Fixed since last audit
- Server responds quickly
Website audit report
23 issues found across 137 checks. Nothing critical.
Scanned 2026-08-31T23:40:36+00:00 · 4 host IPs · cert expires in 48 days
This report is not offered to search engines. It is reachable by link only. If you own novadose.com you can publish or delete it.
Clear improvement — 1 check(s) fixed since the last audit. Score +2.
Measured against every site SEOking has audited: a corpus that grows with each scan and cannot be reconstructed after the fact.
79th percentile of 29 sites audited. The average site scores 72, the median 71.
Marked-up content qualifies for rich results
92% of the sites we have audited get this right and yours does not. Of everything on this report, it is the fault that most sets you apart from your competition, which makes it the first thing worth fixing.
Our own measure of whether your domain is trusted by the systems that decide if mail reaches an inbox. No other website audit reports this. It is built from BounceZero's deliverability platform.
Working, but with faults that measurably cost you inbox placement.
What is pulling it down: DMARC enforcement. See the email deliverability section below.
We have measured deliverability across 221,734 domains. Yours is not among them, which simply means no one has needed to verify an address at it. The score above is from live measurements of your own DNS.
For context, 3.5% of the domains we have measured accept mail to any address, which makes their bounce behaviour unpredictable.
Loaded in a real browser at phone size. This is close to what a visitor and Google's renderer see.

Oldest on the left. Every re-run is kept.
The 23 faults on this report come from 12 underlying causes. Fixing a cause fixes everything under it, so this is ordered by score returned per unit of work, not by severity alone.
The 5 quickest steps here take you from 84 to about 90. That is 6 points for changes measured in minutes and hours, not weeks.
These are all records in your DNS. One editing session fixes every one of them, and it is the change most likely to stop your mail being filtered.
Fixes 5 findings: DMARC policy is enforced · DMARC reports are collected · MTA-STS policy published · TLS reporting enabled · BIMI logo published
A subdomain pointing at a service that released it can be claimed by anyone, who then publishes on your domain. Deleting the record costs nothing and closes it immediately.
Fixes 1 finding: No lookalike domain can send mail as your brand
These do not share a root cause with anything else on the report.
Fixes 3 findings: Pages carry more than their template · The writing is readable · Every submitted page is reachable by a link
Rich results — ratings, prices, FAQs, breadcrumbs — are what turn a listing into an advert, and they are decided by whether a few required properties are present. Markup that is invalid or incomplete is work already done that currently earns nothing.
Fixes 2 findings: Marked-up content qualifies for rich results · Rendering preserves the structured data
A growing share of questions are answered without a results page. Being quotable is a distribution channel, and it is usually blocked by a plugin default rather than a decision.
Fixes 2 findings: AI assistants can cite this site · A curated summary is published for assistants
Internal links decide which of your pages search engines treat as important, and the decision is usually an accident of navigation design. It costs nothing to change and it changes what ranks.
Fixes 2 findings: Navigation promotes pages that earn money · Each page covers a distinct subject
Resilience and reputation work — lower urgency, but cheap while you are already in these systems.
Fixes 2 findings: All page resources load successfully · DNSSEC enabled
Google indexes the mobile version of your site, and these are measured in a real phone-sized browser rather than inferred. A page that scrolls sideways or needs pinching to read loses the visitor before the content matters.
Fixes 2 findings: Tap targets are big enough to hit · Body text is legible on a phone
Image and script weight drive every speed metric you are failing. This is the slowest fix here and the one with the longest tail.
Fixes 1 finding: Largest Contentful Paint under 2.5s (lab)
All set in the same place — your web server or CDN. Half of them are single lines.
Fixes 1 finding: Content Security Policy header
Your title and description are the advert Google runs for you, free, every time someone searches.
Fixes 1 finding: Every page has a meta description
Images are what Largest Contentful Paint usually measures, and WebP is typically a third smaller than the same JPEG. On image-led pages this is the largest saving available.
Fixes 1 finding: Images are sized for the device
Ranked by severity, then by how much score each returns.
DMARC policy is p=none. p=none monitors only — it instructs receivers to do nothing, so nobody is actually prevented from spoofing your domain.
v=DMARC1; p=none;
How to fix: Move to p=quarantine, then p=reject, once your reports are clean.
Measured 3.5s on a simulated phone viewport. Google's threshold for 'good' is 2.5s. This is the metric most likely to be costing you both rankings and visitors who leave before the page paints.
LCP 3496 ms · FCP 675 ms
How to fix: Compress and preload the largest above-the-fold image, and cache the HTML at the edge.
We generated and checked 60 plausible misspellings and variants of your domain. 1 of the 3 registered variants has mail servers configured, so it is technically able to send email that reads as yours to anyone skimming a sender address. Many such domains are entirely unrelated businesses that happen to have a similar name — this is a risk to be aware of and to defend against, not evidence that anyone is doing anything.
novadise.com [mail configured] novadoes.com novados.com
How to fix: Publish DMARC at enforcement so mail claiming to be your domain is rejected outright — that is the defence that works regardless of who owns a lookalike. Then register the closest unregistered variants; they cost a few pounds a year and are the cheapest brand protection available.
1 required propert(y/ies) are missing from your structured data. The markup exists but does not qualify for the rich result it is aiming at — which is the worst of both: the work has been done and earns nothing in the results page.
LocalBusiness is missing 'address'
How to fix: Add the missing properties. Google's Rich Results Test shows exactly which are required for each type.
Across 12 page(s), the median page is 35% its own content and the rest navigation, footer and legal text. 7 page(s) carry under 120 words of their own, or less than a third. A word count that includes the template hides this — those pages look substantial and read as empty, which is what a search engine comparing them to a competitor sees. Every page of this type that was checked has this fault, and your sitemap lists 2 pages built from the same template (/shop) — so this is most likely one template fix affecting up to 2 pages, not 1.
89 own / 722 total (12%) https://novadose.com/product-category/recovery/ 93 own / 726 total (13%) https://novadose.com/product-category/pens/ 97 own / 730 total (13%) https://novadose.com/product-category/longevity/ 101 own / 734 total (14%) https://novadose.com/shop/ 101 own / 734 total (14%) https://novadose.com/product-category/cartridges/ 143 own / 795 total (18%) https://novadose.com/product-category/metabolic/
How to fix: Add substance to the page body rather than the template — for product pages, specifics nobody else has; for category pages, an explanation of what the category is for.
Whether the connection, certificate and headers hold up.
Missing. Limits where scripts may load from, which is the main defence against injected code and card skimmers.
Add a Content-Security-Policy header, starting in report-only mode.
Secure connection working.
Plain HTTP requests are redirected to the secure version.
All resources load securely.
Cookies set Secure and HttpOnly.
Certificate valid for another 48 days (expires 2026-10-19).
Negotiated TLSv1.3.
HSTS is set.
MIME sniffing protection is set.
Clickjacking protection is set.
Referrer policy is set.
Whether your mail reaches inboxes or spam folders.
DMARC policy is p=none. p=none monitors only — it instructs receivers to do nothing, so nobody is actually prevented from spoofing your domain.
v=DMARC1; p=none;
Move to p=quarantine, then p=reject, once your reports are clean.
No rua= address, so DMARC failures are generated and then discarded. You have no visibility into who is sending as you.
v=DMARC1; p=none;
Add rua=mailto:dmarc@yourdomain to start collecting reports.
No MTA-STS policy, so mail to you can be delivered unencrypted if an attacker strips TLS.
Publish an MTA-STS policy and the _mta-sts TXT record.
No TLS-RPT record, so delivery-encryption failures go unreported.
Publish a _smtp._tls TXT record with a reporting address.
No BIMI record. With DMARC at enforcement you could display your logo next to your messages in Gmail and Apple Mail.
Once DMARC is at quarantine or reject, publish a BIMI record with an SVG logo.
DKIM keys published on selector(s): google, k2.
5 mail server(s) configured.
Ends in ~all (soft fail) — the usual safe setting.
The record forces about 1 DNS lookups. Comfortably within the limit of 10.
One SPF record, as required.
How fast real visitors experience the site.
0 of 175 image(s) provide a srcset. Without one, a phone downloads the full desktop image and then scales it down — paying for pixels it never shows.
Add srcset and sizes so each device downloads an appropriate image.
Not available: PageSpeed API returned 429. This usually means the site does not yet have enough Chrome traffic for Google to report field data. Lab measurements below still apply.
Served with gzip compression.
Median response across 12 page(s) was 163 ms.
Homepage HTML is 328 KB.
30 of 35 images declare dimensions.
13 external script file(s) on the homepage.
Pages may be cached by browsers and CDNs.
162 image(s) are served as WebP or AVIF.
35 of 35 images use lazy loading.
The tags, files and signals search engines read first.
1 required propert(y/ies) are missing from your structured data. The markup exists but does not qualify for the rich result it is aiming at — which is the worst of both: the work has been done and earns nothing in the results page.
LocalBusiness is missing 'address'
Add the missing properties. Google's Rich Results Test shows exactly which are required for each type.
2 assistant crawler(s) are blocked in robots.txt, so this site cannot be cited in the answers they write: Applebot-Extended, Google-Extended. These are the crawlers that fetch a page in order to reference it in a reply, which is a referral rather than a copy. Blocking them is a legitimate choice — but it is usually a plugin or CDN default rather than a decision anyone made.
Applebot-Extended — blocks Apple Intelligence Google-Extended — blocks Google AI Overviews and Gemini grounding
If you want to appear in AI answers, allow these agents in robots.txt. If the block is deliberate, no change is needed — but confirm it was deliberate.
1 structured data type(s) present in the served HTML are gone from the rendered page: LocalBusiness. Something on the page is removing or replacing the markup after load, and Google indexes the rendered result.
LocalBusiness
Find the script rewriting the head — usually a framework hydration step replacing server-rendered tags.
No /llms.txt. It is a short, plain-text map of what a site is and which pages matter — a convention some assistants read to decide what to quote, and cheap to publish. It is not yet a standard anyone is obliged to honour, so treat it as a low-cost bet rather than a requirement.
Publish /llms.txt: a heading, one paragraph describing the business, and a linked list of your most important pages.
Not applicable — this site publishes in a single language and declares no regional or translated versions, so hreflang annotations are not needed. Adding them to a single-language site does nothing.
Not measured — not configured on this instance. Connecting Search Console adds what no crawl can see: the queries this site already appears for, where it ranks, and how many people click. It is read-only and can be disconnected at any time.
Not measured — ranking data is not configured on this instance.
Homepage is open to indexing.
Mobile viewport is declared.
Title is 55 characters.
Sitemap found listing 32 URLs.
Description is 120 characters.
Canonical points at this page.
Structured data found: BreadcrumbList, CollectionPage, ImageObject, ListItem, Organization, WebPage, WebSite.
robots.txt present and open to search engines. 9 named crawler(s) are blocked, which is a deliberate choice rather than a fault.
Every canonical points at a page that is allowed to be indexed.
Canonical targets all return 200.
No page is both listed in the sitemap and marked noindex.
All structured data blocks are valid JSON.
No page relies on a directive Google is blocked from reading.
12 of 12 crawled page(s) (100%) can actually be indexed.
Identified as LocalBusiness, Organization.
Organization or Person markup names the business to assistants.
No canonical points at a page that then canonicals somewhere else.
Every sitemap URL is its own canonical.
All structured data is present in the HTML the server sends.
FAQPage or HowTo markup gives assistants a structured answer to cite.
BreadcrumbList markup is present.
Every crawled page sits within four levels of the homepage (deepest: 2).
sameAs links the entity to its real profiles across the web.
10 Open Graph tags found.
URLs use lowercase, hyphenated, extension-free paths.
0 of 12 crawled URLs carry query parameters other than tracking tags.
Language attribute present.
WebSite markup is present.
4 twitter: tag(s) found.
132 structured data object(s) across 12 page(s): Answer, Brand, BreadcrumbList, CollectionPage, FAQPage, ImageObject, ListItem, LocalBusiness, Offer, Organization, and others.
5 training crawler(s) blocked: Bytespider, CCBot, ClaudeBot, GPTBot, meta-externalagent. This is a business decision rather than an SEO one, and it is separate from being cited in answers: refusing training does not remove you from AI results, and allowing it does not put you in them.
Whether pages are unique, linked and crawlable.
Across 12 page(s), the median page is 35% its own content and the rest navigation, footer and legal text. 7 page(s) carry under 120 words of their own, or less than a third. A word count that includes the template hides this — those pages look substantial and read as empty, which is what a search engine comparing them to a competitor sees. Every page of this type that was checked has this fault, and your sitemap lists 2 pages built from the same template (/shop) — so this is most likely one template fix affecting up to 2 pages, not 1.
89 own / 722 total (12%) https://novadose.com/product-category/recovery/ 93 own / 726 total (13%) https://novadose.com/product-category/pens/ 97 own / 730 total (13%) https://novadose.com/product-category/longevity/ 101 own / 734 total (14%) https://novadose.com/shop/ 101 own / 734 total (14%) https://novadose.com/product-category/cartridges/ 143 own / 795 total (18%) https://novadose.com/product-category/metabolic/
Add substance to the page body rather than the template — for product pages, specifics nobody else has; for category pages, an explanation of what the category is for.
12 link(s) appear on nearly every page — the site-wide navigation, which is where most internal authority is allocated. 2 of them point at legal, account or administrative pages, and 1 of those sits among the eight best-linked pages on the site — level with, or above, the pages you sell from. Nobody decides this: a crawler counts every footer link as an endorsement repeated on every page, while visitors ignore footers. Those pages must exist and should not be among the best-linked things you publish.
novadose.com/ 4.0% novadose.com/shop 4.0% novadose.com/product-category/cartridges 4.0% novadose.com/lab-testing 4.0% novadose.com/shipping 4.0% novadose.com/faq 4.0% novadose.com/affiliate-program 4.0% novadose.com/contact 4.0%
4 pair(s) of pages appear to cover the same subject, judged from their titles and headings. Two pages competing for one query split the links and relevance that should accumulate on one, and Google alternates between them — so neither settles into a stable position. Confirm against Search Console, which shows exactly which page it chooses. Every page of this type that was checked has this fault, and your sitemap lists 2 pages built from the same template (/shop) — so this is most likely one template fix affecting up to 2 pages, not 1.
Shop Peptide Pens | NovaDose https://novadose.com/shop/ https://novadose.com/product-category/pens/ Metabolic Archives - NovaDose https://novadose.com/product-category/metabolic/ https://novadose.com/product-category/longevity/ Metabolic Archives - NovaDose https://novadose.com/product-category/metabolic/ https://novadose.com/product-category/recovery/ Longevity Archives - NovaDose https://novadose.com/product-category/longevity/ https://novadose.com/product-category/recovery/
Decide which page owns the subject. Merge the weaker one into it and redirect, or narrow each to a genuinely different question.
3 of 12 crawled pages have no meta description.
Write a description for each page, or generate one from its opening text.
Median reading ease is 37.7 — difficult. 5 page(s) score below 40, which is the range of academic and legal writing. That is correct for a terms page and costly on anything meant to sell, because the reader who bounces was the one who arrived.
9.2 (very difficult) https://novadose.com/product-category/metabolic/ 22.1 (very difficult) https://novadose.com/product/klow-80mg-pen/ 24.8 (very difficult) https://novadose.com/ 35.4 (difficult) https://novadose.com/product-category/cartridges/ 37.7 (difficult) https://novadose.com/privacy/
Shorter sentences and plainer words in the pages that convert. Legal pages can stay as they are.
All 12 crawled pages have distinct titles.
All 12 crawled pages are reachable by internal links.
All 12 crawled pages carry substantial content.
12 of 175 images across the crawl have no alt attribute. Alt text is how search engines read images and how screen readers describe them.
Every crawled page carries at least three internal links, so navigation is consistently rendered.
No two crawled pages share substantially the same text.
All 12 crawled pages returned successfully.
No template produces thin pages across all of its instances.
No page answers 200 while telling the visitor nothing was found.
Every page's body covers the subject its title and heading announce.
All 9 descriptions found are distinct.
Authorship is declared.
0 of 650 internal link(s) use text like 'click here' or no text at all.
Every crawled page is linked from at least one other page.
No phrase dominates a page's text.
An about or contact page is linked.
6 of 12 crawled pages declare a date; the most recent is 2026-08-26.
0 of 12 pages do not have exactly one H1 heading.
No multi-step redirects found.
Sitemap lists 31 URLs; we reached 12 by crawling. 19 sitemap URLs were not linked from the pages we visited.
Every crawled page links onward.
Pages receive 7.9 internal links on average across the crawl, with no single page absorbing most of them.
Publisher is declared in structured data.
Internal links concentrate authority on the pages below, in order. This is the site's own ranking of itself, derived from how it links — read it against what the business actually sells, because search engines read it the same way. Only the crawled sample is modelled, so this describes the navigation rather than every page.
The terms that distinguish each page from the others on this site — not the most frequent words, but the ones this page uses and the others do not. Read them as what a search engine would take the page to be about, and check that it matches what it is for.
What Google needs to place you in map results.
Not applicable — nothing on this site indicates a physical location customers visit: no address, phone link, opening hours, map or local business markup. Local search checks are skipped and do not affect the score. If you do serve customers from premises, publishing an address and phone number is the place to start.
DNS, hosting and delivery configuration.
We generated and checked 60 plausible misspellings and variants of your domain. 1 of the 3 registered variants has mail servers configured, so it is technically able to send email that reads as yours to anyone skimming a sender address. Many such domains are entirely unrelated businesses that happen to have a similar name — this is a risk to be aware of and to defend against, not evidence that anyone is doing anything.
novadise.com [mail configured] novadoes.com novados.com
Publish DMARC at enforcement so mail claiming to be your domain is rejected outright — that is the defence that works regardless of who owns a lookalike. Then register the closest unregistered variants; they cost a few pounds a year and are the cheapest brand protection available.
5 of 31 sitemap URL(s) were never reached by following links from the homepage. A sitemap makes a page known; links are what make it worth crawling and give it any authority at all. A page that exists only in the sitemap is one the site itself does not point at, which is the signal Google reads.
/product-category/longevity/ /product-category/metabolic/ /product-category/recovery/ /product-category/skin/ /product-category/wellness/
Link them from a relevant hub, or remove them from the sitemap if they are not meant to rank.
DNSSEC is not enabled, so DNS answers for your domain can't be cryptographically verified.
Enable DNSSEC at your DNS provider.
Not checked: the blocklists declined queries from this resolver, so reputation could not be confirmed either way. This is excluded from your score rather than guessed at.
Not measured — the certificate transparency log was unavailable (returned 502).
Not measured — no log file supplied. Server logs are the only source that shows what Googlebot actually fetched rather than what it could fetch: which pages it spends its crawl on, which it has never asked for, and what it receives when it does.
2 nameserver(s) configured.
Checked 0 subdomain(s); none point at a cloud service that has released them.
26 of 29 crawled page(s) can be indexed (90%).
No filter, session or calendar URLs that would generate an unbounded space were found.
Every template returns content for most of its URLs.
Every page was reached directly or in a single hop.
0 of 12 URL(s) followed during this crawl returned a redirect or an error (0%).
The deepest page reached sits 2 click(s) from the homepage.
Your certificate covers only your own domain.
Every sitemap file is within the 50,000 URL and 50 MB limits.
31 of 32 sitemap URL(s) carry a lastmod date across 28 distinct value(s).
0 internal link(s) are marked nofollow.
CAA record present.
No version numbers advertised in response headers.
Served from AS13335 (CLOUDFLARENET - Cloudflare, Inc.), announced in 104.21.16.0/20 — a block of 4,096 addresses.
12 page(s) were examined, chosen to cover 11 of the 17 distinct page templates found across 32 known URLs. Pages are sampled by template rather than in sitemap order, because the first pages of a sitemap are usually all the same kind — a sample of one template would describe that template rather than the site. Findings below therefore apply to the templates listed, and a fault in a template is normally a fault on every page built from it.
29 page(s) crawled across 15 template(s). Read the largest ones first — a fault in a template used four hundred times is a different size of problem from the same fault on one page, and the effort to fix it is the same.
Who links to this site, with what text, and how that compares.
Not measured — off-page data is not configured on this instance.
The site loaded in a real browser, the way a visitor and a crawler get it.
Measured 3.5s on a simulated phone viewport. Google's threshold for 'good' is 2.5s. This is the metric most likely to be costing you both rankings and visitors who leave before the page paints.
LCP 3496 ms · FCP 675 ms
Compress and preload the largest above-the-fold image, and cache the HTML at the edge.
4 resource(s) failed to load. Missing images and stylesheets are visible to customers; missing scripts break features.
https://connect.facebook.net/signals/config/941203915020301?v=2.9.390&r=stable&domain=novadose.com&hme=a767ae4c6a92a40ee4d7e358a937ad845c8bdb98a3bbe34 (failed) https://assets.novadose.com/videos/hero-lineup-prd.mp4 (failed) https://stats.g.doubleclick.net/g/collect?v=2&ngs=1&ibt=1&tid=G-73S83L6GG9&cid=1582777720.1788219629>m=45je68s1v9259966447za200zd9259966447&rcb=11&a (failed) https://www.google.com/ccm/collect?rcb=2&frm=0&apvc=1&auid=187419049.1788219629&dt=NovaDose%20%E2%80%94%20Pre-Filled%20Peptide%20Pens%2C%20Lab-Verifie (failed)
Fix or remove these URLs.
53 of 74 tappable element(s) are smaller than 48x48 pixels, and 24 sit closer than 8 pixels to a neighbour. On a phone that means links and buttons that are hard to hit without zooming, and mis-taps on a checkout or contact button cost conversions directly.
SAVE10 (70x21) NovaDose (113x32) Cart (40x40) Menu (40x40) A (350x44)
Give tappable elements at least 48x48 CSS pixels and 8 pixels of spacing — usually padding on the link rather than a bigger font.
125 of 268 text block(s) render below 12px on a mobile viewport. Text that small forces pinch-zooming, which is the single most common reason a visitor leaves a page on a phone before reading it.
Set body text to at least 16px, and never below 12px.
The served HTML contains 1664 words and the rendered page 1555 — the content is present before JavaScript runs.
What the server sends a phone matches what it sends a desktop browser.
The canonical and robots directives are the same before and after JavaScript runs.
93 links in the served HTML, 91 after rendering — navigation is discoverable.
Cumulative Layout Shift measured at 0.000 (good is 0.1 or less).
The page loaded without JavaScript errors.
The page fits the mobile viewport with no sideways scrolling.
0 long JavaScript task(s) blocked the main thread while loading.
The page made 52 network requests to load.
| Final URL | https://novadose.com/ |
|---|---|
| Host IPs | 104.21.22.30, 172.67.202.49, 2606:4700:3030::6815:161e, 2606:4700:3030::ac43:ca31 |
| Pages crawled | 12 of 12 attempted |
| Sitemap URLs | 32 |
| Nameservers | daisy.ns.cloudflare.com, isaac.ns.cloudflare.com |
| Mail servers | alt1.aspmx.l.google.com, alt2.aspmx.l.google.com, alt3.aspmx.l.google.com, alt4.aspmx.l.google.com, aspmx.l.google.com |
| DKIM selectors | google, k2 |
| Mail server IPs | 172.253.157.27, 142.250.102.26, 192.178.213.26 |
| TLS | TLSv1.3 · TLS_AES_256_GCM_SHA384 · issued by Google Trust Services |
| Detected stack | WooCommerce / Cloudflare / Cloudflare · mail on Google Workspace · Google Analytics 4 |
| Browser render | Camoufox (stealth Firefox) · 6.1s · 1555 words, 91 links after JavaScript |
BounceZero Ltd does this work: technical remediation, local SEO and email deliverability. Tell us what you want fixed and we'll reply with what it takes. No call required, no obligation.
We re-audit on a schedule and email you only when a check that was passing starts failing. That is usually a recent change to the site or its DNS, and it is findable while still fresh. No digest, no newsletter.
Monitoring means repeatedly fetching your site and emailing about it, so we ask you to prove you own novadose.com first.