Your position
64th percentile of 28 sites audited. The average site scores 72, the median 67.
Website audit report
2 critical and 4 high-severity issues found across 127 checks.
Scanned 2026-08-17T21:28:46+00:00 · 2 host IPs · cert expires in 64 days
This report is not offered to search engines. It is reachable by link only. If you own mozilla.org you can publish or delete it.
Measured against every site SEOking has audited: a corpus that grows with each scan and cannot be reconstructed after the fact.
64th percentile of 28 sites audited. The average site scores 72, the median 67.
JavaScript does not rewrite indexing directives
100% of the sites we have audited get this right and yours does not. Of everything on this report, it is the fault that most sets you apart from your competition, which makes it the first thing worth fixing.
Our own measure of whether your domain is trusted by the systems that decide if mail reaches an inbox. No other website audit reports this. It is built from BounceZero's deliverability platform.
Your domain is configured the way the top tier of senders are.
We have measured deliverability across 210,156 domains. Yours is not among them, which simply means no one has needed to verify an address at it. The score above is from live measurements of your own DNS.
For context, 2.2% of the domains we have measured accept mail to any address, which makes their bounce behaviour unpredictable.
Loaded in a real browser at phone size. This is close to what a visitor and Google's renderer see.

The 30 faults on this report come from 15 underlying causes. Fixing a cause fixes everything under it, so this is ordered by score returned per unit of work, not by severity alone.
The 7 quickest steps here take you from 76 to about 84. That is 8 points for changes measured in minutes and hours, not weeks.
Translated pages that are not correctly linked to each other are not treated as translations. They compete with each other for the same rankings, and visitors are shown the wrong language.
Fixes 2 findings: Language links point both ways · Each page lists itself
A canonical or noindex injected at runtime silently overrides what the server said, and the served HTML still looks correct to anyone reading the source.
Fixes 3 findings: JavaScript does not rewrite indexing directives · Content is readable without running JavaScript · The title survives rendering
These do not share a root cause with anything else on the report.
Fixes 4 findings: Title is the same before and after JavaScript · Pages carry more than their template · Pages deliver what their titles promise · The writing is readable
These decide whether your pages can appear at all. Nothing else on this report matters until they are right.
Fixes 2 findings: XML sitemap published · Homepage canonical is correct
A subdomain pointing at a service that released it can be claimed by anyone, who then publishes on your domain. Deleting the record costs nothing and closes it immediately.
Fixes 1 finding: No lookalike domain can send mail as your brand
Your title and description are the advert Google runs for you, free, every time someone searches.
Fixes 4 findings: Page titles are unique · Meta descriptions are unique · Structured data present · One H1 per page
Rich results — ratings, prices, FAQs, breadcrumbs — are what turn a listing into an advert, and they are decided by whether a few required properties are present. Markup that is invalid or incomplete is work already done that currently earns nothing.
Fixes 3 findings: The business is identified in structured data · Breadcrumbs are marked up · Site-wide search is declared
Internal links decide which of your pages search engines treat as important, and the decision is usually an accident of navigation design. It costs nothing to change and it changes what ranks.
Fixes 3 findings: Every page is linked from another · Each page covers a distinct subject · Internal authority is spread, not pooled
These are all records in your DNS. One editing session fixes every one of them, and it is the change most likely to stop your mail being filtered.
Fixes 2 findings: MTA-STS policy published · TLS reporting enabled
Google indexes the mobile version of your site, and these are measured in a real phone-sized browser rather than inferred. A page that scrolls sideways or needs pinching to read loses the visitor before the content matters.
Fixes 1 finding: Tap targets are big enough to hit
Depth decides how much authority reaches a page and how often it is recrawled; parameters and capitals manufacture duplicate URLs that compete with the originals.
Fixes 1 finding: URLs are readable
A growing share of questions are answered without a results page. Being quotable is a distribution channel, and it is usually blocked by a plugin default rather than a decision.
Fixes 1 finding: A curated summary is published for assistants
Google's guidance asks who produced a page and why they should be trusted. For advice, health, legal or financial topics an anonymous, undated page competes badly against a named one.
Fixes 1 finding: A publisher is declared in structured data
Resilience and reputation work — lower urgency, but cheap while you are already in these systems.
Fixes 1 finding: DNSSEC enabled
Images are what Largest Contentful Paint usually measures, and WebP is typically a third smaller than the same JPEG. On image-led pages this is the largest saving available.
Fixes 1 finding: Images are sized for the device
Ranked by severity, then by how much score each returns.
17 hreflang reference(s) are not returned. Page A names page B as its translation, but B does not name A back. Google requires the reference to be mutual and discards the entire set when it is not — so the translations compete with each other instead of being recognised as versions of one page. This is the most common hreflang fault and it fails silently.
https://www.mozilla.org/ → names https://www.mozilla.org/en-US/, which does not name it back https://www.mozilla.org/ast/ → names https://www.mozilla.org/ar/, which does not name it back https://www.mozilla.org/ast/ → names https://www.mozilla.org/be/, which does not name it back https://www.mozilla.org/ast/ → names https://www.mozilla.org/bg/, which does not name it back
How to fix: Every page in a language set must list every other page in that set, including itself. The simplest correct implementation emits the same block of links on all of them.
JavaScript changes the directives Google acts on after the page loads. The served HTML looks correct to anyone reading the source, and Google indexes what rendering produced — so a canonical or noindex injected at runtime silently overrides everything the server said.
canonical is added only by JavaScript ('https://www.mozilla.org/en-US/')How to fix: Emit the final canonical and robots directives server-side. Nothing that decides indexing should depend on a script running.
We generated and checked 55 plausible misspellings and variants of your domain. 6 of the 13 registered variants has mail servers configured, so it is technically able to send email that reads as yours to anyone skimming a sender address. Many such domains are entirely unrelated businesses that happen to have a similar name — this is a risk to be aware of and to defend against, not evidence that anyone is doing anything.
mozill.org [mail configured] mozilla.online [mail configured] mozilla.shop [mail configured] mozillla.org [mail configured] nozilla.org [mail configured] ozilla.org [mail configured] m0zilla.org mizilla.org (1 further variant(s) resolve to your own infrastructure and are excluded — those are yours.)
How to fix: Publish DMARC at enforcement so mail claiming to be your domain is rejected outright — that is the defence that works regardless of who owns a lookalike. Then register the closest unregistered variants; they cost a few pounds a year and are the cheapest brand protection available.
3 pages share 1 duplicated title(s). Google treats near-identical pages as competing with each other, and usually indexes only one.
3× Mozilla - Internet for people, not profit (US)
How to fix: Give every page a title describing that page specifically.
2 page(s) declare hreflang for their translations but do not list themselves. A set without a self-reference is ignored, so none of the annotations on those pages currently does anything.
https://www.mozilla.org/ast/ https://www.mozilla.org/cak/
How to fix: Include a self-referencing hreflang on every page in the set.
Whether the connection, certificate and headers hold up.
Secure connection working.
Plain HTTP requests are redirected to the secure version.
All resources load securely.
Certificate valid for another 64 days (expires 2026-10-21).
Negotiated TLSv1.3.
HSTS is set.
Content Security Policy is set.
MIME sniffing protection is set.
Clickjacking protection is set.
Referrer policy is set.
Whether your mail reaches inboxes or spam folders.
No MTA-STS policy, so mail to you can be delivered unencrypted if an attacker strips TLS.
Publish an MTA-STS policy and the _mta-sts TXT record.
No TLS-RPT record, so delivery-encryption failures go unreported.
Publish a _smtp._tls TXT record with a reporting address.
DKIM keys published on selector(s): google.
4 mail server(s) configured.
Ends in ~all (soft fail) — the usual safe setting.
The record forces about 4 DNS lookups. Comfortably within the limit of 10.
Aggregate reports are being sent to a reporting address.
One SPF record, as required.
DMARC policy is p=reject.
BIMI record present — your logo can appear beside your emails.
How fast real visitors experience the site.
53 of 236 image(s) provide a srcset. Without one, a phone downloads the full desktop image and then scales it down — paying for pixels it never shows.
Add srcset and sizes so each device downloads an appropriate image.
Not available: PageSpeed API returned 429. This usually means the site does not yet have enough Chrome traffic for Google to report field data. Lab measurements below still apply.
Served with gzip compression.
Median response across 12 page(s) was 514 ms.
Homepage HTML is 47 KB.
12 of 12 images declare dimensions.
12 external script file(s) on the homepage.
Pages may be cached by browsers and CDNs.
All 84 image(s) are JPEG or PNG, with no WebP or AVIF alternative. WebP is typically 25-35% smaller at the same quality and is supported by every current browser — on image-led pages this is usually the single largest saving available, and images are what Largest Contentful Paint measures.
10 of 12 images use lazy loading.
The tags, files and signals search engines read first.
17 hreflang reference(s) are not returned. Page A names page B as its translation, but B does not name A back. Google requires the reference to be mutual and discards the entire set when it is not — so the translations compete with each other instead of being recognised as versions of one page. This is the most common hreflang fault and it fails silently.
https://www.mozilla.org/ → names https://www.mozilla.org/en-US/, which does not name it back https://www.mozilla.org/ast/ → names https://www.mozilla.org/ar/, which does not name it back https://www.mozilla.org/ast/ → names https://www.mozilla.org/be/, which does not name it back https://www.mozilla.org/ast/ → names https://www.mozilla.org/bg/, which does not name it back
Every page in a language set must list every other page in that set, including itself. The simplest correct implementation emits the same block of links on all of them.
2 page(s) declare hreflang for their translations but do not list themselves. A set without a self-reference is ignored, so none of the annotations on those pages currently does anything.
https://www.mozilla.org/ast/ https://www.mozilla.org/cak/
Include a self-referencing hreflang on every page in the set.
The served HTML carries 324 words against 1,605 after JavaScript runs. Search engines render pages eventually; assistant crawlers generally do not — they fetch the HTML and read what is there. A page whose content only appears after scripts run is close to empty to them, so it cannot be quoted or cited however good the content is.
served 324 words → rendered 1,605
Render the main content server-side. This is the same fix as the js_content finding and it pays twice.
No XML sitemap. Google has to discover your pages by following links, which means deeper pages may never be crawled.
0 URLs · not referenced in robots.txt
Publish sitemap.xml and reference it from robots.txt.
No Organization markup. This is what Google assembles a knowledge panel from — the box with your logo, name and links that appears beside branded searches — and what connects your site to your social profiles. Without it Google infers your identity from third parties instead of from you.
Add Organization JSON-LD with name, url, logo and sameAs links to your social profiles.
No canonical tag, so duplicate URLs of the same page can compete.
Set a self-referencing canonical on every page.
No structured data. Google is reading your page as plain text and cannot qualify you for any rich result.
Add JSON-LD for Organization and your primary content type.
No BreadcrumbList markup. Google replaces the raw URL in your listing with a readable breadcrumb trail when this is present, which is more legible and measurably more clickable — and it is one of the cheapest rich results to earn.
Add BreadcrumbList JSON-LD to every page below the homepage.
3 URL(s) contain capitals, spaces, underscores or a file extension. Google treats /Page and /page as different URLs, so capitals invite duplicates, and underscores are not read as word separators the way hyphens are.
https://www.mozilla.org/en-US/ https://www.mozilla.org/en-US/ https://www.mozilla.org/en-US/
Use lowercase words separated by hyphens, with no file extension. Redirect the old URLs to the new ones.
No WebSite markup. With a SearchAction it can give you a search box directly inside your Google listing for branded queries.
Add WebSite JSON-LD, with potentialAction/SearchAction if the site has its own search.
No /llms.txt. It is a short, plain-text map of what a site is and which pages matter — a convention some assistants read to decide what to quote, and cheap to publish. It is not yet a standard anyone is obliged to honour, so treat it as a low-cost bet rather than a requirement.
Publish /llms.txt: a heading, one paragraph describing the business, and a linked list of your most important pages.
Not measured — not configured on this instance. Connecting Search Console adds what no crawl can see: the queries this site already appears for, where it ranks, and how many people click. It is read-only and can be disconnected at any time.
Not measured — ranking data is not configured on this instance.
Homepage is open to indexing.
Mobile viewport is declared.
Title is 48 characters.
Description is 134 characters.
robots.txt present and open to search engines.
Every canonical points at a page that is allowed to be indexed.
Canonical targets all return 200.
All structured data blocks are valid JSON.
No page relies on a directive Google is blocked from reading.
Every hreflang value is a valid language or language-region code.
Every marked-up entity carries the properties Google requires.
10 of 10 crawled page(s) (100%) can actually be indexed.
Every hreflang target is a live, indexable page.
No canonical points at a page that then canonicals somewhere else.
Every major assistant is allowed to read and cite these pages.
Every crawled page sits within four levels of the homepage (deepest: 1).
7 Open Graph tags found.
An x-default version is declared for visitors whose language matches none of your versions.
0 of 12 crawled URLs carry query parameters other than tracking tags.
Language attribute present.
3 twitter: tag(s) found.
No model-training crawler is blocked, so this content may be used to train future models. This is a business decision rather than an SEO one, and it is separate from being cited in answers: refusing training does not remove you from AI results, and allowing it does not put you in them.
Whether pages are unique, linked and crawlable.
3 pages share 1 duplicated title(s). Google treats near-identical pages as competing with each other, and usually indexes only one.
3× Mozilla - Internet for people, not profit (US)
Give every page a title describing that page specifically.
Across 10 page(s), the median page is 65% its own content and the rest navigation, footer and legal text. 3 page(s) carry under 120 words of their own, or less than a third. A word count that includes the template hides this — those pages look substantial and read as empty, which is what a search engine comparing them to a competitor sees.
76 own / 260 total (29%) https://www.mozilla.org/be/ 69 own / 211 total (33%) https://www.mozilla.org/ar/ 98 own / 296 total (33%) https://www.mozilla.org/ 812 own / 1259 total (64%) https://www.mozilla.org/ast/ 960 own / 1479 total (65%) https://www.mozilla.org/en-US/ 913 own / 1402 total (65%) https://www.mozilla.org/ca/
Add substance to the page body rather than the template — for product pages, specifics nobody else has; for category pages, an explanation of what the category is for.
6 pair(s) of pages appear to cover the same subject, judged from their titles and headings. Two pages competing for one query split the links and relevance that should accumulate on one, and Google alternates between them — so neither settles into a stable position. Confirm against Search Console, which shows exactly which page it chooses.
Mozilla - Internet for people, not profit (US) https://www.mozilla.org/en-US/ https://www.mozilla.org/en-US/ Mozilla - Internet for people, not profit (US) https://www.mozilla.org/en-US/ https://www.mozilla.org/en-US/ Mozilla - Internet for people, not profit (US) https://www.mozilla.org/en-US/ https://www.mozilla.org/en-US/ Internet for people, not profit — Mozilla Global https://www.mozilla.org/ https://www.mozilla.org/en-US/
Decide which page owns the subject. Merge the weaker one into it and redirect, or narrow each to a genuinely different question.
2 page(s) have a title and heading whose subject barely appears in the body. Either the title is written for a query the page does not answer — which loses the visitor on arrival and is measurable as a bounce — or the page is about something its title does not say.
20% of the title's subject in the body Internet for people, not profit — Mozilla Global https://www.mozilla.org/ 29% of the title's subject in the body Internet pa la xente, non pal porgüeyu — Mozilla https://www.mozilla.org/ast/
Make the opening paragraph answer the title directly, or change the title to what the page is really about.
3 pages share 1 duplicated meta description(s). A description is the advert for that specific page; repeating one across a site means Google usually discards it and writes its own from the page text, so you lose control of what searchers read before deciding whether to click.
We’re working to put control of the internet back in the hands of the people using it.… used on 3 pages
Write one description per page, describing what is on that page.
1 crawled page(s) are not linked from any other page we fetched. A page reachable only from a sitemap receives no internal authority at all, and is crawled rarely — it can rank, but it starts from nothing and stays there.
mozilla.org/
Link them from a relevant hub page or from navigation, using the subject as the link text.
Median reading ease is 40.8 — difficult. 3 page(s) score below 40, which is the range of academic and legal writing. That is correct for a terms page and costly on anything meant to sell, because the reader who bounces was the one who arrived.
8.0 (very difficult) https://www.mozilla.org/bs/ 25.9 (very difficult) https://www.mozilla.org/cak/ 33.2 (difficult) https://www.mozilla.org/ca/ 40.8 (difficult) https://www.mozilla.org/ast/ 43.8 (difficult) https://www.mozilla.org/bg/
Shorter sentences and plainer words in the pages that convert. Legal pages can stay as they are.
4 of 12 pages do not have exactly one H1 heading.
Use a single H1 per page stating what the page is about.
One page receives more than half of all internal links found. That concentrates authority in one place while the rest of the site is starved of it.
Link deliberately to the pages you want to rank, not only to the same one from every template.
No publisher in your structured data. It ties each page back to the organisation that stands behind it, which is what carries trust from your brand to an individual article.
Add a publisher property naming your Organization, with its logo.
Not measured — no page declares a publication or modification date, so how recently the site was maintained cannot be determined. That is normal for a brochure site and worth fixing for anything article-based.
All 10 crawled pages are reachable by internal links.
All 12 crawled pages carry substantial content.
0 of 12 crawled pages have no meta description.
0 of 236 images across the crawl have no alt attribute. Alt text is how search engines read images and how screen readers describe them.
Every crawled page carries at least three internal links, so navigation is consistently rendered.
No two crawled pages share substantially the same text.
All 12 crawled pages returned successfully.
No page answers 200 while telling the visitor nothing was found.
1 link(s) appear on nearly every page — the site-wide navigation, which is where most internal authority is allocated.
Authorship is declared.
0 of 1069 internal link(s) use text like 'click here' or no text at all.
No phrase dominates a page's text.
An about or contact page is linked.
No multi-step redirects found.
Every crawled page links onward.
Internal links concentrate authority on the pages below, in order. This is the site's own ranking of itself, derived from how it links — read it against what the business actually sells, because search engines read it the same way. Only the crawled sample is modelled, so this describes the navigation rather than every page.
The terms that distinguish each page from the others on this site — not the most frequent words, but the ones this page uses and the others do not. Read them as what a search engine would take the page to be about, and check that it matches what it is for.
What Google needs to place you in map results.
Not applicable — nothing on this site indicates a physical location customers visit: no address, phone link, opening hours, map or local business markup. Local search checks are skipped and do not affect the score. If you do serve customers from premises, publishing an address and phone number is the place to start.
DNS, hosting and delivery configuration.
We generated and checked 55 plausible misspellings and variants of your domain. 6 of the 13 registered variants has mail servers configured, so it is technically able to send email that reads as yours to anyone skimming a sender address. Many such domains are entirely unrelated businesses that happen to have a similar name — this is a risk to be aware of and to defend against, not evidence that anyone is doing anything.
mozill.org [mail configured] mozilla.online [mail configured] mozilla.shop [mail configured] mozillla.org [mail configured] nozilla.org [mail configured] ozilla.org [mail configured] m0zilla.org mizilla.org (1 further variant(s) resolve to your own infrastructure and are excluded — those are yours.)
Publish DMARC at enforcement so mail claiming to be your domain is rejected outright — that is the defence that works regardless of who owns a lookalike. Then register the closest unregistered variants; they cost a few pounds a year and are the cheapest brand protection available.
DNSSEC is not enabled, so DNS answers for your domain can't be cryptographically verified.
Enable DNSSEC at your DNS provider.
Not checked: the blocklists declined queries from this resolver, so reputation could not be confirmed either way. This is excluded from your score rather than guessed at.
Not measured — the certificate transparency log was unavailable (returned 502).
Not measured — no log file supplied. Server logs are the only source that shows what Googlebot actually fetched rather than what it could fetch: which pages it spends its crawl on, which it has never asked for, and what it receives when it does.
Not measured — no whole-site crawl has been run for this domain. The audit above reasons from a sample of pages chosen to cover each template, which describes how the site is built. It cannot say how many of the site's pages are indexable, which templates are thin across every instance, or what sits too deep to be crawled — those are counts, and a sample cannot produce one.
4 nameserver(s) configured.
Checked 0 subdomain(s); none point at a cloud service that has released them.
No filter, session or calendar URLs that would generate an unbounded space were found.
Every page was reached directly or in a single hop.
0 of 12 URL(s) followed during this crawl returned a redirect or an error (0%).
Your certificate covers only your own domain.
0 internal link(s) are marked nofollow.
CAA record present.
No version numbers advertised in response headers.
Served from AS396982 (GOOGLE-CLOUD-PLATFORM - Google LLC), announced in 2600:1901::/32 — a block of 79,228,162,514,264,337,593,543,950,336 addresses.
12 page(s) were examined, chosen to cover 11 of the 80 distinct page templates found across 12 known URLs. Pages are sampled by template rather than in sitemap order, because the first pages of a sitemap are usually all the same kind — a sample of one template would describe that template rather than the site. Findings below therefore apply to the templates listed, and a fault in a template is normally a fault on every page built from it.
Who links to this site, with what text, and how that compares.
Not measured — off-page data is not configured on this instance.
The site loaded in a real browser, the way a visitor and a crawler get it.
JavaScript changes the directives Google acts on after the page loads. The served HTML looks correct to anyone reading the source, and Google indexes what rendering produced — so a canonical or noindex injected at runtime silently overrides everything the server said.
canonical is added only by JavaScript ('https://www.mozilla.org/en-US/')Emit the final canonical and robots directives server-side. Nothing that decides indexing should depend on a script running.
51 of 70 tappable element(s) are smaller than 48x48 pixels, and 25 sit closer than 8 pixels to a neighbour. On a phone that means links and buttons that are hard to hit without zooming, and mis-taps on a checkout or contact button cost conversions directly.
Menu (44x32) A (113x36) Pause animation (136x32) Learn about us (128x22) Explore our products (181x22)
Give tappable elements at least 48x48 CSS pixels and 8 pixels of spacing — usually padding on the link rather than a bigger font.
JavaScript rewrites the page title after load. Google usually indexes the served title, so the one you see in the browser may not be the one shown in search results.
served: Internet for people, not profit — Mozilla Global rendered: Mozilla - Internet for people, not profit (US)
Set the final title server-side rather than changing it in script.
The title tag changes after JavaScript runs. Google usually indexes the rendered title, but rendering is queued separately and can lag the first crawl, so for a while the served title is what appears in results.
served: Internet for people, not profit — Mozilla Global rendered: Mozilla - Internet for people, not profit (US)
Render the final title server-side.
The served HTML contains 324 words and the rendered page 1605 — the content is present before JavaScript runs.
What the server sends a phone matches what it sends a desktop browser.
Measured 1.5s on a simulated phone viewport. Google's threshold for 'good' is 2.5s.
135 links in the served HTML, 89 after rendering — navigation is discoverable.
Cumulative Layout Shift measured at 0.000 (good is 0.1 or less).
The page loaded without JavaScript errors.
Every image, script and stylesheet loaded.
The page fits the mobile viewport with no sideways scrolling.
0 long JavaScript task(s) blocked the main thread while loading.
0 of 221 text block(s) render below 12px on a mobile viewport.
The page made 45 network requests to load.
| Final URL | https://www.mozilla.org/ |
|---|---|
| Host IPs | 2600:1901:0:c197::, 35.190.14.201 |
| Pages crawled | 12 of 12 attempted |
| Sitemap URLs | 0 |
| Nameservers | ns1-240.akam.net, ns4-64.akam.net, ns5-65.akam.net, ns7-66.akam.net |
| Mail servers | alt1.aspmx.l.google.com, alt2.aspmx.l.google.com, aspmx.l.google.com, aspmx3.googlemail.com |
| DKIM selectors | |
| Mail server IPs | 172.253.157.27, 142.250.102.27, 172.253.116.26 |
| TLS | TLSv1.3 · TLS_AES_256_GCM_SHA384 · issued by Google Trust Services |
| Detected stack | custom / Fastly / other-dns · mail on Google Workspace |
| Browser render | Camoufox (stealth Firefox) · 5.4s · 1605 words, 89 links after JavaScript |
BounceZero Ltd does this work: technical remediation, local SEO and email deliverability. Tell us what you want fixed and we'll reply with what it takes. No call required, no obligation.
We re-audit on a schedule and email you only when a check that was passing starts failing. That is usually a recent change to the site or its DNS, and it is findable while still fresh. No digest, no newsletter.
Monitoring means repeatedly fetching your site and emailing about it, so we ask you to prove you own mozilla.org first.