they mean. Quite often it's neither, and rankings simply moved.