SEOking

Website audit report

bbc.co.uk

83
/ 100
B · Good

1 critical and 2 high-severity issues found across 129 checks.

Checks run
129
Passed
97
Failed
23
Pages crawled
12

Scanned 2026-09-01T01:46:05+00:00 · 8 host IPs · cert expires in 145 days

This report is not offered to search engines. It is reachable by link only. If you own bbc.co.uk you can publish or delete it.

What changed since last time

A few checks regressed since the last audit. None are critical, but they were passing before. Score -1.

Regressed: was passing, now failing

  • No phrase is repeated unnaturally

How you compare

Measured against every site SEOking has audited: a corpus that grows with each scan and cannot be reconstructed after the fact.

Your position

72th percentile of 29 sites audited. The average site scores 72, the median 71.

The most unusual thing you fail

Reasonable number of scripts

83% of the sites we have audited get this right and yours does not. Of everything on this report, it is the fault that most sets you apart from your competition, which makes it the first thing worth fixing.

Inbox Trust Index

Our own measure of whether your domain is trusted by the systems that decide if mail reaches an inbox. No other website audit reports this. It is built from BounceZero's deliverability platform.

73
/ 100
Good

Solid foundations, with a few gaps worth closing.

What is pulling it down: DKIM signing. See the email deliverability section below.

Measured against our corpus

We have measured deliverability across 221,734 domains. Yours is not among them, which simply means no one has needed to verify an address at it. The score above is from live measurements of your own DNS.

For context, 3.5% of the domains we have measured accept mail to any address, which makes their bounce behaviour unpredictable.

How your page actually renders

Loaded in a real browser at phone size. This is close to what a visitor and Google's renderer see.

Screenshot of bbc.co.uk on a mobile viewport
390 × 844 viewport
Words rendered
2075
JS errors
12
Failed resources
1

Score over time

84
84
84
84
83

Oldest on the left. Every re-run is kept.

Your plan

The 23 faults on this report come from 10 underlying causes. Fixing a cause fixes everything under it, so this is ordered by score returned per unit of work, not by severity alone.

The 5 quickest steps here take you from 83 to about 90. That is 7 points for changes measured in minutes and hours, not weeks.

  1. 1. Stop JavaScript overriding the indexing directives

    Development work · days to weeks→ 86/100

    A canonical or noindex injected at runtime silently overrides what the server said, and the served HTML still looks correct to anyone reading the source.

    Fixes 2 findings: JavaScript does not rewrite indexing directives · The title survives rendering

  2. 2. Fix email authentication

    DNS edit · minutes→ 88/100

    These are all records in your DNS. One editing session fixes every one of them, and it is the change most likely to stop your mail being filtered.

    Fixes 3 findings: DKIM signing is configured · MTA-STS policy published · TLS reporting enabled

  3. 3. Harden DNS and hosting

    Server or CDN config · under an hour→ 90/100

    Resilience and reputation work — lower urgency, but cheap while you are already in these systems.

    Fixes 4 findings: No JavaScript errors on load · All page resources load successfully · Certificate is not shared with unrelated domains · DNSSEC enabled

  4. 4. Point the site's own authority at the pages that earn

    Template change · a few hours→ 93/100

    Internal links decide which of your pages search engines treat as important, and the decision is usually an accident of navigation design. It costs nothing to change and it changes what ranks.

    Fixes 4 findings: Navigation promotes pages that earn money · Every page is linked from another · Each page covers a distinct subject · Every page is linked from somewhere

  5. 5. Close the takeover and impersonation gaps

    DNS edit · minutes→ 94/100

    A subdomain pointing at a service that released it can be claimed by anyone, who then publishes on your domain. Deleting the record costs nothing and closes it immediately.

    Fixes 1 finding: No lookalike domain can send mail as your brand

  6. 6. Decide whether AI assistants may cite you

    Server or CDN config · under an hour→ 96/100

    A growing share of questions are answered without a results page. Being quotable is a distribution channel, and it is usually blocked by a plugin default rather than a decision.

    Fixes 2 findings: AI assistants can cite this site · A curated summary is published for assistants

  7. 7. Make the structured data qualify

    Template change · a few hours→ 98/100

    Rich results — ratings, prices, FAQs, breadcrumbs — are what turn a listing into an advert, and they are decided by whether a few required properties are present. Markup that is invalid or incomplete is work already done that currently earns nothing.

    Fixes 3 findings: Breadcrumbs are marked up · The entity links out to its profiles · Site-wide search is declared

  8. 8. Remaining individual fixes

    Mixed · varies→ 99/100

    These do not share a root cause with anything else on the report.

    Fixes 2 findings: Title is the same before and after JavaScript · No phrase is repeated unnaturally

  9. 9. Make the sitemap trustworthy

    Server or CDN config · under an hour→ 99/100

    lastmod is how Google decides what to recrawl first. A timestamp that is identical on every URL is a build date, and Google learns to ignore lastmod for the whole site once it notices.

    Fixes 1 finding: Sitemap lastmod dates are meaningful

  10. 10. Reduce what the page has to load

    Development work · days to weeks→ 100/100

    Image and script weight drive every speed metric you are failing. This is the slowest fix here and the one with the longest tail.

    Fixes 1 finding: Reasonable number of scripts

Fix these first

Ranked by severity, then by how much score each returns.

  1. critical

    1. JavaScript does not rewrite indexing directives

    +9 pts

    JavaScript changes the directives Google acts on after the page loads. The served HTML looks correct to anyone reading the source, and Google indexes what rendering produced — so a canonical or noindex injected at runtime silently overrides everything the server said.

    canonical: served 'https://www.bbc.co.uk/', rendered 'https://www.bbc.com'
    robots: served 'max-image-preview:large', rendered 'noodp, noydir'

    How to fix: Emit the final canonical and robots directives server-side. Nothing that decides indexing should depend on a script running.

  2. high

    2. DKIM signing is configured

    +8 pts

    No DKIM keys found on any common selector. Without DKIM your mail cannot prove it was not altered in transit, and DMARC cannot pass on forwarded messages.

    How to fix: Enable DKIM in your mail provider and publish the key it gives you.

  3. high

    3. No lookalike domain can send mail as your brand

    +8 pts

    We generated and checked 31 plausible misspellings and variants of your domain. 9 of the 15 registered variants has mail servers configured, so it is technically able to send email that reads as yours to anyone skimming a sender address. Many such domains are entirely unrelated businesses that happen to have a similar name — this is a risk to be aware of and to defend against, not evidence that anyone is doing anything.

    b-bc.co.uk   [mail configured]
    bb.co.uk   [mail configured]
    bbc.co   [mail configured]
    bbc.net   [mail configured]
    bbcc.co.uk   [mail configured]
    bcb.co.uk   [mail configured]
    bvc.co.uk   [mail configured]
    gbc.co.uk   [mail configured]
    (1 further variant(s) resolve to your own infrastructure and are excluded — those are yours.)

    How to fix: Publish DMARC at enforcement so mail claiming to be your domain is rejected outright — that is the defence that works regardless of who owns a lookalike. Then register the closest unregistered variants; they cost a few pounds a year and are the cheapest brand protection available.

Full results

Security & trust

Whether the connection, certificate and headers hold up.

10 passed · 0 failed
100%
  • Served over HTTPS

    Secure connection working.

  • HTTP redirects to HTTPS

    Plain HTTP requests are redirected to the secure version.

  • No insecure mixed content

    All resources load securely.

  • Certificate is not near expiry

    Certificate valid for another 145 days (expires 2027-01-24).

  • Modern TLS version

    Negotiated TLSv1.3.

  • HSTS header

    HSTS is set.

  • Content Security Policy header

    Content Security Policy is set.

  • MIME sniffing protection header

    MIME sniffing protection is set.

  • Clickjacking protection header

    Clickjacking protection is set.

  • Referrer policy header

    Referrer policy is set.

Email deliverability

Whether your mail reaches inboxes or spam folders.

7 passed · 3 failed
80%
  • DKIM signing is configuredhigh

    No DKIM keys found on any common selector. Without DKIM your mail cannot prove it was not altered in transit, and DMARC cannot pass on forwarded messages.

    Enable DKIM in your mail provider and publish the key it gives you.

  • MTA-STS policy publishedlow

    No MTA-STS policy, so mail to you can be delivered unencrypted if an attacker strips TLS.

    Publish an MTA-STS policy and the _mta-sts TXT record.

  • TLS reporting enabledlow

    No TLS-RPT record, so delivery-encryption failures go unreported.

    Publish a _smtp._tls TXT record with a reporting address.

  • Domain can receive email

    2 mail server(s) configured.

  • SPF ends with a fail qualifier

    Ends in ~all (soft fail) — the usual safe setting.

  • SPF stays under the lookup limit

    The record forces about 2 DNS lookups. Comfortably within the limit of 10.

  • DMARC reports are collected

    Aggregate reports are being sent to a reporting address.

  • Exactly one SPF record

    One SPF record, as required.

  • DMARC policy is enforced

    DMARC policy is p=reject.

  • BIMI logo published

    BIMI record present — your logo can appear beside your emails.

Speed & Core Web Vitals

How fast real visitors experience the site.

8 passed · 1 failed · 1 skipped
92%
  • Reasonable number of scriptsmedium

    55 external script file(s) on the homepage. Each one is a separate request that can block rendering.

    Remove unused third-party tags and combine what remains.

  • Core Web Vitals from real users

    Not available: PageSpeed API returned 429. This usually means the site does not yet have enough Chrome traffic for Google to report field data. Lab measurements below still apply.

  • Compression enabled

    Served with gzip compression.

  • Server responds quickly

    Median response across 12 page(s) was 153 ms.

  • Homepage HTML is not oversized

    Homepage HTML is 713 KB.

  • Images declare width and height

    100 of 103 images declare dimensions.

  • Browser caching is allowed

    Pages may be cached by browsers and CDNs.

  • Images use a modern format

    35 image(s) are served as WebP or AVIF.

  • Images load lazily

    95 of 103 images use lazy loading.

  • Images are sized for the device

    489 of 590 image(s) provide a srcset.

Search fundamentals

The tags, files and signals search engines read first.

34 passed · 5 failed · 2 skipped
92%
  • AI assistants can cite this sitemedium

    6 assistant crawler(s) are blocked in robots.txt, so this site cannot be cited in the answers they write: Applebot-Extended, ChatGPT-User, Google-Extended, OAI-SearchBot, Perplexity-User, PerplexityBot. These are the crawlers that fetch a page in order to reference it in a reply, which is a referral rather than a copy. Blocking them is a legitimate choice — but it is usually a plugin or CDN default rather than a decision anyone made.

    Applebot-Extended — blocks Apple Intelligence
    ChatGPT-User — blocks ChatGPT when a user asks it to open a link
    Google-Extended — blocks Google AI Overviews and Gemini grounding
    OAI-SearchBot — blocks ChatGPT search results
    Perplexity-User — blocks Perplexity when a user follows a link
    PerplexityBot — blocks Perplexity answers

    If you want to appear in AI answers, allow these agents in robots.txt. If the block is deliberate, no change is needed — but confirm it was deliberate.

  • Breadcrumbs are marked upmedium

    No BreadcrumbList markup. Google replaces the raw URL in your listing with a readable breadcrumb trail when this is present, which is more legible and measurably more clickable — and it is one of the cheapest rich results to earn.

    Add BreadcrumbList JSON-LD to every page below the homepage.

  • The entity links out to its profilesmedium

    The Organization markup has no sameAs links; they are how an assistant confirms which business is yours.

    Add sameAs URLs to the Google Business Profile, LinkedIn, X and any other profiles the business owns.

  • Site-wide search is declaredlow

    No WebSite markup. With a SearchAction it can give you a search box directly inside your Google listing for branded queries.

    Add WebSite JSON-LD, with potentialAction/SearchAction if the site has its own search.

  • A curated summary is published for assistantslow

    No /llms.txt. It is a short, plain-text map of what a site is and which pages matter — a convention some assistants read to decide what to quote, and cheap to publish. It is not yet a standard anyone is obliged to honour, so treat it as a low-cost bet rather than a requirement.

    Publish /llms.txt: a heading, one paragraph describing the business, and a linked list of your most important pages.

  • Search Console connected

    Not measured — not configured on this instance. Connecting Search Console adds what no crawl can see: the queries this site already appears for, where it ranks, and how many people click. It is read-only and can be disconnected at any time.

  • Current search visibility

    Not measured — ranking data is not configured on this instance.

  • Homepage is indexable

    Homepage is open to indexing.

  • Mobile viewport declared

    Mobile viewport is declared.

  • Homepage title is present and well sized

    Title is 10 characters.

  • XML sitemap published

    Sitemap found listing 18011 URLs.

  • Homepage meta description is present

    Description is 148 characters.

  • Homepage canonical is correct

    Canonical points at this page.

  • Structured data present

    Structured data found: CollectionPage, ImageObject, ItemList, NewsMediaOrganization.

  • robots.txt does not block the site

    robots.txt present and open to search engines. 39 named crawler(s) are blocked, which is a deliberate choice rather than a fault.

  • Canonicals point at indexable pages

    Every canonical points at a page that is allowed to be indexed.

  • Language links point both ways

    Every hreflang reference is reciprocated by the page it names.

  • Canonical targets are live pages

    Canonical targets all return 200.

  • Sitemap and page directives agree

    No page is both listed in the sitemap and marked noindex.

  • Structured data parses

    All structured data blocks are valid JSON.

  • Noindex directives are readable

    No page relies on a directive Google is blocked from reading.

  • Language codes are valid

    Every hreflang value is a valid language or language-region code.

  • Marked-up content qualifies for rich results

    Every marked-up entity carries the properties Google requires.

  • Most crawled pages are indexable

    12 of 12 crawled page(s) (100%) can actually be indexed.

  • Each page lists itself

    Every page with hreflang annotations includes itself.

  • Language links point at indexable pages

    Every hreflang target is a live, indexable page.

  • The business is identified in structured data

    Identified as NewsMediaOrganization, Organization.

  • The business is a describable entity

    Organization or Person markup names the business to assistants.

  • No canonical chains

    No canonical points at a page that then canonicals somewhere else.

  • Sitemap lists canonical pages only

    Every sitemap URL is its own canonical.

  • Structured data is in the served HTML

    All structured data is present in the HTML the server sends.

  • Content is marked up to be answered

    FAQPage or HowTo markup gives assistants a structured answer to cite.

  • Pages are close to the homepage

    Every crawled page sits within four levels of the homepage (deepest: 4).

  • Social preview configured

    7 Open Graph tags found.

  • A default version is declared

    An x-default version is declared for visitors whose language matches none of your versions.

  • URLs are readable

    URLs use lowercase, hyphenated, extension-free paths.

  • Content is not served behind query parameters

    0 of 12 crawled URLs carry query parameters other than tracking tags.

  • Page language declared

    Language attribute present.

  • Link previews are configured for X/Twitter

    7 twitter: tag(s) found.

  • Structured data in use

    34 structured data object(s) across 12 page(s): Article, CollectionPage, ImageObject, ItemList, NewsMediaOrganization, Organization.

  • Model-training access is stated

    5 training crawler(s) blocked: Bytespider, CCBot, ClaudeBot, GPTBot, meta-externalagent. This is a business decision rather than an SEO one, and it is separate from being cited in answers: refusing training does not remove you from AI results, and allowing it does not put you in them.

Content & structure

Whether pages are unique, linked and crawlable.

24 passed · 5 failed
78%
  • Every page is linked from somewheremedium

    1 of 12 crawled pages had no internal link pointing at them. Search engines discover pages by following links, so an unlinked page is found late or not at all — and passes on none of its authority.

    1 affected URL

    Link these from a relevant parent page, your navigation, or a hub page.

  • Navigation promotes pages that earn moneymedium

    9 link(s) appear on nearly every page — the site-wide navigation, which is where most internal authority is allocated. 3 of them point at legal, account or administrative pages, and 3 of those sit among the eight best-linked pages on the site — level with, or above, the pages you sell from. Nobody decides this: a crawler counts every footer link as an endorsement repeated on every page, while visitors ignore footers. Those pages must exist and should not be among the best-linked things you publish.

    bbc.co.uk/accessibility  0.2%  [utility]
    bbc.co.uk/sounds  0.2%
    bbc.co.uk/sport  0.2%
    bbc.co.uk/usingthebbc/terms  0.2%  [utility]
    bbc.co.uk/aboutthebbc  0.2%
    bbc.co.uk/contact  0.2%
    bbc.co.uk/bbcnewsletter  0.2%
    bbc.co.uk/careers  0.2%  [utility]
  • Each page covers a distinct subjectmedium

    1 pair(s) of pages appear to cover the same subject, judged from their titles and headings. Two pages competing for one query split the links and relevance that should accumulate on one, and Google alternates between them — so neither settles into a stable position. Confirm against Search Console, which shows exactly which page it chooses. Every page of this type that was checked has this fault, and your sitemap lists 4 pages built from the same template (/sport/football/teams/{slug}) — so this is most likely one template fix affecting up to 4 pages, not 1.

    Aston Villa FC - Transfer news, results, fixtures, video and
       https://www.bbc.co.uk/sport/football/teams/aston-villa
       https://www.bbc.co.uk/sport/football/teams/arsenal
    1 affected URL

    Decide which page owns the subject. Merge the weaker one into it and redirect, or narrow each to a genuinely different question.

  • Every page is linked from anothermedium

    1 crawled page(s) are not linked from any other page we fetched. A page reachable only from a sitemap receives no internal authority at all, and is crawled rarely — it can rank, but it starts from nothing and stays there.

    bbc.co.uk/sport/articles/c72pkn599xwo
    1 affected URL

    Link them from a relevant hub page or from navigation, using the subject as the link text.

  • No phrase is repeated unnaturallymedium

    1 phrase(s) make up more than 5% of a page's own words. Repetition at that level reads badly to a person and has not helped rankings in over a decade — it is now a signal in the wrong direction. Every page of this type that was checked has this fault, and your sitemap lists 8 pages built from the same template (/sport/football/{slug}) — so this is most likely one template fix affecting up to 8 pages, not 1.

    "bst august" is 10% of the page
       https://www.bbc.co.uk/sport/football/world-cup
    1 affected URL

    Write the phrase once where it belongs and use natural variations elsewhere.

  • Page titles are unique

    All 12 crawled pages have distinct titles.

  • Pages have enough content

    All 12 crawled pages carry substantial content.

  • Every page has a meta description

    1 of 12 crawled pages have no meta description.

    1 affected URL
  • Images have alt text

    0 of 590 images across the crawl have no alt attribute. Alt text is how search engines read images and how screen readers describe them.

  • Navigation is present on every page

    Every crawled page carries at least three internal links, so navigation is consistently rendered.

  • Pages are meaningfully different from each other

    No two crawled pages share substantially the same text.

  • No broken internal pages

    All 12 crawled pages returned successfully.

  • Pages carry more than their template

    Across 12 page(s), the median page is 76% its own content and the rest navigation, footer and legal text.

  • Missing pages return a real 404

    No page answers 200 while telling the visitor nothing was found.

  • Pages deliver what their titles promise

    Every page's body covers the subject its title and heading announce.

  • Meta descriptions are unique

    All 11 descriptions found are distinct.

  • Content identifies who wrote it

    Authorship is declared.

  • Links describe where they go

    7 of 2066 internal link(s) use text like 'click here' or no text at all.

  • There is a route to who you are

    An about or contact page is linked.

  • Content carries recent dates

    4 of 12 crawled pages declare a date; the most recent is 2026-10-21.

  • The writing is readable

    Median reading ease is 64.1 — readable.

  • One H1 per page

    0 of 12 pages do not have exactly one H1 heading.

  • No long redirect chains

    No multi-step redirects found.

  • Sitemap matches the real site

    Sitemap lists 18011 URLs; we reached 12 by crawling. 18005 sitemap URLs were not linked from the pages we visited.

  • No dead-end pages

    Every crawled page links onward.

  • Internal authority is spread, not pooled

    Pages receive 5.5 internal links on average across the crawl, with no single page absorbing most of them.

  • A publisher is declared in structured data

    Publisher is declared in structured data.

  • Where internal authority goes

    Internal links concentrate authority on the pages below, in order. This is the site's own ranking of itself, derived from how it links — read it against what the business actually sells, because search engines read it the same way. Only the crawled sample is modelled, so this describes the navigation rather than every page.

  • What each page is about

    The terms that distinguish each page from the others on this site — not the most frequent words, but the ones this page uses and the others do not. Read them as what a search engine would take the page to be about, and check that it matches what it is for.

Local business signals

What Google needs to place you in map results.

0 passed · 0 failed · 1 skipped
100%
  • Local business signals

    Not applicable — nothing on this site indicates a physical location customers visit: no address, phone link, opening hours, map or local business markup. Local search checks are skipped and do not affect the score. If you do serve customers from premises, publishing an address and phone number is the place to start.

Infrastructure

DNS, hosting and delivery configuration.

11 passed · 4 failed · 4 skipped
72%
  • No lookalike domain can send mail as your brandhigh

    We generated and checked 31 plausible misspellings and variants of your domain. 9 of the 15 registered variants has mail servers configured, so it is technically able to send email that reads as yours to anyone skimming a sender address. Many such domains are entirely unrelated businesses that happen to have a similar name — this is a risk to be aware of and to defend against, not evidence that anyone is doing anything.

    b-bc.co.uk   [mail configured]
    bb.co.uk   [mail configured]
    bbc.co   [mail configured]
    bbc.net   [mail configured]
    bbcc.co.uk   [mail configured]
    bcb.co.uk   [mail configured]
    bvc.co.uk   [mail configured]
    gbc.co.uk   [mail configured]
    (1 further variant(s) resolve to your own infrastructure and are excluded — those are yours.)

    Publish DMARC at enforcement so mail claiming to be your domain is rejected outright — that is the defence that works regardless of who owns a lookalike. Then register the closest unregistered variants; they cost a few pounds a year and are the cheapest brand protection available.

  • Certificate is not shared with unrelated domainsmedium

    The certificate served for your site also covers 9 unrelated domain(s). That is characteristic of low-cost shared hosting: you share an address and a reputation with strangers, and their behaviour is visible to anyone who looks at your certificate.

    account.bbc.com, bbc.com, bbcrussian.com, news.bbcimg.co.uk, node1.bbcimg.co.uk, r.bbci.co.uk

    Move to a certificate that covers only your own domains — with Let's Encrypt this costs nothing.

  • Sitemap lastmod dates are meaningfulmedium

    Only 0 of 18011 sitemap URL(s) declare a lastmod. It is the signal Google uses to decide what to recrawl first, so without it updates are found late.

    []; []

    Emit lastmod from the date the page content actually changed, not from the time the sitemap was generated.

  • DNSSEC enabledlow

    DNSSEC is not enabled, so DNS answers for your domain can't be cryptographically verified.

    Enable DNSSEC at your DNS provider.

  • Mail server IP is not blacklisted

    Not checked: the blocklists declined queries from this resolver, so reputation could not be confirmed either way. This is excluded from your score rather than guessed at.

  • Certificate history reviewed

    Not measured — the certificate transparency log was unavailable (returned 502).

  • Server log analysis

    Not measured — no log file supplied. Server logs are the only source that shows what Googlebot actually fetched rather than what it could fetch: which pages it spends its crawl on, which it has never asked for, and what it receives when it does.

  • Whole-site analysis

    Not measured — no whole-site crawl has been run for this domain. The audit above reasons from a sample of pages chosen to cover each template, which describes how the site is built. It cannot say how many of the site's pages are indexable, which templates are thin across every instance, or what sits too deep to be crawled — those are counts, and a sample cannot produce one.

  • Redundant nameservers

    8 nameserver(s) configured.

  • No subdomain can be taken over

    Checked 0 subdomain(s); none point at a cloud service that has released them.

  • No unbounded URL spaces

    No filter, session or calendar URLs that would generate an unbounded space were found.

  • Pages are reached without redirect chains

    Every page was reached directly or in a single hop.

  • Crawled URLs return content

    0 of 12 URL(s) followed during this crawl returned a redirect or an error (0%).

  • Sitemap files are within Google's limits

    Every sitemap file is within the 50,000 URL and 50 MB limits.

  • Internal links pass authority

    0 internal link(s) are marked nofollow.

  • CAA record restricts certificate issuance

    CAA record present.

  • Software versions are not disclosed

    No version numbers advertised in response headers.

  • Hosting network identified

    Served from AS54113 (FASTLY - Fastly, Inc.), announced in 151.101.0.0/22 — a block of 1,024 addresses.

  • What this audit examined

    12 page(s) were examined, chosen to cover 11 of the 18099 distinct page templates found across 18011 known URLs. Pages are sampled by template rather than in sitemap order, because the first pages of a sitemap are usually all the same kind — a sample of one template would describe that template rather than the site. Findings below therefore apply to the templates listed, and a fault in a template is normally a fault on every page built from it.

Off-page authority

Who links to this site, with what text, and how that compares.

0 passed · 0 failed · 1 skipped
100%
  • Off-page profile

    Not measured — off-page data is not configured on this instance.

What Google's renderer sees

The site loaded in a real browser, the way a visitor and a crawler get it.

3 passed · 5 failed
49%
  • JavaScript does not rewrite indexing directivescritical

    JavaScript changes the directives Google acts on after the page loads. The served HTML looks correct to anyone reading the source, and Google indexes what rendering produced — so a canonical or noindex injected at runtime silently overrides everything the server said.

    canonical: served 'https://www.bbc.co.uk/', rendered 'https://www.bbc.com'
    robots: served 'max-image-preview:large', rendered 'noodp, noydir'

    Emit the final canonical and robots directives server-side. Nothing that decides indexing should depend on a script running.

  • No JavaScript errors on loadmedium

    12 JavaScript error(s) fire when the page loads. Broken scripts commonly break booking forms, menus and tracking without anything looking wrong.

    [JavaScript Error: "Cookie “” has been rejected for invalid characters in the name." {file: "https://www.bbc.co.uk/" line: 0}]
    [JavaScript Error: "Cookie “” has been rejected for invalid characters in the name." {file: "https://www.bbc.co.uk/" line: 0}]
    [JavaScript Error: "Cookie “” has been rejected for invalid characters in the name." {file: "https://www.bbc.co.uk/" line: 0}]
    [JavaScript Error: "Cookie “” has been rejected for invalid characters in the name." {file: "https://www.bbc.co.uk/" line: 0}]
    [JavaScript Error: "Cookie “” has been rejected for invalid characters in the name." {file: "https://www.bbc.co.uk/" line: 0}]

    Open your browser's console on the live site and fix what it reports.

  • All page resources load successfullymedium

    1 resource(s) failed to load. Missing images and stylesheets are visible to customers; missing scripts break features.

    https://cdn.optimizely.com/public/4621041136/s/bbcx_prod.js (failed)
    1 affected URL

    Fix or remove these URLs.

  • Title is the same before and after JavaScriptmedium

    JavaScript rewrites the page title after load. Google usually indexes the served title, so the one you see in the browser may not be the one shown in search results.

    served:   BBC - Home
    rendered: BBC Home - Breaking News, World News, US News, Sports, Business, Innovation, Climate, Culture, Travel, Video &

    Set the final title server-side rather than changing it in script.

  • The title survives renderingmedium

    The title tag changes after JavaScript runs. Google usually indexes the rendered title, but rendering is queued separately and can lag the first crawl, so for a while the served title is what appears in results.

    served:   BBC - Home
    rendered: BBC Home - Breaking News, World News, US News, Sports, Business, Innovation, Climate, Cult

    Render the final title server-side.

  • Content is in the HTML, not built by JavaScript

    The served HTML contains 2075 words and the rendered page 2075 — the content is present before JavaScript runs.

  • The mobile page matches the desktop page

    What the server sends a phone matches what it sends a desktop browser.

  • Navigation links are crawlable without JavaScript

    182 links in the served HTML, 182 after rendering — navigation is discoverable.

Scan details

Final URLhttps://www.bbc.co.uk/
Host IPs151.101.0.81, 151.101.128.81, 151.101.192.81, 151.101.64.81, 2a04:4e42:200::81, 2a04:4e42:400::81, 2a04:4e42:600::81, 2a04:4e42::81
Pages crawled12 of 12 attempted
Sitemap URLs18011
Nameserversddns0.bbc.co.uk, ddns0.bbc.com, ddns1.bbc.co.uk, ddns1.bbc.com, dns0.bbc.co.uk, dns0.bbc.com, dns1.bbc.co.uk, dns1.bbc.com
Mail serverscluster1.eu.messagelabs.com, cluster1a.eu.messagelabs.com
DKIM selectorsnone found
Mail server IPs85.158.142.217, 85.158.142.213, 195.245.231.67
TLSTLSv1.3 · TLS_AES_128_GCM_SHA256 · issued by GlobalSign nv-sa
Detected stackcustom / Fastly / other-dns · Meta Pixel
Browser renderCamoufox (stealth Firefox) · 5.9s · 2075 words, 182 links after JavaScript
12 URLs crawled
  • https://www.bbc.co.uk/
  • https://www.bbc.co.uk/accessibility
  • https://www.bbc.co.uk/sounds/play/m0030cfh
  • https://www.bbc.co.uk/sport
  • https://www.bbc.co.uk/sport/football
  • https://www.bbc.co.uk/sport/football/teams/aston-villa
  • https://www.bbc.co.uk/sport/football/world-cup
  • https://www.bbc.co.uk/aboutthebbc
  • https://www.bbc.co.uk/sport/articles/c72pkn599xwo
  • https://www.bbc.co.uk/sport/football/teams/arsenal
  • https://www.bbc.co.uk/aboutthebbc/governance/mission
  • https://www.bbc.co.uk/sport/tennis

Want these fixed?

BounceZero Ltd does this work: technical remediation, local SEO and email deliverability. Tell us what you want fixed and we'll reply with what it takes. No call required, no obligation.

We only email you about this request. No list, no newsletter.

Watch this site

We re-audit on a schedule and email you only when a check that was passing starts failing. That is usually a recent change to the site or its DNS, and it is findable while still fresh. No digest, no newsletter.

Monitoring means repeatedly fetching your site and emailing about it, so we ask you to prove you own bbc.co.uk first.