SEO monitoring: what to watch on a client's site, how often, and how to avoid alert noise
Published 7 October 20268 min readBy the SmoothSeen editorial team
SEO monitoring is the regular watch over anything that can break a site's visibility without anyone noticing: pages dropping out of the index, robots.txt suddenly blocking everything, the certificate expiring, or Core Web Vitals getting worse. It works with immediate alerts for whatever cuts traffic and a weekly or monthly review for everything else.
Key points
- SEO monitoring watches for whatever can break a site's visibility without anyone noticing, between one report and the next.
- Anything that cuts traffic (site down, robots.txt blocking, expired certificate, security warning) needs an immediate alert; the rest, a weekly or monthly review.
- Certificates keep getting shorter. The CA/Browser Forum approved cutting maximum validity from 398 to 47 days between March 2026 and March 2029, and Let's Encrypt moves to 45 days in 2028.
- Core Web Vitals field data covers a 28-day window, so checking it daily will not tell you whether a fix has worked.
- A useful alert says what changed, where and compared with what, and only fires above the normal variation of the measurement.
To check it on your own site: For agencies
On this page
It is what happens between two reports. The SEO client report explains what changed, why and what comes next; monitoring tells you something has broken before the client notices, so the report can also say what you did about it.
What should you monitor on a client's website, and how often?
Watch first for what takes a site out of Google overnight, then for what wears it down slowly. Frequency is set by how much damage each failure does while nobody sees it, not by how easy it is to measure.
- What to monitor
- Uptime
- What can happen
- The site or server stops responding
- Frequency
- Every few minutes
- With what
- An uptime monitor
- What to monitor
- HTTPS certificate
- What can happen
- It expires and the browser warns that the site is not secure
- Frequency
- Daily
- With what
- Uptime monitor or
openssl
- What to monitor
- robots.txt
- What can happen
- A deployment pushes the staging file with
Disallow: / - Frequency
- Daily and after every deployment
- With what
curland the robots.txt report in Search Console
- What to monitor
- Indexing
- What can happen
- A forgotten
noindexor a wrong canonical - Frequency
- Weekly
- With what
- Page indexing report in Search Console
- What to monitor
- Security warnings
- What can happen
- Hacked content, malware or deceptive pages
- Frequency
- As soon as the warning arrives
- With what
- Search Console emails
- What to monitor
- Core Web Vitals
- What can happen
- A new template slows loading or hurts stability
- Frequency
- Weekly or monthly
- With what
- PageSpeed Insights and Search Console
- What to monitor
- Broken links
- What can happen
- Pages deleted or moved without a redirect
- Frequency
- Monthly
- With what
- A site crawl
- What to monitor
- Template changes
- What can happen
- A redesign changes titles, canonicals or structured data
- Frequency
- After every deployment
- With what
- Review one URL per template
robots.txt: the failure that does the most damage in the least time
The classic case is a deployment that pushes the staging robots.txt to production, with a Disallow: / that blocks everything. Google generally caches robots.txt for up to 24 hours, so the block can take that long to show and as long again to lift1. If the file returns a server error, Google stops crawling the site for the first 12 hours and, if the error persists, uses the last good version for 30 days1.
The robots.txt report in Search Console shows which files Google found for the top 20 hosts on the site, when it last read them and what errors they have. It also lets you request a recrawl in an emergency2. So you do not depend on checking the report, this check fits into a daily task (replace example.com with the client's domain):
# Once, when robots.txt is correct: save the reference copy
curl -s https://www.example.com/robots.txt -o robots-good.txt
# Every day (for example, from cron):
# 1. Does the file respond? A 5xx stops Google crawling
curl -s -o /dev/null -w "%{http_code}\n" https://www.example.com/robots.txt
# 2. Has it changed since the good copy?
curl -s https://www.example.com/robots.txt -o robots-today.txt
diff -q robots-good.txt robots-today.txt || echo "robots.txt has changed: review it"
# 3. Is there a full block?
grep -nE "^Disallow:[[:space:]]*/[[:space:]]*$" robots-today.txt && echo "There is a full Disallow: /"A Disallow: / is not always a mistake: it may sit in the group for a training crawler the client has chosen to block. That is why the alert says "review it" rather than "fix it". What each AI crawler does and which ones to let through is covered in the guide to AI crawlers and robots.txt.
The certificate: shorter every year
On 11 April 2025 the CA/Browser Forum, which brings together certificate authorities and browser makers, approved cutting the maximum validity of public TLS certificates from 398 to 47 days in phases, between March 2026 and March 20293. Let's Encrypt, which issued 90-day certificates, will move to 64 days in February 2027 and to 45 in February 20284.
At those lengths, manual renewal stops being viable. Let's Encrypt recommends automating renewal and having monitoring that alerts you if a certificate is not renewed when it should be4. The expiry date takes one line to check:
echo | openssl s_client -connect www.example.com:443 -servername www.example.com 2>/dev/null \
| openssl x509 -noout -enddateWhat else to check for HTTPS, from mixed content to redirects, is in the guide to HTTPS and SEO.
Core Web Vitals: why checking them daily does not help
Real-user data in PageSpeed Insights covers the previous 28 days5. The Core Web Vitals report in Search Console uses the same source, and when you mark an issue as fixed it starts a 28-day validation to confirm it6. A fix therefore shows up gradually: on day one it accounts for only 1/28 of the window.
The same applies in reverse. A new template that worsens LCP does not move field data overnight. That is what the Lighthouse lab test is for: it gives a result immediately, although it varies from one run to the next. The useful combination is a lab test after every deployment and field data every week or month. The thresholds and what each metric measures are in the guide to Core Web Vitals.
Which free tools can monitor a website?
Three cover most of the table at no cost:
- Search Console emails. Search Console sends property messages to all relevant users, for example an alert about a new indexing issue7. Restricted users only receive messages that affect them directly, so your agency should be added as a full user on the client's property8.
- The Security issues report in Search Console. It covers hacked content, malware and unwanted software, and social engineering pages. Affected pages may appear in Google with a warning or trigger a browser warning page9.
- An uptime monitor. For example, UptimeRobot's free plan includes 50 monitors with checks every 5 minutes and alerts for certificate and domain expiry. UptimeRobot presents it as aimed at personal and non-profit projects, so check its terms before using it for clients10.
What none of the three does is compare two full analyses of the same page and tell you what has got worse. Broken links need a separate crawl; how to run one is in the guide to broken links.
How do you tell a useful alert from noise?
A useful alert asks for a specific action, says what changed, where and compared with what, and only fires above the normal variation of the measurement. Anything that does not meet those three conditions goes into a weekly summary, not the inbox.
- Useful alert
- "robots.txt has changed and now has
Disallow: /in the general group" - Noise
- "robots.txt has changed" every time someone adds a comment
- Useful alert
- "The site has returned 503 for 10 minutes"
- Noise
- A single failed check
- Useful alert
- "The certificate expires in 7 days and has not been renewed"
- Noise
- A daily warning starting 60 days before
- Useful alert
- "Field LCP for the product template has gone from 2.3 to 3.1 s in a month"
- Noise
- A lab test that drops 3 points in one run
- Useful alert
- "The home page score has dropped 9 points since the previous analysis"
- Noise
- Any one-point movement
Three rules so the alerts are still being read six months from now:
- A threshold above natural variation. Lab tests vary from run to run and field data moves on its own. An alert for every point ends up in an email rule that archives it.
- Comparison on the same basis. Today's state against the previous measurement of the same page, measured the same way. If the tool changes how it measures, the difference is neither yours nor the client's.
- One owner per alert type. If a type of alert has gone a month without anyone acting on it, remove it or move it to the summary.
How does SmoothSeen handle monitoring?
Declaration of interest: this blog belongs to SmoothSeen. Its scheduled monitoring re-analyses each client without you having to remember: monthly on the Professional plan, weekly on Agency and daily on Enterprise.
- What it watches: the page you choose for each client or, if you choose none, the last one you analysed. Each automatic analysis runs the same SEO and AI visibility checks as one launched by hand, and uses one analysis from the monthly quota.
- When it alerts: if the web or AI score drops 5 points or more against the previous analysis of that page, you get an email with the drop and a link to the report. Below that figure, movement is usually measurement noise. Analyses you launch by hand do not trigger alerts.
- What you see next: the before-and-after view separates what was fixed, what is new and what is still pending between two analyses of the same client, judged on the same basis. With white label on the Agency and Enterprise plans, the alert email goes out under your agency's brand; we explain it in the guide to white-label SEO reports.
What it does not do matters too. It watches one page per client, not the whole site. It does not replace an uptime monitor: if the site is down or rejects the analysis, there is no score to compare. And it does not connect to Search Console or track rankings, so Search Console emails are still essential.
Frequently asked questions
How often should you check a client's SEO?
It depends on the failure. Check uptime every few minutes; the certificate and robots.txt daily and after every deployment; indexing weekly; and Core Web Vitals, broken links and content monthly. A full audit makes sense when you start working with the client and after every redesign or migration.
Does Search Console alert you if a site stops being indexed?
It emails owners and relevant users about new issues on the property, such as an indexing problem. But it does so at its own pace, after crawling, not at the moment a noindex goes live. That is why it pays to add your own check of robots.txt and of the most important pages after each deployment.
Why don't Core Web Vitals improve right after a fix?
Because the real-user data shown in PageSpeed Insights and Search Console covers the previous 28 days. Visits from before the fix stay in the window until they drop out of it. To check the fix straight away, use the lab test, and allow about four weeks to see the full effect in field data.
What is the difference between monitoring and auditing a website?
An audit is a full, one-off review that finds everything that is wrong and ranks it by severity. Monitoring is the repeated watch over a smaller set of signals, designed to catch what breaks afterwards. The first tells you where to start; the second, whether anything has changed since.
What to do next
Pick one client and check three things today: that your agency receives their Search Console emails, that a monitor watches their uptime and certificate, and that you have a good copy of their robots.txt to compare against. Then decide what goes into the next report with the guide to the SEO client report.
Sources
- 1How Google Interprets the robots.txt Specification, Google for Developers, updated 31 August 2026.
- 2robots.txt report, Search Console Help, accessed 7 October 2026.
- 3Ballot SC081v3: Introduce Schedule of Reducing Validity and Data Reuse Periods, CA/Browser Forum, 11 April 2025.
- 4Decreasing Certificate Lifetimes to 45 Days, Let's Encrypt, 2 December 2025.
- 5About PageSpeed Insights, Google for Developers, updated 21 October 2024.
- 6Core Web Vitals report, Search Console Help, accessed 7 October 2026.
- 7Message panel, Search Console Help, accessed 7 October 2026.
- 8Managing owners, users, and permissions, Search Console Help, accessed 7 October 2026.
- 9Security issues report, Search Console Help, accessed 7 October 2026.
- 10Plans & Pricing, UptimeRobot, accessed 7 October 2026.
How to cite this article
SmoothSeen. (2026, October 7). SEO monitoring: what to watch on a client's site, how often, and how to avoid alert noise. https://smoothseen.com/en/blog/seo-monitoring/
Keep reading
SEO client reports in 2026: what to include (AI visibility too) and how to prove results
What an SEO client report should cover in 2026, AI visibility included, how to prove results without inflating numbers, and a section-by-section template.
AI visibility audit: a block-by-block checklist to audit a client's site
A five-block checklist to audit whether ChatGPT, Gemini or Perplexity can read and cite a client's site, with an annotated robots.txt and sources.
White label SEO reports: what they should include and what to tell clients about your tools
What a white label SEO report is, what it should carry under your brand, what to tell clients about your tools and the mistakes that give the vendor away.