[{"data":1,"prerenderedAt":8356},["ShallowReactive",2],{"blog-article:en:discovers-urls":3,"blog-translations:discovers-new-urls":926,"related-blog-articles:en:discovers-urls":934},{"id":4,"title":5,"author":6,"body":7,"category":910,"description":911,"draft":912,"extension":913,"featured":914,"image":915,"imageAlt":916,"locale":917,"meta":918,"navigation":914,"path":919,"publishedAt":920,"seo":921,"slug":922,"stem":923,"translationKey":924,"updatedAt":920,"__hash__":925},"blog\u002Fblog\u002Fen\u002Fdiscovers-urls.md","How Google Discovers New URLs: Links, Sitemaps and Crawling","SeoNest Team",{"type":8,"value":9,"toc":893},"minimark",[10,15,19,35,39,54,57,62,65,69,169,175,179,185,188,195,235,241,248,251,258,263,267,270,281,306,309,340,346,352,357,361,364,367,397,404,407,414,420,431,434,439,443,446,449,457,460,466,472,482,485,491,494,500,504,511,514,520,527,538,543,547,550,583,586,593,596,600,603,610,616,638,642,645,680,687,691,701,704,707,713,716,720,725,731,735,741,745,748,752,758,762,768,772,775,778,784,788,889],[11,12,14],"h2",{"id":13},"how-google-discovers-new-urls","How Google Discovers New URLs",[16,17,18],"p",{},"Publishing a page does not automatically mean Google knows that it exists. Before Google can crawl, understand, or index a page, its systems normally need to discover the page’s URL.",[16,20,21,22,26,27,34],{},"Google calls this ",[23,24,25],"strong",{},"URL discovery",". According to Google’s documentation, new URLs are commonly found through links on pages Google already knows and through submitted sitemaps. Googlebot can then place discovered URLs into its crawling process, but discovery alone does not guarantee that a URL will be crawled, indexed, or shown in search results. (",[28,29,33],"a",{"href":30,"rel":31},"https:\u002F\u002Fdevelopers.google.com\u002Fsearch\u002Fdocs\u002Ffundamentals\u002Fhow-search-works?utm_source=chatgpt.com",[32],"nofollow","developers.google.com",")",[11,36,38],{"id":37},"direct-answer","Direct Answer",[16,40,41,42,45,46,49,50,34],{},"Google primarily discovers new URLs by ",[23,43,44],{},"following links from previously discovered pages"," and by ",[23,47,48],{},"reading sitemaps"," provided by website owners. Googlebot can also encounter URLs while processing redirects and links generated by JavaScript when those links are implemented in a crawlable way. (",[28,51,33],{"href":52,"rel":53},"https:\u002F\u002Fdevelopers.google.com\u002Fsearch\u002Fdocs\u002Ffundamentals\u002Fget-started-developers?utm_source=chatgpt.com",[32],[16,55,56],{},"The important distinction is:",[16,58,59],{},[23,60,61],{},"Discovery → Crawling → Indexing → Serving",[16,63,64],{},"These are separate stages. A discovered URL is only a URL Google knows about. It is not automatically an indexed page.",[11,66,68],{"id":67},"key-facts","Key Facts",[70,71,72,88],"table",{},[73,74,75],"thead",{},[76,77,78,82,85],"tr",{},[79,80,81],"th",{},"Mechanism",[79,83,84],{},"Can help Google discover a URL?",[79,86,87],{},"Important limitation",[89,90,91,103,113,123,133,143,158],"tbody",{},[76,92,93,97,100],{},[94,95,96],"td",{},"Internal links",[94,98,99],{},"Yes",[94,101,102],{},"The link should be crawlable",[76,104,105,108,110],{},[94,106,107],{},"External links",[94,109,99],{},[94,111,112],{},"Google must encounter the linking page",[76,114,115,118,120],{},[94,116,117],{},"XML sitemap",[94,119,99],{},[94,121,122],{},"A sitemap is a hint, not a guarantee",[76,124,125,128,130],{},[94,126,127],{},"RSS\u002FAtom feed",[94,129,99],{},[94,131,132],{},"Usually covers recent content",[76,134,135,138,140],{},[94,136,137],{},"Redirect",[94,139,99],{},[94,141,142],{},"Googlebot may encounter the destination while navigating URLs",[76,144,145,148,150],{},[94,146,147],{},"JavaScript-generated link",[94,149,99],{},[94,151,152,153,157],{},"It should ultimately produce a crawlable ",[154,155,156],"code",{},"\u003Ca href>"," link",[76,159,160,163,166],{},[94,161,162],{},"Search Console request",[94,164,165],{},"Yes, for URLs you manage",[94,167,168],{},"Requesting crawling does not guarantee indexing",[16,170,171,172,34],{},"Google explicitly says that it does not maintain a central registry containing every web page. Its crawlers continuously discover new and updated URLs across the web instead. (",[28,173,33],{"href":30,"rel":174},[32],[11,176,178],{"id":177},"links-are-the-main-discovery-path","Links Are the Main Discovery Path",[16,180,181,182,34],{},"Googlebot discovers new URLs primarily from links embedded in pages that Google already knows about. Google’s documentation describes a simple example: a category or hub page links to a newly published blog post, allowing Google to discover that new URL. (",[28,183,33],{"href":30,"rel":184},[32],[16,186,187],{},"The same principle applies both internally and externally.",[16,189,190,191,194],{},"An ",[23,192,193],{},"internal link"," points from one page on your site to another:",[196,197,202],"pre",{"className":198,"code":199,"language":200,"meta":201,"style":201},"language-html shiki shiki-themes github-light github-dark","\u003Ca href=\"\u002Fguides\u002Ftechnical-seo\">Technical SEO Guide\u003C\u002Fa>\n","html","",[154,203,204],{"__ignoreMap":201},[205,206,209,213,216,220,223,227,230,232],"span",{"class":207,"line":208},"line",1,[205,210,212],{"class":211},"sVt8B","\u003C",[205,214,28],{"class":215},"s9eBZ",[205,217,219],{"class":218},"sScJk"," href",[205,221,222],{"class":211},"=",[205,224,226],{"class":225},"sZZnC","\"\u002Fguides\u002Ftechnical-seo\"",[205,228,229],{"class":211},">Technical SEO Guide\u003C\u002F",[205,231,28],{"class":215},[205,233,234],{"class":211},">\n",[16,236,190,237,240],{},[23,238,239],{},"external link"," from another website can expose your URL through the same general crawling process.",[16,242,243,244,34],{},"For important pages, Google recommends making sure each page has a link from at least one other page on your site. (",[28,245,33],{"href":246,"rel":247},"https:\u002F\u002Fdevelopers.google.com\u002Fsearch\u002Fdocs\u002Fcrawling-indexing\u002Flinks-crawlable?authuser=2&utm_source=chatgpt.com",[32],[16,249,250],{},"This is why site architecture matters for discovery. A page may exist perfectly well on your server but remain difficult for Google to find if nothing Google can crawl points to it.",[16,252,253,254,257],{},"Pages with no meaningful internal links are commonly called ",[23,255,256],{},"orphan pages",".",[16,259,260],{},[205,261,262],{},"INTERNAL LINK: Internal Linking for SEO",[11,264,266],{"id":265},"links-must-be-crawlable","Links Must Be Crawlable",[16,268,269],{},"Not every clickable interface element is necessarily a link Google can reliably extract.",[16,271,272,273,276,277,280],{},"Google says the safest structure is an HTML ",[154,274,275],{},"\u003Ca>"," element with an ",[154,278,279],{},"href"," attribute:",[196,282,284],{"className":198,"code":283,"language":200,"meta":201,"style":201},"\u003Ca href=\"\u002Fservices\u002Fseo\">SEO Services\u003C\u002Fa>\n",[154,285,286],{"__ignoreMap":201},[205,287,288,290,292,294,296,299,302,304],{"class":207,"line":208},[205,289,212],{"class":211},[205,291,28],{"class":215},[205,293,219],{"class":218},[205,295,222],{"class":211},[205,297,298],{"class":225},"\"\u002Fservices\u002Fseo\"",[205,300,301],{"class":211},">SEO Services\u003C\u002F",[205,303,28],{"class":215},[205,305,234],{"class":211},[16,307,308],{},"Patterns based only on JavaScript event handlers are less reliable:",[196,310,312],{"className":198,"code":311,"language":200,"meta":201,"style":201},"\u003Cspan onclick=\"openPage('\u002Fservices\u002Fseo')\">SEO Services\u003C\u002Fspan>\n",[154,313,314],{"__ignoreMap":201},[205,315,316,318,320,323,325,328,331,334,336,338],{"class":207,"line":208},[205,317,212],{"class":211},[205,319,205],{"class":215},[205,321,322],{"class":218}," onclick",[205,324,222],{"class":211},[205,326,327],{"class":225},"\"",[205,329,330],{"class":218},"openPage",[205,332,333],{"class":225},"('\u002Fservices\u002Fseo')\"",[205,335,301],{"class":211},[205,337,205],{"class":215},[205,339,234],{"class":211},[16,341,342,343,34],{},"Google can execute JavaScript, and JavaScript can insert links into the rendered DOM. However, Google still recommends implementing those links according to its crawlable-link guidance. (",[28,344,33],{"href":246,"rel":345},[32],[16,347,348,349,34],{},"For JavaScript-heavy applications, every piece of content intended to appear as a separate search result should also have its own URL. (",[28,350,33],{"href":52,"rel":351},[32],[16,353,354],{},[205,355,356],{},"INTERNAL LINK: JavaScript SEO Explained",[11,358,360],{"id":359},"sitemaps-help-google-find-urls","Sitemaps Help Google Find URLs",[16,362,363],{},"A sitemap gives Google a structured list of URLs you consider important.",[16,365,366],{},"For example:",[196,368,372],{"className":369,"code":370,"language":371,"meta":201,"style":201},"language-xml shiki shiki-themes github-light github-dark","\u003Curl>\n  \u003Cloc>https:\u002F\u002Fexample.com\u002Fblog\u002Fnew-article\u003C\u002Floc>\n  \u003Clastmod>2026-09-20\u003C\u002Flastmod>\n\u003C\u002Furl>\n","xml",[154,373,374,379,385,391],{"__ignoreMap":201},[205,375,376],{"class":207,"line":208},[205,377,378],{},"\u003Curl>\n",[205,380,382],{"class":207,"line":381},2,[205,383,384],{},"  \u003Cloc>https:\u002F\u002Fexample.com\u002Fblog\u002Fnew-article\u003C\u002Floc>\n",[205,386,388],{"class":207,"line":387},3,[205,389,390],{},"  \u003Clastmod>2026-09-20\u003C\u002Flastmod>\n",[205,392,394],{"class":207,"line":393},4,[205,395,396],{},"\u003C\u002Furl>\n",[16,398,399,400,34],{},"Google describes sitemaps as an important discovery mechanism, particularly for large websites, recently launched sites, sites with few external links, and sites containing specialized media or news content. (",[28,401,33],{"href":402,"rel":403},"https:\u002F\u002Fdevelopers.google.com\u002Fsearch\u002Fdocs\u002Fcrawling-indexing\u002Fsitemaps\u002Foverview?authuser=1&utm_source=chatgpt.com",[32],[16,405,406],{},"A sitemap is especially useful when a page is not likely to be discovered quickly through normal link crawling.",[16,408,409,410,413],{},"However, submitting a sitemap does ",[23,411,412],{},"not"," mean:",[415,416,417],"blockquote",{},[16,418,419],{},"“Google must crawl and index every URL listed here.”",[16,421,422,423,426,427,34],{},"Google explicitly describes sitemap submission as a ",[23,424,425],{},"hint",". It does not guarantee that Google will download, crawl, or index every submitted URL. (",[28,428,33],{"href":429,"rel":430},"https:\u002F\u002Fdevelopers.google.com\u002Fsearch\u002Fdocs\u002Fcrawling-indexing\u002Fsitemaps\u002Fbuild-sitemap?authuser=77&utm_source=chatgpt.com",[32],[16,432,433],{},"Sitemaps should therefore complement good internal linking rather than replace it.",[16,435,436],{},[205,437,438],{},"INTERNAL LINK: XML Sitemaps Explained",[11,440,442],{"id":441},"discovery-is-not-crawling","Discovery Is Not Crawling",[16,444,445],{},"This distinction causes a large amount of SEO confusion.",[16,447,448],{},"Suppose Google finds:",[196,450,455],{"className":451,"code":453,"language":454,"meta":201},[452],"language-text","https:\u002F\u002Fexample.com\u002Fnew-page\n","text",[154,456,453],{"__ignoreMap":201},[16,458,459],{},"through an internal link.",[16,461,462,463,257],{},"At this point Google may know the URL exists. That is ",[23,464,465],{},"discovery",[16,467,468,469,257],{},"Googlebot may later fetch the URL. That is ",[23,470,471],{},"crawling",[16,473,474,475,478,479,34],{},"Google may then analyze the content and decide whether and how to store it in its search index. That is ",[23,476,477],{},"indexing",". (",[28,480,33],{"href":30,"rel":481},[32],[16,483,484],{},"A simplified flow looks like this:",[196,486,489],{"className":487,"code":488,"language":454,"meta":201},[452],"URL discovered\n      ↓\nAdded to crawling process\n      ↓\nGooglebot fetches the URL\n      ↓\nContent is processed\u002Frendered\n      ↓\nGoogle evaluates it for indexing\n",[154,490,488],{"__ignoreMap":201},[16,492,493],{},"Not every URL moves through every step.",[16,495,496,497,34],{},"Google explicitly states that following its technical requirements does not guarantee crawling, indexing, or appearance in Search. (",[28,498,33],{"href":30,"rel":499},[32],[11,501,503],{"id":502},"robotstxt-does-not-hide-a-url","robots.txt Does Not Hide a URL",[16,505,506,507,510],{},"A common misconception is that blocking a URL in ",[154,508,509],{},"robots.txt"," prevents Google from discovering it.",[16,512,513],{},"That is not necessarily true.",[16,515,516,517,519],{},"If another page links to the blocked URL, Google may still learn that the URL exists. A ",[154,518,509],{}," rule prevents the specified crawler from fetching the blocked resource; it does not necessarily erase knowledge of the URL.",[16,521,522,523,34],{},"Google notes that a blocked URL may even appear in search results without a snippet because Google cannot crawl its content. (",[28,524,33],{"href":525,"rel":526},"https:\u002F\u002Fdevelopers.google.com\u002Fcrawling\u002Fdocs\u002Frobots-txt\u002Frobots-txt-spec?authuser=117&utm_source=chatgpt.com",[32],[16,528,529,530,533,534,34],{},"If your goal is to prevent indexing, Google recommends using ",[154,531,532],{},"noindex"," while allowing the crawler to access the page so it can see that directive. (",[28,535,33],{"href":536,"rel":537},"https:\u002F\u002Fdevelopers.google.com\u002Fsearch\u002Fdocs\u002Fcrawling-indexing\u002Fblock-indexing?utm_source=chatgpt.com",[32],[16,539,540],{},[205,541,542],{},"INTERNAL LINK: robots.txt Explained",[11,544,546],{"id":545},"what-about-nofollow","What About nofollow?",[16,548,549],{},"A link using:",[196,551,553],{"className":198,"code":552,"language":200,"meta":201,"style":201},"\u003Ca href=\"\u002Fprivate-page\" rel=\"nofollow\">Page\u003C\u002Fa>\n",[154,554,555],{"__ignoreMap":201},[205,556,557,559,561,563,565,568,571,573,576,579,581],{"class":207,"line":208},[205,558,212],{"class":211},[205,560,28],{"class":215},[205,562,219],{"class":218},[205,564,222],{"class":211},[205,566,567],{"class":225},"\"\u002Fprivate-page\"",[205,569,570],{"class":218}," rel",[205,572,222],{"class":211},[205,574,575],{"class":225},"\"nofollow\"",[205,577,578],{"class":211},">Page\u003C\u002F",[205,580,28],{"class":215},[205,582,234],{"class":211},[16,584,585],{},"generally tells Google not to follow that particular link.",[16,587,588,589,34],{},"However, this does not guarantee that the destination URL remains undiscovered. Google may find the same URL through another internal link, another website, or a sitemap. (",[28,590,33],{"href":591,"rel":592},"https:\u002F\u002Fdevelopers.google.com\u002Fsearch\u002Fdocs\u002Fcrawling-indexing\u002Fqualify-outbound-links?utm_source=chatgpt.com",[32],[16,594,595],{},"Discovery is therefore best understood as a web-wide process rather than something controlled by a single link.",[11,597,599],{"id":598},"search-console-and-url-submission","Search Console and URL Submission",[16,601,602],{},"For a small number of pages you manage, Google Search Console's URL Inspection tool can be used to request crawling.",[16,604,605,606,34],{},"For larger groups of URLs, Google recommends using a sitemap. (",[28,607,33],{"href":608,"rel":609},"https:\u002F\u002Fdevelopers.google.com\u002Fsearch\u002Fdocs\u002Fcrawling-indexing\u002Fask-google-to-recrawl?utm_source=chatgpt.com",[32],[16,611,612,613,34],{},"Repeatedly requesting indexing does not make Google crawl the same URL faster, and a crawl request does not guarantee inclusion in search results. (",[28,614,33],{"href":608,"rel":615},[32],[16,617,618,619,622,623,626,627,630,631,478,634,34],{},"Another common misconception involves Google's ",[23,620,621],{},"Indexing API",". It is not a general-purpose API for submitting ordinary pages. Google currently documents it for pages containing ",[154,624,625],{},"JobPosting"," or livestream ",[154,628,629],{},"BroadcastEvent"," content embedded in ",[154,632,633],{},"VideoObject",[28,635,33],{"href":636,"rel":637},"https:\u002F\u002Fdevelopers.google.com\u002Fsearch\u002Fapis\u002Findexing-api\u002Fv3\u002Fusing-api?utm_source=chatgpt.com",[32],[11,639,641],{"id":640},"improve-url-discovery","Improve URL Discovery",[16,643,644],{},"For most websites, the practical approach is straightforward:",[646,647,648,652,655,661,664,667,674,677],"ol",{},[649,650,651],"li",{},"Give every important page a permanent, crawlable URL.",[649,653,654],{},"Link to new pages from existing relevant pages.",[649,656,657,658,660],{},"Use normal ",[154,659,156],{}," links.",[649,662,663],{},"Keep important pages reachable through your site architecture.",[649,665,666],{},"Maintain an accurate sitemap containing URLs you want Google to find.",[649,668,669,670,673],{},"Update meaningful ",[154,671,672],{},"\u003Clastmod>"," values when content actually changes.",[649,675,676],{},"Avoid accidentally blocking required pages or resources.",[649,678,679],{},"Use Search Console to diagnose important URLs that are not being discovered or crawled.",[16,681,682,683,34],{},"Google also warns that discovery may be slower if important links available on desktop are missing from the mobile version of a site, because Google indexes the mobile version of pages. (",[28,684,33],{"href":685,"rel":686},"https:\u002F\u002Fdevelopers.google.com\u002Fsearch\u002Fdocs\u002Fcrawling-indexing\u002Ftroubleshoot-crawling-errors?authuser=2&utm_source=chatgpt.com",[32],[11,688,690],{"id":689},"seonest-recommendation","SeoNest Recommendation",[16,692,693,694,697,698,257],{},"Treat ",[23,695,696],{},"internal links as the primary discovery architecture"," and ",[23,699,700],{},"sitemaps as a complementary discovery signal",[16,702,703],{},"A new page should ideally be discoverable naturally from another useful page rather than existing only inside a sitemap. For large or frequently updated websites, automate sitemap generation and ensure newly published canonical URLs enter the sitemap promptly.",[16,705,706],{},"If an important page is not appearing in Google, diagnose the stages separately:",[196,708,711],{"className":709,"code":710,"language":454,"meta":201},[452],"Does Google know the URL?\n        ↓\nCan Google crawl it?\n        ↓\nCan Google render the content?\n        ↓\nIs it eligible for indexing?\n        ↓\nDid Google choose to index it?\n",[154,712,710],{"__ignoreMap":201},[16,714,715],{},"Trying to solve an indexing problem by repeatedly submitting the URL will not help if the underlying problem is actually site architecture, crawlability, rendering, duplication, or content quality.",[11,717,719],{"id":718},"faq","FAQ",[721,722,724],"h4",{"id":723},"how-long-does-google-take-to-discover-a-new-url","How long does Google take to discover a new URL?",[16,726,727,728,34],{},"There is no guaranteed discovery time. Google says crawling after a request can take from a few days to a few weeks, and its crawling schedule is algorithmic. (",[28,729,33],{"href":608,"rel":730},[32],[721,732,734],{"id":733},"does-google-need-a-sitemap-to-discover-pages","Does Google need a sitemap to discover pages?",[16,736,737,738,34],{},"No. If your pages are properly linked, Google can usually discover most of them through links. Sitemaps become particularly useful for large, new, complex, or media-heavy sites. (",[28,739,33],{"href":402,"rel":740},[32],[721,742,744],{"id":743},"can-google-discover-a-page-with-no-internal-links","Can Google discover a page with no internal links?",[16,746,747],{},"Potentially. It might discover the URL through an external link, sitemap, or another source. But relying on that is poor site architecture for an important page.",[721,749,751],{"id":750},"does-sitemap-submission-guarantee-indexing","Does sitemap submission guarantee indexing?",[16,753,754,755,34],{},"No. Google explicitly says sitemap submission is a hint and does not guarantee crawling or indexing. (",[28,756,33],{"href":429,"rel":757},[32],[721,759,761],{"id":760},"does-robotstxt-stop-url-discovery","Does robots.txt stop URL discovery?",[16,763,764,765,34],{},"Not necessarily. Google may know a blocked URL from links or other discovery mechanisms even when it cannot crawl the page. (",[28,766,33],{"href":525,"rel":767},[32],[11,769,771],{"id":770},"final-takeaway","Final Takeaway",[16,773,774],{},"Google cannot crawl a page it does not know exists.",[16,776,777],{},"New URLs are primarily discovered as Googlebot follows crawlable links across the web and processes sitemaps provided by site owners. Once discovered, a URL enters a separate process in which Google decides whether and when to crawl it, then whether the resulting content should be indexed.",[16,779,780,781],{},"For SEO, the practical lesson is simple: ",[23,782,783],{},"publish URLs into a discoverable web structure, not merely onto a server.",[11,785,787],{"id":786},"sources","Sources",[789,790,791,806,818,830,842,853,865,878],"ul",{},[649,792,793,794,478,798,801,802],{},"Google Search Central — ",[795,796,797],"em",{},"In-depth guide to how Google Search works",[28,799,33],{"href":30,"rel":800},[32],") ",[28,803,805],{"href":30,"rel":804},[32],"Google documentation",[649,807,793,808,478,811,801,814],{},[795,809,810],{},"Link best practices for Google",[28,812,33],{"href":246,"rel":813},[32],[28,815,805],{"href":816,"rel":817},"https:\u002F\u002Fdevelopers.google.com\u002Fsearch\u002Fdocs\u002Fcrawling-indexing\u002Flinks-crawlable?utm_source=chatgpt.com",[32],[649,819,793,820,478,823,801,826],{},[795,821,822],{},"Learn about sitemaps",[28,824,33],{"href":402,"rel":825},[32],[28,827,805],{"href":828,"rel":829},"https:\u002F\u002Fdevelopers.google.com\u002Fsearch\u002Fdocs\u002Fcrawling-indexing\u002Fsitemaps\u002Foverview?utm_source=chatgpt.com",[32],[649,831,793,832,478,835,801,838],{},[795,833,834],{},"Build and submit a sitemap",[28,836,33],{"href":429,"rel":837},[32],[28,839,805],{"href":840,"rel":841},"https:\u002F\u002Fdevelopers.google.com\u002Fsearch\u002Fdocs\u002Fcrawling-indexing\u002Fsitemaps\u002Fbuild-sitemap?utm_source=chatgpt.com",[32],[649,843,793,844,478,847,801,850],{},[795,845,846],{},"Ask Google to recrawl your URLs",[28,848,33],{"href":608,"rel":849},[32],[28,851,805],{"href":608,"rel":852},[32],[649,854,793,855,478,858,801,862],{},[795,856,857],{},"Understand JavaScript SEO basics",[28,859,33],{"href":860,"rel":861},"https:\u002F\u002Fdevelopers.google.com\u002Fsearch\u002Fdocs\u002Fcrawling-indexing\u002Fjavascript\u002Fjavascript-seo-basics?utm_source=chatgpt.com",[32],[28,863,805],{"href":860,"rel":864},[32],[649,866,867,868,478,871,801,874],{},"Google Crawling Infrastructure — ",[795,869,870],{},"How Google interprets the robots.txt specification",[28,872,33],{"href":525,"rel":873},[32],[28,875,805],{"href":876,"rel":877},"https:\u002F\u002Fdevelopers.google.com\u002Fcrawling\u002Fdocs\u002Frobots-txt\u002Frobots-txt-spec?utm_source=chatgpt.com",[32],[649,879,793,880,478,883,801,886],{},[795,881,882],{},"Using the Indexing API",[28,884,33],{"href":636,"rel":885},[32],[28,887,805],{"href":636,"rel":888},[32],[890,891,892],"style",{},"html pre.shiki code .sVt8B, html code.shiki .sVt8B{--shiki-default:#24292E;--shiki-dark:#E1E4E8}html pre.shiki code .s9eBZ, html code.shiki .s9eBZ{--shiki-default:#22863A;--shiki-dark:#85E89D}html pre.shiki code .sScJk, html code.shiki .sScJk{--shiki-default:#6F42C1;--shiki-dark:#B392F0}html pre.shiki code .sZZnC, html code.shiki .sZZnC{--shiki-default:#032F62;--shiki-dark:#9ECBFF}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":201,"searchDepth":381,"depth":381,"links":894},[895,896,897,898,899,900,901,902,903,904,905,906,907,908,909],{"id":13,"depth":381,"text":14},{"id":37,"depth":381,"text":38},{"id":67,"depth":381,"text":68},{"id":177,"depth":381,"text":178},{"id":265,"depth":381,"text":266},{"id":359,"depth":381,"text":360},{"id":441,"depth":381,"text":442},{"id":502,"depth":381,"text":503},{"id":545,"depth":381,"text":546},{"id":598,"depth":381,"text":599},{"id":640,"depth":381,"text":641},{"id":689,"depth":381,"text":690},{"id":718,"depth":381,"text":719},{"id":770,"depth":381,"text":771},{"id":786,"depth":381,"text":787},"Technical SEO","Learn how Google discovers new URLs through links, sitemaps, redirects and crawling, and why URL discovery does not automatically mean indexing.",false,"md",true,"\u002Fdiscovers-in-urls.png","Google Discovers New URLs","en",{},"\u002Fblog\u002Fen\u002Fdiscovers-urls","2026-09-20",{"title":5,"description":911},"discovers-urls","blog\u002Fen\u002Fdiscovers-urls","discovers-new-urls","gTtq60HxSEYwEFtieYhEck5y2lz11DLG0fJmVdPMyLo",[927,928,931],{"locale":917,"slug":922},{"locale":929,"slug":930},"ru","obnaruzhivaet-url",{"locale":932,"slug":933},"uz","url-aniqlash",[935,1983,2873,4101,4943,5689,6939,7670],{"id":936,"title":937,"author":6,"body":938,"category":1973,"description":1974,"draft":912,"extension":913,"featured":914,"image":1975,"imageAlt":1976,"locale":917,"meta":1977,"navigation":914,"path":1978,"publishedAt":920,"seo":1979,"slug":1980,"stem":1981,"translationKey":1980,"updatedAt":920,"__hash__":1982},"blog\u002Fblog\u002Fen\u002Fcls-explained.md","CLS Explained: What Cumulative Layout Shift Means",{"type":8,"value":939,"toc":1948},[940,944,951,959,963,968,978,981,984,988,991,1035,1042,1049,1053,1056,1062,1072,1077,1081,1087,1090,1096,1103,1112,1115,1121,1127,1132,1135,1141,1150,1153,1157,1160,1174,1177,1180,1184,1187,1191,1194,1197,1255,1258,1307,1321,1325,1328,1331,1334,1368,1378,1382,1385,1388,1392,1395,1419,1423,1438,1441,1479,1482,1510,1524,1528,1534,1542,1549,1556,1559,1564,1570,1574,1577,1580,1586,1592,1597,1601,1604,1737,1747,1751,1757,1763,1769,1775,1777,1780,1783,1793,1795,1799,1805,1809,1819,1823,1826,1830,1833,1837,1843,1845,1851,1854,1857,1859,1945],[11,941,943],{"id":942},"cls-explained-cumulative-layout-shift","CLS Explained: Cumulative Layout Shift",[16,945,946,947,950],{},"A page can load quickly and still feel broken. You start reading, an image appears, the text suddenly moves downward, and the button you were about to click jumps somewhere else. That instability is what ",[23,948,949],{},"Cumulative Layout Shift (CLS)"," is designed to measure.",[16,952,953,954,34],{},"CLS is one of Google's three Core Web Vitals, alongside Largest Contentful Paint (LCP) and Interaction to Next Paint (INP). Unlike those metrics, CLS is not measured in milliseconds. It produces a unitless score that represents how much visible content moved unexpectedly and how significant that movement was. (",[28,955,958],{"href":956,"rel":957},"https:\u002F\u002Fweb.dev\u002Farticles\u002Fcls?authuser=6",[32],"web.dev",[11,960,962],{"id":961},"what-is-cls","What Is CLS?",[16,964,965],{},[23,966,967],{},"Cumulative Layout Shift measures the visual stability of a web page by quantifying unexpected movement of visible content.",[16,969,970,971,974,975,34],{},"A layout shift occurs when a visible element changes its starting position between two rendered frames. CLS then groups unexpected shifts into short bursts called ",[23,972,973],{},"session windows"," and reports the session window with the largest combined shift score. (",[28,976,958],{"href":956,"rel":977},[32],[16,979,980],{},"A practical example is an article where the browser initially renders the headline and text, then an image without reserved dimensions loads above them. The image takes up space, pushes the article downward, and forces the reader to find their place again.",[16,982,983],{},"That movement contributes to CLS.",[11,985,987],{"id":986},"cls-score","CLS Score",[16,989,990],{},"Google's current thresholds are:",[70,992,993,1003],{},[73,994,995],{},[76,996,997,1000],{},[79,998,999],{},"CLS",[79,1001,1002],{},"Assessment",[89,1004,1005,1015,1025],{},[76,1006,1007,1012],{},[94,1008,1009],{},[23,1010,1011],{},"0.10 or lower",[94,1013,1014],{},"Good",[76,1016,1017,1022],{},[94,1018,1019],{},[23,1020,1021],{},"Above 0.10 to 0.25",[94,1023,1024],{},"Needs improvement",[76,1026,1027,1032],{},[94,1028,1029],{},[23,1030,1031],{},"Above 0.25",[94,1033,1034],{},"Poor",[16,1036,1037,1038,1041],{},"For Core Web Vitals evaluation, Google recommends looking at the ",[23,1039,1040],{},"75th percentile of page visits",", segmented between mobile and desktop. In practical terms, at least 75% of visits should experience a CLS of 0.10 or lower.",[16,1043,1044,1045,1048],{},"CLS is unitless. A score of ",[154,1046,1047],{},"0.1"," does not mean 0.1 seconds. It represents the combined severity of unexpected visual movement.",[11,1050,1052],{"id":1051},"why-cls-matters","Why CLS Matters",[16,1054,1055],{},"Layout instability directly affects usability.",[16,1057,1058,1059,34],{},"A shift can make someone lose their reading position, cause a form control to move while they are interacting with it, or make a user accidentally click a different button from the one they intended. The problem becomes especially noticeable on slower networks, where images, advertisements, fonts, API responses, and third-party content may arrive later than they do during local development. (",[28,1060,958],{"href":956,"rel":1061},[32],[16,1063,1064,1065,1067,1068,34],{},"CLS also matters to search performance. Google documents Core Web Vitals as signals used by its ranking systems and recommends achieving good Core Web Vitals for Search and user experience. However, a good CLS score does ",[23,1066,412],{}," guarantee higher rankings. Google evaluates many signals, and Core Web Vitals are only one part of page experience. (",[28,1069,33],{"href":1070,"rel":1071},"https:\u002F\u002Fdevelopers.google.com\u002Fsearch\u002Fdocs\u002Fappearance\u002Fcore-web-vitals?authuser=1",[32],[16,1073,1074],{},[205,1075,1076],{},"INTERNAL LINK: Core Web Vitals Explained",[11,1078,1080],{"id":1079},"how-cls-works","How CLS Works",[16,1082,1083,1084,257],{},"CLS starts with individual ",[23,1085,1086],{},"layout shift scores",[16,1088,1089],{},"For every relevant shift, the browser evaluates two factors:",[196,1091,1094],{"className":1092,"code":1093,"language":454,"meta":201},[452],"layout shift score = impact fraction × distance fraction\n",[154,1095,1093],{"__ignoreMap":201},[16,1097,1098,1099,1102],{},"The ",[23,1100,1101],{},"impact fraction"," represents how much of the viewport is affected by unstable elements before and after the movement.",[16,1104,1098,1105,1108,1109,34],{},[23,1106,1107],{},"distance fraction"," measures how far the most displaced unstable element moved relative to the viewport's largest dimension. (",[28,1110,958],{"href":956,"rel":1111},[32],[16,1113,1114],{},"Suppose a moving element affects 75% of the viewport and moves a distance equivalent to 25% of the viewport's largest dimension:",[196,1116,1119],{"className":1117,"code":1118,"language":454,"meta":201},[452],"0.75 × 0.25 = 0.1875\n",[154,1120,1118],{"__ignoreMap":201},[16,1122,1123,1124,257],{},"The layout shift score for that event is therefore ",[154,1125,1126],{},"0.1875",[1128,1129,1131],"h3",{"id":1130},"session-windows","Session Windows",[16,1133,1134],{},"Modern CLS does not simply add every layout shift that occurs throughout a page's lifetime.",[16,1136,1137,1138,1140],{},"Individual unexpected shifts are grouped into ",[23,1139,973],{},". A session window contains shifts separated by less than one second and can last for a maximum of five seconds.",[16,1142,1143,1144,478,1147,34],{},"The page's CLS is the combined score of the ",[23,1145,1146],{},"largest session window",[28,1148,958],{"href":956,"rel":1149},[32],[16,1151,1152],{},"This approach prevents long-lived pages such as single-page applications and infinite-scroll interfaces from being automatically penalized simply because users keep them open longer.",[11,1154,1156],{"id":1155},"expected-shifts","Expected Shifts",[16,1158,1159],{},"Not every movement contributes to CLS.",[16,1161,1162,1163,1166,1167,1170,1171,34],{},"A shift caused directly by a discrete user interaction—such as a click, tap, or keypress—can be excluded when it happens within ",[23,1164,1165],{},"500 milliseconds"," of that interaction. The Layout Instability API exposes this through the ",[154,1168,1169],{},"hadRecentInput"," property. (",[28,1172,958],{"href":956,"rel":1173},[32],[16,1175,1176],{},"For example, expanding an accordion immediately after a user clicks it is generally expected.",[16,1178,1179],{},"However, scrolling is different. Continuous interactions such as scrolling are not treated in the same way. If lazy-loaded content suddenly pushes existing content downward while the user scrolls, that movement can still contribute to CLS.",[11,1181,1183],{"id":1182},"common-cls-causes","Common CLS Causes",[16,1185,1186],{},"The most frequent causes are surprisingly ordinary.",[1128,1188,1190],{"id":1189},"unsized-images","Unsized Images",[16,1192,1193],{},"An image without known dimensions can initially occupy little or no layout space. Once the image loads, the browser discovers its size and moves surrounding content.",[16,1195,1196],{},"Reserve the required space using HTML dimensions:",[196,1198,1200],{"className":198,"code":1199,"language":200,"meta":201,"style":201},"\u003Cimg\n  src=\"product.jpg\"\n  width=\"1200\"\n  height=\"800\"\n  alt=\"Product\"\n>\n",[154,1201,1202,1209,1219,1229,1239,1250],{"__ignoreMap":201},[205,1203,1204,1206],{"class":207,"line":208},[205,1205,212],{"class":211},[205,1207,1208],{"class":215},"img\n",[205,1210,1211,1214,1216],{"class":207,"line":381},[205,1212,1213],{"class":218},"  src",[205,1215,222],{"class":211},[205,1217,1218],{"class":225},"\"product.jpg\"\n",[205,1220,1221,1224,1226],{"class":207,"line":387},[205,1222,1223],{"class":218},"  width",[205,1225,222],{"class":211},[205,1227,1228],{"class":225},"\"1200\"\n",[205,1230,1231,1234,1236],{"class":207,"line":393},[205,1232,1233],{"class":218},"  height",[205,1235,222],{"class":211},[205,1237,1238],{"class":225},"\"800\"\n",[205,1240,1242,1245,1247],{"class":207,"line":1241},5,[205,1243,1244],{"class":218},"  alt",[205,1246,222],{"class":211},[205,1248,1249],{"class":225},"\"Product\"\n",[205,1251,1253],{"class":207,"line":1252},6,[205,1254,234],{"class":211},[16,1256,1257],{},"Responsive CSS can still resize the image:",[196,1259,1263],{"className":1260,"code":1261,"language":1262,"meta":201,"style":201},"language-css shiki shiki-themes github-light github-dark","img {\n  width: 100%;\n  height: auto;\n}\n","css",[154,1264,1265,1273,1291,1302],{"__ignoreMap":201},[205,1266,1267,1270],{"class":207,"line":208},[205,1268,1269],{"class":215},"img",[205,1271,1272],{"class":211}," {\n",[205,1274,1275,1278,1281,1284,1288],{"class":207,"line":381},[205,1276,1223],{"class":1277},"sj4cs",[205,1279,1280],{"class":211},": ",[205,1282,1283],{"class":1277},"100",[205,1285,1287],{"class":1286},"szBVR","%",[205,1289,1290],{"class":211},";\n",[205,1292,1293,1295,1297,1300],{"class":207,"line":387},[205,1294,1233],{"class":1277},[205,1296,1280],{"class":211},[205,1298,1299],{"class":1277},"auto",[205,1301,1290],{"class":211},[205,1303,1304],{"class":207,"line":393},[205,1305,1306],{"class":211},"}\n",[16,1308,1309,1310,697,1313,1316,1317,34],{},"Modern browsers can use the ",[154,1311,1312],{},"width",[154,1314,1315],{},"height"," attributes to determine the image's aspect ratio before the image finishes loading. (",[28,1318,958],{"href":1319,"rel":1320},"https:\u002F\u002Fweb.dev\u002Farticles\u002Foptimize-cls",[32],[1128,1322,1324],{"id":1323},"ads-and-embeds","Ads and Embeds",[16,1326,1327],{},"Advertisements, video embeds, maps, social widgets, and iframes often load after the surrounding page.",[16,1329,1330],{},"If their container initially has no height, everything below it may move when the content appears.",[16,1332,1333],{},"Reserve predictable space:",[196,1335,1337],{"className":1260,"code":1336,"language":1262,"meta":201,"style":201},".video-wrapper {\n  aspect-ratio: 16 \u002F 9;\n}\n",[154,1338,1339,1346,1364],{"__ignoreMap":201},[205,1340,1341,1344],{"class":207,"line":208},[205,1342,1343],{"class":218},".video-wrapper",[205,1345,1272],{"class":211},[205,1347,1348,1351,1353,1356,1359,1362],{"class":207,"line":381},[205,1349,1350],{"class":1277},"  aspect-ratio",[205,1352,1280],{"class":211},[205,1354,1355],{"class":1277},"16",[205,1357,1358],{"class":211}," \u002F ",[205,1360,1361],{"class":1277},"9",[205,1363,1290],{"class":211},[205,1365,1366],{"class":207,"line":387},[205,1367,1306],{"class":211},[16,1369,1370,1371,1374,1375,34],{},"For variable-height content, a suitable ",[154,1372,1373],{},"min-height"," or placeholder can reduce movement. Removing reserved space when no advertisement appears can itself create another layout shift, so placeholders need to be designed carefully. (",[28,1376,958],{"href":1319,"rel":1377},[32],[1128,1379,1381],{"id":1380},"dynamic-content","Dynamic Content",[16,1383,1384],{},"Cookie notices, promotional banners, alerts, recommendations, and asynchronously loaded components can cause large shifts when inserted above content the user is already viewing.",[16,1386,1387],{},"Prefer reserving space beforehand or, where appropriate, displaying the component as an overlay rather than inserting it into the document flow.",[1128,1389,1391],{"id":1390},"web-fonts","Web Fonts",[16,1393,1394],{},"A fallback font and the final web font can have different character widths, line heights, or metrics. When the real font arrives, text may wrap differently and move surrounding content.",[16,1396,1397,1398,1401,1402,1405,1406,1405,1409,1412,1413,478,1416,34],{},"Possible improvements include selecting a closer fallback font, loading critical fonts earlier, using ",[154,1399,1400],{},"font-display"," appropriately, and adjusting fallback font metrics with properties such as ",[154,1403,1404],{},"size-adjust",", ",[154,1407,1408],{},"ascent-override",[154,1410,1411],{},"descent-override",", and ",[154,1414,1415],{},"line-gap-override",[28,1417,958],{"href":1319,"rel":1418},[32],[1128,1420,1422],{"id":1421},"layout-based-animations","Layout-Based Animations",[16,1424,1425,1426,1405,1429,1405,1432,1434,1435,1437],{},"Animating properties such as ",[154,1427,1428],{},"top",[154,1430,1431],{},"left",[154,1433,1312],{},", or ",[154,1436,1315],{}," can change layout.",[16,1439,1440],{},"Where possible, use compositor-friendly transforms:",[196,1442,1444],{"className":1260,"code":1443,"language":1262,"meta":201,"style":201},".card {\n  transform: translateY(20px);\n}\n",[154,1445,1446,1453,1475],{"__ignoreMap":201},[205,1447,1448,1451],{"class":207,"line":208},[205,1449,1450],{"class":218},".card",[205,1452,1272],{"class":211},[205,1454,1455,1458,1460,1463,1466,1469,1472],{"class":207,"line":381},[205,1456,1457],{"class":1277},"  transform",[205,1459,1280],{"class":211},[205,1461,1462],{"class":1277},"translateY",[205,1464,1465],{"class":211},"(",[205,1467,1468],{"class":1277},"20",[205,1470,1471],{"class":1286},"px",[205,1473,1474],{"class":211},");\n",[205,1476,1477],{"class":207,"line":387},[205,1478,1306],{"class":211},[16,1480,1481],{},"instead of repeatedly changing:",[196,1483,1485],{"className":1260,"code":1484,"language":1262,"meta":201,"style":201},".card {\n  top: 20px;\n}\n",[154,1486,1487,1493,1506],{"__ignoreMap":201},[205,1488,1489,1491],{"class":207,"line":208},[205,1490,1450],{"class":218},[205,1492,1272],{"class":211},[205,1494,1495,1498,1500,1502,1504],{"class":207,"line":381},[205,1496,1497],{"class":1277},"  top",[205,1499,1280],{"class":211},[205,1501,1468],{"class":1277},[205,1503,1471],{"class":1286},[205,1505,1290],{"class":211},[205,1507,1508],{"class":207,"line":387},[205,1509,1306],{"class":211},[16,1511,1512,1513,1516,1517,1520,1521,34],{},"Using ",[154,1514,1515],{},"transform: translate()"," or ",[154,1518,1519],{},"transform: scale()"," can visually move elements without creating the same type of layout shift. (",[28,1522,958],{"href":956,"rel":1523},[32],[11,1525,1527],{"id":1526},"how-to-measure-cls","How to Measure CLS",[16,1529,1530,1531,257],{},"Start with ",[23,1532,1533],{},"field data",[16,1535,1536,1537,34],{},"Chrome UX Report (CrUX) contains aggregated real-user Core Web Vitals data, including CLS. PageSpeed Insights can display CrUX field data where sufficient data is available, while Search Console groups pages through its Core Web Vitals report. CrUX reports CLS at the 75th percentile and treats CLS as a unitless metric. (",[28,1538,1541],{"href":1539,"rel":1540},"https:\u002F\u002Fdeveloper.chrome.com\u002Fdocs\u002Fcrux\u002Fapi?utm_source=chatgpt.com",[32],"developer.chrome.com",[16,1543,1544,1545,1548],{},"Then use ",[23,1546,1547],{},"lab tools"," to investigate the problem.",[16,1550,1551,1552,34],{},"Chrome DevTools' Performance panel exposes individual layout shifts and groups them into clusters. You can inspect shift scores, affected elements, timing, screenshots, and potential culprits. Chrome's Rendering tools can also highlight layout-shift regions visually. (",[28,1553,1541],{"href":1554,"rel":1555},"https:\u002F\u002Fdeveloper.chrome.com\u002Fdocs\u002Fdevtools\u002Fperformance\u002Freference?authuser=1&hl=en&utm_source=chatgpt.com",[32],[16,1557,1558],{},"A useful workflow is:",[16,1560,1561],{},[23,1562,1563],{},"Field CLS is poor → reproduce the page → identify the largest shift cluster → inspect the shifted elements → locate the element that caused the movement → fix it → measure again.",[16,1565,1566,1567,34],{},"Do not assume the element that moved is the root cause. A paragraph may move because an advertisement, image, banner, or another component above it changed size. (",[28,1568,958],{"href":1319,"rel":1569},[32],[11,1571,1573],{"id":1572},"lab-vs-field-cls","Lab vs Field CLS",[16,1575,1576],{},"One common debugging mistake is expecting Lighthouse and real-user CLS to match exactly.",[16,1578,1579],{},"They measure different situations.",[16,1581,1582,1583,34],{},"A normal Lighthouse test primarily observes the initial page load. Real users may continue scrolling, opening menus, loading more products, triggering route changes, or keeping a page open for several minutes. Unexpected shifts happening later can therefore appear in CrUX even when a simple Lighthouse load looks stable. (",[28,1584,958],{"href":1319,"rel":1585},[32],[16,1587,1588,1589,257],{},"When lab CLS is low but field CLS is high, investigate ",[23,1590,1591],{},"post-load interactions and scrolling behavior",[16,1593,1594],{},[205,1595,1596],{},"INTERNAL LINK: Lab Data vs Field Data",[11,1598,1600],{"id":1599},"cls-debugging","CLS Debugging",[16,1602,1603],{},"For difficult cases, Chromium exposes layout shifts through the Layout Instability API:",[196,1605,1609],{"className":1606,"code":1607,"language":1608,"meta":201,"style":201},"language-js shiki shiki-themes github-light github-dark","new PerformanceObserver((entryList) => {\n  for (const entry of entryList.getEntries()) {\n    if (!entry.hadRecentInput) {\n      console.log('Layout shift:', entry.value, entry.sources);\n    }\n  }\n}).observe({\n  type: 'layout-shift',\n  buffered: true\n});\n","js",[154,1610,1611,1633,1659,1672,1688,1693,1698,1710,1722,1731],{"__ignoreMap":201},[205,1612,1613,1616,1619,1622,1626,1628,1631],{"class":207,"line":208},[205,1614,1615],{"class":1286},"new",[205,1617,1618],{"class":218}," PerformanceObserver",[205,1620,1621],{"class":211},"((",[205,1623,1625],{"class":1624},"s4XuR","entryList",[205,1627,801],{"class":211},[205,1629,1630],{"class":1286},"=>",[205,1632,1272],{"class":211},[205,1634,1635,1638,1641,1644,1647,1650,1653,1656],{"class":207,"line":381},[205,1636,1637],{"class":1286},"  for",[205,1639,1640],{"class":211}," (",[205,1642,1643],{"class":1286},"const",[205,1645,1646],{"class":1277}," entry",[205,1648,1649],{"class":1286}," of",[205,1651,1652],{"class":211}," entryList.",[205,1654,1655],{"class":218},"getEntries",[205,1657,1658],{"class":211},"()) {\n",[205,1660,1661,1664,1666,1669],{"class":207,"line":387},[205,1662,1663],{"class":1286},"    if",[205,1665,1640],{"class":211},[205,1667,1668],{"class":1286},"!",[205,1670,1671],{"class":211},"entry.hadRecentInput) {\n",[205,1673,1674,1677,1680,1682,1685],{"class":207,"line":393},[205,1675,1676],{"class":211},"      console.",[205,1678,1679],{"class":218},"log",[205,1681,1465],{"class":211},[205,1683,1684],{"class":225},"'Layout shift:'",[205,1686,1687],{"class":211},", entry.value, entry.sources);\n",[205,1689,1690],{"class":207,"line":1241},[205,1691,1692],{"class":211},"    }\n",[205,1694,1695],{"class":207,"line":1252},[205,1696,1697],{"class":211},"  }\n",[205,1699,1701,1704,1707],{"class":207,"line":1700},7,[205,1702,1703],{"class":211},"}).",[205,1705,1706],{"class":218},"observe",[205,1708,1709],{"class":211},"({\n",[205,1711,1713,1716,1719],{"class":207,"line":1712},8,[205,1714,1715],{"class":211},"  type: ",[205,1717,1718],{"class":225},"'layout-shift'",[205,1720,1721],{"class":211},",\n",[205,1723,1725,1728],{"class":207,"line":1724},9,[205,1726,1727],{"class":211},"  buffered: ",[205,1729,1730],{"class":1277},"true\n",[205,1732,1734],{"class":207,"line":1733},10,[205,1735,1736],{"class":211},"});\n",[16,1738,1739,1740,1743,1744,34],{},"This is useful for debugging individual shifts, but it is not a complete implementation of the CLS metric. Correct CLS calculation requires grouping shifts into session windows and handling additional lifecycle cases. For production Real User Monitoring, the ",[154,1741,1742],{},"web-vitals"," library is generally safer than reimplementing the complete metric yourself. (",[28,1745,958],{"href":956,"rel":1746},[32],[11,1748,1750],{"id":1749},"common-misconceptions","Common Misconceptions",[16,1752,1753,1756],{},[23,1754,1755],{},"“CLS measures loading speed.”","\nNo. CLS measures visual stability. A page can load quickly and still have terrible CLS.",[16,1758,1759,1762],{},[23,1760,1761],{},"“Any movement increases CLS.”","\nNo. CLS focuses on unexpected layout shifts. Some shifts associated closely with discrete user input are excluded.",[16,1764,1765,1768],{},[23,1766,1767],{},"“A Lighthouse CLS of zero means users see zero CLS.”","\nNot necessarily. Post-load shifts may appear in field data but never occur during a simple synthetic page-load test.",[16,1770,1771,1774],{},[23,1772,1773],{},"“The shifted element caused the problem.”","\nNot always. It may simply have been pushed by another element.",[11,1776,690],{"id":689},[16,1778,1779],{},"Treat CLS as a layout architecture problem rather than a score to optimize after development.",[16,1781,1782],{},"Reserve space for media and third-party components before they load. Design asynchronous UI so loading does not unexpectedly displace existing content. Test pages under realistic network conditions and user flows, not only during initial load.",[16,1784,1785,1786,1789,1790,257],{},"For production sites, combine field monitoring with DevTools debugging. Field data tells you ",[23,1787,1788],{},"whether real users experience instability","; diagnostic tooling helps determine ",[23,1791,1792],{},"why",[11,1794,719],{"id":718},[721,1796,1798],{"id":1797},"is-cls-part-of-core-web-vitals","Is CLS part of Core Web Vitals?",[16,1800,1801,1802,34],{},"Yes. CLS is the Core Web Vital that measures visual stability. The other current Core Web Vitals are LCP for loading performance and INP for responsiveness. (",[28,1803,33],{"href":1070,"rel":1804},[32],[721,1806,1808],{"id":1807},"what-is-a-good-cls","What is a good CLS?",[16,1810,1811,1812,1815,1816,34],{},"A CLS of ",[23,1813,1814],{},"0.10 or lower at the 75th percentile of page visits"," is considered good. (",[28,1817,958],{"href":956,"rel":1818},[32],[721,1820,1822],{"id":1821},"is-cls-measured-in-seconds","Is CLS measured in seconds?",[16,1824,1825],{},"No. CLS is a unitless score.",[721,1827,1829],{"id":1828},"can-lazy-loading-increase-cls","Can lazy loading increase CLS?",[16,1831,1832],{},"Lazy loading itself is not necessarily the problem. CLS occurs when lazy-loaded content appears without sufficient space having already been reserved.",[721,1834,1836],{"id":1835},"can-cls-happen-after-page-load","Can CLS happen after page load?",[16,1838,1839,1840,34],{},"Yes. Unexpected shifts can occur during scrolling, dynamic content updates, SPA transitions, or other post-load behavior. This is one reason field CLS may be higher than Lighthouse CLS. (",[28,1841,958],{"href":1319,"rel":1842},[32],[11,1844,771],{"id":770},[16,1846,1847,1848],{},"CLS answers a simple question: ",[23,1849,1850],{},"does the page stay where the user expects it to stay?",[16,1852,1853],{},"A good CLS is not achieved by making every page static. Modern interfaces can still load content dynamically, animate elements, and react to user input. The important principle is predictability: reserve space before content arrives, avoid unexpectedly moving existing content, and validate the result using real-user data.",[16,1855,1856],{},"When a layout is stable by design, a good CLS score usually follows.",[11,1858,787],{"id":786},[646,1860,1861,1874,1887,1901,1915,1931],{},[649,1862,1863,1864,1866,1867,1640,1871,34],{},"web.dev — ",[23,1865,949],{},". Last updated April 12, 2023. ",[28,1868,949],{"href":1869,"rel":1870},"https:\u002F\u002Fweb.dev\u002Farticles\u002Fcls?utm_source=chatgpt.com",[32],[28,1872,958],{"href":956,"rel":1873},[32],[649,1875,1863,1876,1879,1880,1640,1884,34],{},[23,1877,1878],{},"Optimize Cumulative Layout Shift",". Published May 5, 2020; updated February 7, 2025. ",[28,1881,1878],{"href":1882,"rel":1883},"https:\u002F\u002Fweb.dev\u002Farticles\u002Foptimize-cls?utm_source=chatgpt.com",[32],[28,1885,958],{"href":1319,"rel":1886},[32],[649,1888,1863,1889,1892,1893,1640,1897,34],{},[23,1890,1891],{},"Debug layout shifts",". Published March 11, 2021; updated February 7, 2025. ",[28,1894,1891],{"href":1895,"rel":1896},"https:\u002F\u002Fweb.dev\u002Farticles\u002Fdebug-layout-shifts?utm_source=chatgpt.com",[32],[28,1898,958],{"href":1899,"rel":1900},"https:\u002F\u002Fweb.dev\u002Farticles\u002Fdebug-layout-shifts",[32],[649,1902,793,1903,1906,1907,1640,1912,34],{},[23,1904,1905],{},"Understanding Core Web Vitals and Google search results",". Last updated December 10, 2025. ",[28,1908,1911],{"href":1909,"rel":1910},"https:\u002F\u002Fdevelopers.google.com\u002Fsearch\u002Fdocs\u002Fappearance\u002Fcore-web-vitals?utm_source=chatgpt.com",[32],"Google Search Central Core Web Vitals documentation",[28,1913,33],{"href":1070,"rel":1914},[32],[649,1916,1917,1918,1921,1922,1640,1927,34],{},"Chrome for Developers — ",[23,1919,1920],{},"Chrome UX Report: Metrics",". Published June 23, 2022; updated September 15, 2026. ",[28,1923,1926],{"href":1924,"rel":1925},"https:\u002F\u002Fdeveloper.chrome.com\u002Fdocs\u002Fcrux\u002Fmethodology\u002Fmetrics?utm_source=chatgpt.com",[32],"Chrome UX Report Metrics",[28,1928,1541],{"href":1929,"rel":1930},"https:\u002F\u002Fdeveloper.chrome.com\u002Fdocs\u002Fcrux\u002Fmethodology\u002Fmetrics?authuser=804924846",[32],[649,1932,1917,1933,1936,1937,1640,1942,34],{},[23,1934,1935],{},"Performance features reference",". ",[28,1938,1941],{"href":1939,"rel":1940},"https:\u002F\u002Fdeveloper.chrome.com\u002Fdocs\u002Fdevtools\u002Fperformance\u002Freference?utm_source=chatgpt.com",[32],"Chrome DevTools Performance reference",[28,1943,1541],{"href":1554,"rel":1944},[32],[890,1946,1947],{},"html pre.shiki code .sVt8B, html code.shiki .sVt8B{--shiki-default:#24292E;--shiki-dark:#E1E4E8}html pre.shiki code .s9eBZ, html code.shiki .s9eBZ{--shiki-default:#22863A;--shiki-dark:#85E89D}html pre.shiki code .sScJk, html code.shiki .sScJk{--shiki-default:#6F42C1;--shiki-dark:#B392F0}html pre.shiki code .sZZnC, html code.shiki .sZZnC{--shiki-default:#032F62;--shiki-dark:#9ECBFF}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sj4cs, html code.shiki .sj4cs{--shiki-default:#005CC5;--shiki-dark:#79B8FF}html pre.shiki code .szBVR, html code.shiki .szBVR{--shiki-default:#D73A49;--shiki-dark:#F97583}html pre.shiki code .s4XuR, html code.shiki .s4XuR{--shiki-default:#E36209;--shiki-dark:#FFAB70}",{"title":201,"searchDepth":381,"depth":381,"links":1949},[1950,1951,1952,1953,1954,1957,1958,1965,1966,1967,1968,1969,1970,1971,1972],{"id":942,"depth":381,"text":943},{"id":961,"depth":381,"text":962},{"id":986,"depth":381,"text":987},{"id":1051,"depth":381,"text":1052},{"id":1079,"depth":381,"text":1080,"children":1955},[1956],{"id":1130,"depth":387,"text":1131},{"id":1155,"depth":381,"text":1156},{"id":1182,"depth":381,"text":1183,"children":1959},[1960,1961,1962,1963,1964],{"id":1189,"depth":387,"text":1190},{"id":1323,"depth":387,"text":1324},{"id":1380,"depth":387,"text":1381},{"id":1390,"depth":387,"text":1391},{"id":1421,"depth":387,"text":1422},{"id":1526,"depth":381,"text":1527},{"id":1572,"depth":381,"text":1573},{"id":1599,"depth":381,"text":1600},{"id":1749,"depth":381,"text":1750},{"id":689,"depth":381,"text":690},{"id":718,"depth":381,"text":719},{"id":770,"depth":381,"text":771},{"id":786,"depth":381,"text":787},"Performance","Learn what Cumulative Layout Shift (CLS) measures, how the score works, what causes layout shifts, and how to diagnose and improve CLS.","\u002Fcls-defination.png","image of CLS",{},"\u002Fblog\u002Fen\u002Fcls-explained",{"title":937,"description":1974},"cls-explained","blog\u002Fen\u002Fcls-explained","q2ITFn4ZZSmPH-olBc8JwTQH8GeuS9lNVnvPYKBTH6E",{"id":1984,"title":1985,"author":6,"body":1986,"category":910,"description":2864,"draft":912,"extension":913,"featured":914,"image":2865,"imageAlt":2866,"locale":917,"meta":2867,"navigation":914,"path":2868,"publishedAt":920,"seo":2869,"slug":2870,"stem":2871,"translationKey":2870,"updatedAt":920,"__hash__":2872},"blog\u002Fblog\u002Fen\u002Fcrawling-in-seo.md","What Is Crawling in SEO? How Search Crawlers Work",{"type":8,"value":1987,"toc":2843},[1988,1992,1997,2017,2020,2022,2027,2030,2039,2043,2046,2110,2113,2118,2122,2125,2130,2133,2138,2141,2166,2178,2181,2186,2204,2223,2227,2230,2234,2241,2244,2249,2253,2257,2260,2262,2280,2296,2300,2304,2310,2312,2329,2341,2344,2347,2351,2354,2359,2362,2372,2378,2381,2390,2393,2423,2432,2436,2440,2443,2449,2455,2460,2464,2467,2482,2485,2488,2509,2515,2518,2523,2527,2530,2541,2544,2595,2598,2600,2609,2618,2627,2633,2635,2642,2645,2648,2651,2653,2657,2663,2667,2673,2677,2683,2687,2690,2694,2697,2699,2702,2708,2711,2713,2841],[11,1989,1991],{"id":1990},"what-is-crawling-in-seo","What Is Crawling in SEO?",[16,1993,1994,1995,257],{},"Before a search engine can understand or rank a web page, it usually has to find and retrieve it. That process is called ",[23,1996,471],{},[16,1998,1999,2000,1405,2003,1434,2006,2009,2010,2013,2014,34],{},"Search engines use automated programs called ",[23,2001,2002],{},"crawlers",[23,2004,2005],{},"bots",[23,2007,2008],{},"spiders"," to discover URLs and request their content. Google’s primary search crawler is called ",[23,2011,2012],{},"Googlebot",". It can discover pages through links, sitemaps, previously known URLs, and other signals, then fetch those URLs so their content can move into later search-processing stages. (",[28,2015,33],{"href":30,"rel":2016},[32],[16,2018,2019],{},"Crawling sounds simple, but problems with links, robots.txt, servers, redirects, JavaScript, or URL architecture can stop important pages from being discovered efficiently.",[11,2021,38],{"id":37},[16,2023,2024],{},[23,2025,2026],{},"Crawling in SEO is the process search engine bots use to discover and retrieve URLs from the web.",[16,2028,2029],{},"A crawler finds a URL, checks whether it is allowed to access it, sends a request to the server, receives the response, and may extract additional URLs from the page.",[16,2031,2032,2033,2035,2036,34],{},"Crawling does ",[23,2034,412],{}," mean a page is indexed or will rank. It only makes the page available for further processing. Google explicitly notes that not every crawled page is eventually indexed. (",[28,2037,33],{"href":30,"rel":2038},[32],[11,2040,2042],{"id":2041},"crawling-vs-indexing","Crawling vs Indexing",[16,2044,2045],{},"These concepts are closely related but are not interchangeable.",[70,2047,2048,2058],{},[73,2049,2050],{},[76,2051,2052,2055],{},[79,2053,2054],{},"Stage",[79,2056,2057],{},"What happens",[89,2059,2060,2070,2080,2090,2100],{},[76,2061,2062,2067],{},[94,2063,2064],{},[23,2065,2066],{},"Discovery",[94,2068,2069],{},"The search engine becomes aware that a URL exists.",[76,2071,2072,2077],{},[94,2073,2074],{},[23,2075,2076],{},"Crawling",[94,2078,2079],{},"A crawler requests and retrieves the URL.",[76,2081,2082,2087],{},[94,2083,2084],{},[23,2085,2086],{},"Rendering",[94,2088,2089],{},"When necessary, the crawler processes the page and its JavaScript-generated content.",[76,2091,2092,2097],{},[94,2093,2094],{},[23,2095,2096],{},"Indexing",[94,2098,2099],{},"Search systems analyze the content and decide whether and how it should enter the search index.",[76,2101,2102,2107],{},[94,2103,2104],{},[23,2105,2106],{},"Serving",[94,2108,2109],{},"Indexed information may be selected for relevant search results.",[16,2111,2112],{},"A page can therefore be discovered but not crawled, crawled but not indexed, or indexed without ranking prominently for a particular query.",[16,2114,2115],{},[205,2116,2117],{},"INTERNAL LINK: What Is Indexing in SEO?",[11,2119,2121],{"id":2120},"how-crawling-works","How Crawling Works",[16,2123,2124],{},"A simplified crawling sequence looks like this:",[16,2126,2127],{},[23,2128,2129],{},"URL discovered → crawling permissions checked → HTTP request → server response → content processed → links discovered → indexing systems",[16,2131,2132],{},"Suppose Googlebot already knows this page:",[16,2134,2135],{},[154,2136,2137],{},"https:\u002F\u002Fexample.com\u002Fblog\u002F",[16,2139,2140],{},"The page contains a standard HTML link:",[196,2142,2144],{"className":198,"code":2143,"language":200,"meta":201,"style":201},"\u003Ca href=\"\u002Fblog\u002Ftechnical-seo\u002F\">Technical SEO\u003C\u002Fa>\n",[154,2145,2146],{"__ignoreMap":201},[205,2147,2148,2150,2152,2154,2156,2159,2162,2164],{"class":207,"line":208},[205,2149,212],{"class":211},[205,2151,28],{"class":215},[205,2153,219],{"class":218},[205,2155,222],{"class":211},[205,2157,2158],{"class":225},"\"\u002Fblog\u002Ftechnical-seo\u002F\"",[205,2160,2161],{"class":211},">Technical SEO\u003C\u002F",[205,2163,28],{"class":215},[205,2165,234],{"class":211},[16,2167,2168,2169,2171,2172,2174,2175,34],{},"Google can extract that URL and add it to the URLs it may crawl. Google specifically recommends using crawlable ",[154,2170,275],{}," elements with an ",[154,2173,279],{}," attribute for links you want its crawlers to follow reliably. (",[28,2176,33],{"href":816,"rel":2177},[32],[16,2179,2180],{},"The crawler may then request:",[16,2182,2183],{},[154,2184,2185],{},"https:\u002F\u002Fexample.com\u002Fblog\u002Ftechnical-seo\u002F",[16,2187,2188,2189,2192,2193,2196,2197,2200,2201,257],{},"Your server might respond with ",[154,2190,2191],{},"200 OK",", a redirect such as ",[154,2194,2195],{},"301",", an error such as ",[154,2198,2199],{},"404",", or a server failure such as ",[154,2202,2203],{},"503",[16,2205,2206,2207,2210,2211,2214,2215,2218,2219,34],{},"A successful ",[154,2208,2209],{},"2xx"," response allows Google to pass the retrieved content into further processing, but even a successful response does not guarantee indexing. Persistent ",[154,2212,2213],{},"5xx"," errors and ",[154,2216,2217],{},"429 Too Many Requests"," responses can cause Google to reduce its crawling rate. (",[28,2220,33],{"href":2221,"rel":2222},"https:\u002F\u002Fdevelopers.google.com\u002Fcrawling\u002Fdocs\u002Ftroubleshooting\u002Fhttp-status-codes?authuser=19&utm_source=chatgpt.com",[32],[11,2224,2226],{"id":2225},"how-crawlers-find-urls","How Crawlers Find URLs",[16,2228,2229],{},"Search engines do not need you to submit every page manually.",[1128,2231,2233],{"id":2232},"internal-and-external-links","Internal and External Links",[16,2235,2236,2237,34],{},"Links are one of the primary discovery mechanisms. Google documents that Googlebot discovers new URLs mainly through links found on pages it already knows. (",[28,2238,33],{"href":2239,"rel":2240},"https:\u002F\u002Fdevelopers.google.com\u002Fsearch\u002Fdocs\u002Fcrawling-indexing\u002Fgooglebot?utm_source=chatgpt.com",[32],[16,2242,2243],{},"This makes internal linking part of technical SEO, not just navigation.",[16,2245,2246,2247,257],{},"An important page that has no crawlable links pointing to it may be harder for crawlers to discover. Such pages are commonly described as ",[23,2248,256],{},[16,2250,2251],{},[205,2252,262],{},[1128,2254,2256],{"id":2255},"xml-sitemaps","XML Sitemaps",[16,2258,2259],{},"An XML sitemap provides search engines with a structured list of URLs you consider relevant.",[16,2261,366],{},[196,2263,2265],{"className":369,"code":2264,"language":371,"meta":201,"style":201},"\u003Curl>\n  \u003Cloc>https:\u002F\u002Fexample.com\u002Fblog\u002Ftechnical-seo\u002F\u003C\u002Floc>\n\u003C\u002Furl>\n",[154,2266,2267,2271,2276],{"__ignoreMap":201},[205,2268,2269],{"class":207,"line":208},[205,2270,378],{},[205,2272,2273],{"class":207,"line":381},[205,2274,2275],{},"  \u003Cloc>https:\u002F\u002Fexample.com\u002Fblog\u002Ftechnical-seo\u002F\u003C\u002Floc>\n",[205,2277,2278],{"class":207,"line":387},[205,2279,396],{},[16,2281,2282,2283,2285,2286,1516,2289,2292,2293,34],{},"Google describes sitemap submission as a ",[23,2284,425],{},", not a command or guarantee that every listed URL will be crawled or indexed. A single sitemap is limited to ",[23,2287,2288],{},"50,000 URLs",[23,2290,2291],{},"50 MB uncompressed","; larger sites can use multiple sitemaps and a sitemap index. (",[28,2294,33],{"href":429,"rel":2295},[32],[16,2297,2298],{},[205,2299,438],{},[11,2301,2303],{"id":2302},"robotstxt-and-crawling","robots.txt and Crawling",[16,2305,2306,2307,2309],{},"A ",[154,2308,509],{}," file can tell compliant crawlers which URL paths they are allowed or disallowed to request.",[16,2311,366],{},[196,2313,2317],{"className":2314,"code":2315,"language":2316,"meta":201,"style":201},"language-txt shiki shiki-themes github-light github-dark","User-agent: *\nDisallow: \u002Fadmin\u002F\n","txt",[154,2318,2319,2324],{"__ignoreMap":201},[205,2320,2321],{"class":207,"line":208},[205,2322,2323],{},"User-agent: *\n",[205,2325,2326],{"class":207,"line":381},[205,2327,2328],{},"Disallow: \u002Fadmin\u002F\n",[16,2330,2331,2332,2335,2336,34],{},"The Robots Exclusion Protocol was standardized as ",[23,2333,2334],{},"RFC 9309"," in September 2022. The specification describes crawlers as automated clients and makes clear that robots.txt rules are not an access-control or authorization system. (",[28,2337,2340],{"href":2338,"rel":2339},"https:\u002F\u002Fwww.rfc-editor.org\u002Frfc\u002Frfc9309.html?utm_source=chatgpt.com",[32],"rfc-editor.org",[16,2342,2343],{},"That distinction matters.",[16,2345,2346],{},"If sensitive information must remain private, use authentication or another real access-control mechanism. Do not depend on robots.txt.",[1128,2348,2350],{"id":2349},"robotstxt-is-not-noindex","robots.txt Is Not noindex",[16,2352,2353],{},"A common SEO mistake is assuming:",[415,2355,2356],{},[16,2357,2358],{},"“If I block a URL in robots.txt, Google cannot index it.”",[16,2360,2361],{},"That is not reliably true.",[16,2363,2364,2365,2367,2368,34],{},"Google may discover a blocked URL through links and potentially show the URL in search results without crawling its content. Google therefore recommends ",[154,2366,532],{}," when the objective is to prevent an accessible page from appearing in Google Search. (",[28,2369,33],{"href":2370,"rel":2371},"https:\u002F\u002Fdevelopers.google.com\u002Fsearch\u002Fdocs\u002Fcrawling-indexing\u002Frobots\u002Fintro?authuser=1&utm_source=chatgpt.com",[32],[16,2373,2374,2375,2377],{},"There is an important catch: Google must be able to crawl the page to see its ",[154,2376,532],{}," directive.",[16,2379,2380],{},"So this combination can be counterproductive:",[196,2382,2384],{"className":2314,"code":2383,"language":2316,"meta":201,"style":201},"Disallow: \u002Fprivate-page\u002F\n",[154,2385,2386],{"__ignoreMap":201},[205,2387,2388],{"class":207,"line":208},[205,2389,2383],{},[16,2391,2392],{},"combined with:",[196,2394,2396],{"className":198,"code":2395,"language":200,"meta":201,"style":201},"\u003Cmeta name=\"robots\" content=\"noindex\">\n",[154,2397,2398],{"__ignoreMap":201},[205,2399,2400,2402,2405,2408,2410,2413,2416,2418,2421],{"class":207,"line":208},[205,2401,212],{"class":211},[205,2403,2404],{"class":215},"meta",[205,2406,2407],{"class":218}," name",[205,2409,222],{"class":211},[205,2411,2412],{"class":225},"\"robots\"",[205,2414,2415],{"class":218}," content",[205,2417,222],{"class":211},[205,2419,2420],{"class":225},"\"noindex\"",[205,2422,234],{"class":211},[16,2424,2425,2426,2428,2429,34],{},"If crawling is blocked, Googlebot may never retrieve the HTML containing the ",[154,2427,532],{}," instruction. (",[28,2430,33],{"href":536,"rel":2431},[32],[16,2433,2434],{},[205,2435,542],{},[11,2437,2439],{"id":2438},"javascript-and-rendering","JavaScript and Rendering",[16,2441,2442],{},"Modern websites may deliver only part of their meaningful content in the original HTML and generate the rest through JavaScript.",[16,2444,2445,2446,34],{},"Google documents that during its processing it can render pages and execute JavaScript using a recent version of Chrome. Rendering matters because content or links introduced by JavaScript may not exist in the initial HTML response. (",[28,2447,33],{"href":30,"rel":2448},[32],[16,2450,2451,2452,34],{},"However, JavaScript rendering does not remove the need for a technically crawlable website. Important links should still use standard link markup, essential resources should remain accessible, and developers should verify what Google actually receives and renders. (",[28,2453,33],{"href":816,"rel":2454},[32],[16,2456,2457],{},[205,2458,2459],{},"INTERNAL LINK: JavaScript SEO Basics",[11,2461,2463],{"id":2462},"crawl-budget","Crawl Budget",[16,2465,2466],{},"Search engines cannot continuously crawl every URL on the web.",[16,2468,2469,2470,2473,2474,2477,2478,34],{},"Google describes ",[23,2471,2472],{},"crawl budget"," as the URLs its crawling systems ",[795,2475,2476],{},"can and want to crawl",", based mainly on crawl capacity and crawl demand. (",[28,2479,33],{"href":2480,"rel":2481},"https:\u002F\u002Fdevelopers.google.com\u002Fcrawling\u002Fdocs\u002Fcrawl-budget?utm_source=chatgpt.com",[32],[16,2483,2484],{},"For most ordinary websites, crawl budget is not something that requires aggressive optimization.",[16,2486,2487],{},"Google’s current guidance is primarily aimed at very large or rapidly changing sites, including roughly:",[789,2489,2490,2497,2503],{},[649,2491,2492,2493,2496],{},"sites with ",[23,2494,2495],{},"1 million or more unique pages"," that change moderately often;",[649,2498,2492,2499,2502],{},[23,2500,2501],{},"10,000 or more unique pages"," that change very rapidly;",[649,2504,2505,2506,257],{},"sites with many URLs reported as ",[23,2507,2508],{},"Discovered – currently not indexed",[16,2510,2511,2512,34],{},"Google explicitly says these numbers are rough classifications rather than exact thresholds. (",[28,2513,33],{"href":2480,"rel":2514},[32],[16,2516,2517],{},"Large ecommerce sites, marketplaces, publishers, and sites with faceted navigation can create huge URL spaces through filters, sorting parameters, calendars, session IDs, or duplicates. In those situations, crawl efficiency becomes substantially more important.",[16,2519,2520],{},[205,2521,2522],{},"INTERNAL LINK: Crawl Budget Explained",[11,2524,2526],{"id":2525},"diagnosing-crawling-problems","Diagnosing Crawling Problems",[16,2528,2529],{},"If an important page is not appearing in search, first determine whether the problem is actually crawling.",[16,2531,2532,2533,2536,2537,34],{},"Check the URL with ",[23,2534,2535],{},"Google Search Console’s URL Inspection tool",". Google documents that it can show the current indexing status, test a live URL, request crawling, and provide information about loaded resources. (",[28,2538,33],{"href":2539,"rel":2540},"https:\u002F\u002Fdevelopers.google.com\u002Fsearch\u002Fdocs\u002Fmonitor-debug\u002Fsearch-console-start?utm_source=chatgpt.com",[32],[16,2542,2543],{},"Then investigate:",[646,2545,2546,2551,2556,2566,2578,2583,2589],{},[649,2547,2548,2550],{},[23,2549,2066],{}," — Is the page internally linked or included in the sitemap?",[649,2552,2553,2555],{},[23,2554,509],{}," — Is Googlebot accidentally blocked?",[649,2557,2558,2561,2562,2565],{},[23,2559,2560],{},"HTTP response"," — Does the URL return the expected ",[154,2563,2564],{},"200",", redirect, or error?",[649,2567,2568,2571,2572,1434,2575,2577],{},[23,2569,2570],{},"Server availability"," — Are DNS, network, timeout, ",[154,2573,2574],{},"429",[154,2576,2213],{}," errors occurring?",[649,2579,2580,2582],{},[23,2581,2086],{}," — Is important content available after JavaScript processing?",[649,2584,2585,2588],{},[23,2586,2587],{},"URL duplication"," — Are filters or parameters producing unnecessary URL variations?",[649,2590,2591,2594],{},[23,2592,2593],{},"Server logs"," — Has Googlebot actually requested the URL?",[16,2596,2597],{},"For crawler-level debugging, server access logs are especially valuable because they show what was actually requested rather than what you assume a crawler did.",[11,2599,1750],{"id":1749},[16,2601,2602,2605,2606,34],{},[23,2603,2604],{},"“A sitemap guarantees crawling.”","\nNo. Google calls sitemaps a hint. (",[28,2607,33],{"href":429,"rel":2608},[32],[16,2610,2611,2614,2615,34],{},[23,2612,2613],{},"“Crawled means indexed.”","\nNo. Crawled content still has to pass later processing and indexing decisions. (",[28,2616,33],{"href":2480,"rel":2617},[32],[16,2619,2620,2623,2624,34],{},[23,2621,2622],{},"“robots.txt removes pages from Google.”","\nNot necessarily. It primarily controls crawling. (",[28,2625,33],{"href":2370,"rel":2626},[32],[16,2628,2629,2632],{},[23,2630,2631],{},"“More crawling always means better SEO.”","\nNot necessarily. The objective is efficient access to useful, important URLs—not maximizing crawler requests.",[11,2634,690],{"id":689},[16,2636,2637,2638,2641],{},"For most websites, crawling should be treated as an ",[23,2639,2640],{},"access and architecture problem",", not something to manipulate.",[16,2643,2644],{},"Make important pages discoverable through standard internal links, maintain an accurate sitemap, return correct HTTP responses, avoid accidentally blocking required pages or resources, and keep unnecessary URL variations under control.",[16,2646,2647],{},"Then verify the result with Search Console and server logs.",[16,2649,2650],{},"Only invest heavily in crawl-budget optimization when the site's scale or URL-generation behavior provides a real reason to do so.",[11,2652,719],{"id":718},[721,2654,2656],{"id":2655},"can-a-page-rank-without-being-crawled","Can a Page Rank Without Being Crawled?",[16,2658,2659,2660,34],{},"Search engines generally need to retrieve content before they can fully process and index it. A blocked URL may sometimes appear as a URL-only result based on external information, but its content cannot be processed normally if the crawler cannot retrieve it. (",[28,2661,33],{"href":2370,"rel":2662},[32],[721,2664,2666],{"id":2665},"how-often-does-google-crawl-a-website","How Often Does Google Crawl a Website?",[16,2668,2669,2670,34],{},"There is no universal schedule. Googlebot algorithmically determines what to crawl, how frequently, and how many URLs to request while also trying to avoid overloading servers. (",[28,2671,33],{"href":30,"rel":2672},[32],[721,2674,2676],{"id":2675},"does-submitting-a-sitemap-make-google-crawl-faster","Does Submitting a Sitemap Make Google Crawl Faster?",[16,2678,2679,2680,34],{},"A sitemap can improve discovery, especially for new, updated, large, or difficult-to-discover URL sets, but submitting one does not guarantee immediate crawling. (",[28,2681,33],{"href":429,"rel":2682},[32],[721,2684,2686],{"id":2685},"should-every-page-be-crawlable","Should Every Page Be Crawlable?",[16,2688,2689],{},"No. Administrative URLs, duplicate URL combinations, internal search results, and other low-value URL spaces may reasonably be restricted depending on the site's architecture. Pages intended to appear in organic search, however, generally need to remain accessible to search crawlers.",[721,2691,2693],{"id":2692},"is-crawling-a-ranking-factor","Is Crawling a Ranking Factor?",[16,2695,2696],{},"Crawling is primarily a prerequisite for search systems to retrieve and process content. It should not be confused with a documented ranking signal. A page being crawled frequently does not by itself demonstrate that it will rank higher.",[11,2698,771],{"id":770},[16,2700,2701],{},"Crawling is the retrieval layer of search.",[16,2703,2704,2705,2707],{},"Search engine crawlers discover URLs, request them from servers, process the responses, and find additional URLs to explore. Good technical SEO makes that process predictable: important content is easy to discover and fetch, irrelevant URL spaces do not consume unnecessary resources, and directives such as robots.txt and ",[154,2706,532],{}," are used for their correct purposes.",[16,2709,2710],{},"If crawling fails, the rest of the search pipeline may never get the content it needs.",[11,2712,787],{"id":786},[646,2714,2715,2728,2740,2752,2765,2777,2789,2801,2814,2826],{},[649,2716,2717,2720,2721,1640,2725,34],{},[23,2718,2719],{},"Google Search Central — In-Depth Guide to How Google Search Works."," Google for Developers. ",[28,2722,2724],{"href":30,"rel":2723},[32],"How Google Search Works",[28,2726,33],{"href":30,"rel":2727},[32],[649,2729,2730,2720,2733,1640,2737,34],{},[23,2731,2732],{},"Google Search Central — Googlebot.",[28,2734,2736],{"href":2239,"rel":2735},[32],"Googlebot documentation",[28,2738,33],{"href":2239,"rel":2739},[32],[649,2741,2742,2720,2745,1640,2749,34],{},[23,2743,2744],{},"Google Crawling Infrastructure — Optimize Your Crawl Budget.",[28,2746,2748],{"href":2480,"rel":2747},[32],"Crawl budget documentation",[28,2750,33],{"href":2480,"rel":2751},[32],[649,2753,2754,2720,2757,1640,2762,34],{},[23,2755,2756],{},"Google Search Central — Introduction to robots.txt.",[28,2758,2761],{"href":2759,"rel":2760},"https:\u002F\u002Fdevelopers.google.com\u002Fsearch\u002Fdocs\u002Fcrawling-indexing\u002Frobots\u002Fintro?utm_source=chatgpt.com",[32],"robots.txt introduction",[28,2763,33],{"href":2370,"rel":2764},[32],[649,2766,2767,2770,2771,1640,2774,34],{},[23,2768,2769],{},"Koster, M.; Illyes, G.; Zeller, H.; Sassman, L. — RFC 9309: Robots Exclusion Protocol."," IETF, September 2022. ",[28,2772,2334],{"href":2338,"rel":2773},[32],[28,2775,2340],{"href":2338,"rel":2776},[32],[649,2778,2779,2720,2782,1640,2786,34],{},[23,2780,2781],{},"Google Search Central — Build and Submit a Sitemap.",[28,2783,2785],{"href":840,"rel":2784},[32],"Google sitemap documentation",[28,2787,33],{"href":429,"rel":2788},[32],[649,2790,2791,2720,2794,1640,2798,34],{},[23,2792,2793],{},"Google Search Central — Link Best Practices for Google.",[28,2795,2797],{"href":816,"rel":2796},[32],"Crawlable links documentation",[28,2799,33],{"href":816,"rel":2800},[32],[649,2802,2803,2720,2806,1640,2811,34],{},[23,2804,2805],{},"Google Crawling Infrastructure — How HTTP Status Codes Affect Google's Crawlers.",[28,2807,2810],{"href":2808,"rel":2809},"https:\u002F\u002Fdevelopers.google.com\u002Fcrawling\u002Fdocs\u002Ftroubleshooting\u002Fhttp-status-codes?utm_source=chatgpt.com",[32],"HTTP status code documentation",[28,2812,33],{"href":2221,"rel":2813},[32],[649,2815,2816,2720,2819,1640,2823,34],{},[23,2817,2818],{},"Google Search Central — Block Search Indexing with noindex.",[28,2820,2822],{"href":536,"rel":2821},[32],"noindex documentation",[28,2824,33],{"href":536,"rel":2825},[32],[649,2827,2828,2831,2832,1640,2837,34],{},[23,2829,2830],{},"Sitemaps.org — Sitemaps XML Format."," ",[28,2833,2836],{"href":2834,"rel":2835},"https:\u002F\u002Fwww.sitemaps.org\u002Fprotocol.html?utm_source=chatgpt.com",[32],"Sitemaps protocol",[28,2838,2840],{"href":2834,"rel":2839},[32],"sitemaps.org",[890,2842,892],{},{"title":201,"searchDepth":381,"depth":381,"links":2844},[2845,2846,2847,2848,2849,2853,2856,2857,2858,2859,2860,2861,2862,2863],{"id":1990,"depth":381,"text":1991},{"id":37,"depth":381,"text":38},{"id":2041,"depth":381,"text":2042},{"id":2120,"depth":381,"text":2121},{"id":2225,"depth":381,"text":2226,"children":2850},[2851,2852],{"id":2232,"depth":387,"text":2233},{"id":2255,"depth":387,"text":2256},{"id":2302,"depth":381,"text":2303,"children":2854},[2855],{"id":2349,"depth":387,"text":2350},{"id":2438,"depth":381,"text":2439},{"id":2462,"depth":381,"text":2463},{"id":2525,"depth":381,"text":2526},{"id":1749,"depth":381,"text":1750},{"id":689,"depth":381,"text":690},{"id":718,"depth":381,"text":719},{"id":770,"depth":381,"text":771},{"id":786,"depth":381,"text":787},"Learn what crawling means in SEO, how search engine bots discover and fetch URLs, how robots.txt, sitemaps and JavaScript affect crawling, and how to diagnose crawl problems.","\u002Fcrawling-in-seo.png","Explanation the Crawling in SEO",{},"\u002Fblog\u002Fen\u002Fcrawling-in-seo",{"title":1985,"description":2864},"crawling-in-seo","blog\u002Fen\u002Fcrawling-in-seo","-0T-w1i4uX-vbLamStXvvw7wZ2TSObcV4eByHkX9GoA",{"id":2874,"title":2875,"author":6,"body":2876,"category":4091,"description":4092,"draft":912,"extension":913,"featured":914,"image":4093,"imageAlt":4094,"locale":917,"meta":4095,"navigation":914,"path":4096,"publishedAt":920,"seo":4097,"slug":4098,"stem":4099,"translationKey":4098,"updatedAt":920,"__hash__":4100},"blog\u002Fblog\u002Fen\u002Fdocker-production.md","Docker for Production Web Applications: Practical Guide",{"type":8,"value":2877,"toc":4069},[2878,2882,2889,2892,2894,2897,2900,2904,2998,3002,3005,3013,3016,3208,3211,3222,3226,3229,3238,3241,3244,3253,3259,3264,3268,3271,3285,3296,3299,3303,3306,3317,3320,3347,3354,3360,3364,3371,3374,3430,3433,3436,3440,3447,3450,3457,3460,3465,3470,3473,3478,3482,3485,3505,3512,3523,3526,3541,3558,3561,3565,3568,3570,3593,3600,3603,3623,3626,3631,3635,3650,3653,3664,3667,3671,3674,3835,3854,3858,3865,3872,3876,3879,3882,3885,3890,3892,3895,3898,3903,3906,3909,3911,3915,3918,3922,3931,3938,3944,3948,3951,3959,3962,3964,3967,3970,3972,4066],[11,2879,2881],{"id":2880},"docker-for-production-web-applications","Docker for Production Web Applications",[16,2883,2884,2885,2888],{},"Docker can run production web applications reliably, but ",[154,2886,2887],{},"docker compose up -d"," is not, by itself, a production strategy. The difficult part is not starting containers. It is making sure those containers can be rebuilt predictably, survive failures, avoid exposing unnecessary privileges, preserve important data, stay within resource limits, produce usable logs, and be replaced safely during deployments.",[16,2890,2891],{},"For a small or medium web application on a single server, Docker Compose can be a perfectly reasonable production deployment model. Docker explicitly documents Compose for single-host production deployments. As infrastructure grows across multiple machines, however, scheduling, failover, service discovery, rolling deployments, and orchestration become separate architectural concerns.",[11,2893,38],{"id":37},[16,2895,2896],{},"Docker is suitable for production when containers are treated as disposable runtime units rather than miniature servers. Build immutable images, run applications with the least privilege they require, persist state outside the container layer, configure health checks and restart behavior, constrain CPU and memory, rotate or export logs, protect secrets, expose only necessary ports, and maintain tested backup and deployment procedures.",[16,2898,2899],{},"Docker provides most of these primitives. Production reliability comes from configuring them correctly.",[11,2901,2903],{"id":2902},"production-essentials","Production Essentials",[70,2905,2906,2916],{},[73,2907,2908],{},[76,2909,2910,2913],{},[79,2911,2912],{},"Area",[79,2914,2915],{},"Production expectation",[89,2917,2918,2926,2934,2942,2950,2958,2966,2974,2982,2990],{},[76,2919,2920,2923],{},[94,2921,2922],{},"Images",[94,2924,2925],{},"Reproducible, minimal and tested",[76,2927,2928,2931],{},[94,2929,2930],{},"Application",[94,2932,2933],{},"Stateless where practical",[76,2935,2936,2939],{},[94,2937,2938],{},"Security",[94,2940,2941],{},"Non-root, least privilege, controlled Docker access",[76,2943,2944,2947],{},[94,2945,2946],{},"Resources",[94,2948,2949],{},"CPU and memory limits",[76,2951,2952,2955],{},[94,2953,2954],{},"Networking",[94,2956,2957],{},"Only necessary ports exposed",[76,2959,2960,2963],{},[94,2961,2962],{},"State",[94,2964,2965],{},"Persistent volumes or external managed services",[76,2967,2968,2971],{},[94,2969,2970],{},"Reliability",[94,2972,2973],{},"Health checks and restart policies",[76,2975,2976,2979],{},[94,2977,2978],{},"Logs",[94,2980,2981],{},"Rotation or external aggregation",[76,2983,2984,2987],{},[94,2985,2986],{},"Secrets",[94,2988,2989],{},"Kept outside image layers",[76,2991,2992,2995],{},[94,2993,2994],{},"Deployment",[94,2996,2997],{},"Repeatable build, deploy and rollback process",[11,2999,3001],{"id":3000},"build-production-images","Build Production Images",[16,3003,3004],{},"A production image should contain what the application needs to run, not everything that was required to build it.",[16,3006,3007,3008,34],{},"Docker recommends multi-stage builds for separating compilers, development dependencies and build tooling from the final runtime image. Smaller runtime images generally contain fewer unnecessary dependencies and reduce the available attack surface. Docker also recommends trusted, minimal base images and periodically rebuilding images so updated dependencies can be incorporated. (",[28,3009,3012],{"href":3010,"rel":3011},"https:\u002F\u002Fdocs.docker.com\u002Fbuild\u002Fbuilding\u002Fbest-practices\u002F?utm_source=chatgpt.com",[32],"docs.docker.com",[16,3014,3015],{},"A typical pattern looks like this:",[196,3017,3021],{"className":3018,"code":3019,"language":3020,"meta":201,"style":201},"language-dockerfile shiki shiki-themes github-light github-dark","# syntax=docker\u002Fdockerfile:1\n\nFROM node:24-alpine AS build\n\nWORKDIR \u002Fapp\n\nCOPY package*.json .\u002F\nRUN npm ci\n\nCOPY . .\nRUN npm run build\n\n\nFROM node:24-alpine AS runtime\n\nWORKDIR \u002Fapp\n\nENV NODE_ENV=production\n\nCOPY package*.json .\u002F\nRUN npm ci --omit=dev && npm cache clean --force\n\nCOPY --from=build \u002Fapp\u002Fdist .\u002Fdist\n\nUSER node\n\nEXPOSE 3000\n\nHEALTHCHECK --interval=30s \\\n  --timeout=3s \\\n  --start-period=10s \\\n  --retries=3 \\\n  CMD wget -qO- http:\u002F\u002F127.0.0.1:3000\u002Fhealth || exit 1\n\nCMD [\"node\", \"dist\u002Fserver.js\"]\n","dockerfile",[154,3022,3023,3028,3033,3038,3042,3047,3051,3056,3061,3065,3070,3076,3081,3086,3092,3097,3102,3107,3113,3118,3123,3129,3134,3140,3145,3151,3156,3162,3167,3173,3179,3185,3191,3197,3202],{"__ignoreMap":201},[205,3024,3025],{"class":207,"line":208},[205,3026,3027],{},"# syntax=docker\u002Fdockerfile:1\n",[205,3029,3030],{"class":207,"line":381},[205,3031,3032],{"emptyLinePlaceholder":914},"\n",[205,3034,3035],{"class":207,"line":387},[205,3036,3037],{},"FROM node:24-alpine AS build\n",[205,3039,3040],{"class":207,"line":393},[205,3041,3032],{"emptyLinePlaceholder":914},[205,3043,3044],{"class":207,"line":1241},[205,3045,3046],{},"WORKDIR \u002Fapp\n",[205,3048,3049],{"class":207,"line":1252},[205,3050,3032],{"emptyLinePlaceholder":914},[205,3052,3053],{"class":207,"line":1700},[205,3054,3055],{},"COPY package*.json .\u002F\n",[205,3057,3058],{"class":207,"line":1712},[205,3059,3060],{},"RUN npm ci\n",[205,3062,3063],{"class":207,"line":1724},[205,3064,3032],{"emptyLinePlaceholder":914},[205,3066,3067],{"class":207,"line":1733},[205,3068,3069],{},"COPY . .\n",[205,3071,3073],{"class":207,"line":3072},11,[205,3074,3075],{},"RUN npm run build\n",[205,3077,3079],{"class":207,"line":3078},12,[205,3080,3032],{"emptyLinePlaceholder":914},[205,3082,3084],{"class":207,"line":3083},13,[205,3085,3032],{"emptyLinePlaceholder":914},[205,3087,3089],{"class":207,"line":3088},14,[205,3090,3091],{},"FROM node:24-alpine AS runtime\n",[205,3093,3095],{"class":207,"line":3094},15,[205,3096,3032],{"emptyLinePlaceholder":914},[205,3098,3100],{"class":207,"line":3099},16,[205,3101,3046],{},[205,3103,3105],{"class":207,"line":3104},17,[205,3106,3032],{"emptyLinePlaceholder":914},[205,3108,3110],{"class":207,"line":3109},18,[205,3111,3112],{},"ENV NODE_ENV=production\n",[205,3114,3116],{"class":207,"line":3115},19,[205,3117,3032],{"emptyLinePlaceholder":914},[205,3119,3121],{"class":207,"line":3120},20,[205,3122,3055],{},[205,3124,3126],{"class":207,"line":3125},21,[205,3127,3128],{},"RUN npm ci --omit=dev && npm cache clean --force\n",[205,3130,3132],{"class":207,"line":3131},22,[205,3133,3032],{"emptyLinePlaceholder":914},[205,3135,3137],{"class":207,"line":3136},23,[205,3138,3139],{},"COPY --from=build \u002Fapp\u002Fdist .\u002Fdist\n",[205,3141,3143],{"class":207,"line":3142},24,[205,3144,3032],{"emptyLinePlaceholder":914},[205,3146,3148],{"class":207,"line":3147},25,[205,3149,3150],{},"USER node\n",[205,3152,3154],{"class":207,"line":3153},26,[205,3155,3032],{"emptyLinePlaceholder":914},[205,3157,3159],{"class":207,"line":3158},27,[205,3160,3161],{},"EXPOSE 3000\n",[205,3163,3165],{"class":207,"line":3164},28,[205,3166,3032],{"emptyLinePlaceholder":914},[205,3168,3170],{"class":207,"line":3169},29,[205,3171,3172],{},"HEALTHCHECK --interval=30s \\\n",[205,3174,3176],{"class":207,"line":3175},30,[205,3177,3178],{},"  --timeout=3s \\\n",[205,3180,3182],{"class":207,"line":3181},31,[205,3183,3184],{},"  --start-period=10s \\\n",[205,3186,3188],{"class":207,"line":3187},32,[205,3189,3190],{},"  --retries=3 \\\n",[205,3192,3194],{"class":207,"line":3193},33,[205,3195,3196],{},"  CMD wget -qO- http:\u002F\u002F127.0.0.1:3000\u002Fhealth || exit 1\n",[205,3198,3200],{"class":207,"line":3199},34,[205,3201,3032],{"emptyLinePlaceholder":914},[205,3203,3205],{"class":207,"line":3204},35,[205,3206,3207],{},"CMD [\"node\", \"dist\u002Fserver.js\"]\n",[16,3209,3210],{},"This is an illustrative Node.js example rather than a universal Dockerfile. The important pattern is the separation between build and runtime stages, installation of production-only dependencies, execution as a non-root user, and an application-level health endpoint.",[16,3212,3213,3214,3217,3218,34],{},"Docker recommends using ",[154,3215,3216],{},"USER"," when a service does not require root privileges. (",[28,3219,3012],{"href":3220,"rel":3221},"https:\u002F\u002Fdocs.docker.com\u002Fbuild\u002Fbuilding\u002Fbest-practices\u002F",[32],[1128,3223,3225],{"id":3224},"pinning-images","Pinning Images",[16,3227,3228],{},"Image tags are mutable. An image such as:",[196,3230,3232],{"className":3018,"code":3231,"language":3020,"meta":201,"style":201},"FROM alpine:3.21\n",[154,3233,3234],{"__ignoreMap":201},[205,3235,3236],{"class":207,"line":208},[205,3237,3231],{},[16,3239,3240],{},"may resolve to a different underlying image after its publisher releases an update.",[16,3242,3243],{},"Docker supports pinning an image by digest:",[196,3245,3247],{"className":3018,"code":3246,"language":3020,"meta":201,"style":201},"FROM alpine:3.21@sha256:...\n",[154,3248,3249],{"__ignoreMap":201},[205,3250,3251],{"class":207,"line":208},[205,3252,3246],{},[16,3254,3255,3256,34],{},"This improves reproducibility because the same digest identifies the same image content. The tradeoff is important: strict digest pinning also means updates do not arrive automatically. A sensible production process combines controlled pinning with automated dependency-update checks rather than permanently freezing old images. (",[28,3257,3012],{"href":3220,"rel":3258},[32],[16,3260,3261],{},[205,3262,3263],{},"INTERNAL LINK: How Docker Images and Layers Work",[11,3265,3267],{"id":3266},"keep-secrets-out","Keep Secrets Out",[16,3269,3270],{},"Passwords, private tokens and credentials should never be baked into an image.",[16,3272,3273,3274,1516,3277,3280,3281,34],{},"Docker specifically warns against using Dockerfile ",[154,3275,3276],{},"ARG",[154,3278,3279],{},"ENV"," for build secrets because those values can persist in the resulting image or its metadata. BuildKit secret mounts make credentials temporarily available during a build without storing them in the final image. (",[28,3282,3012],{"href":3283,"rel":3284},"https:\u002F\u002Fdocs.docker.com\u002Freference\u002Fbuild-checks\u002Fsecrets-used-in-arg-or-env\u002F?utm_source=chatgpt.com",[32],[16,3286,3287,3288,3291,3292,34],{},"Docker Compose also supports runtime secrets. On Linux containers, those secrets can be mounted as files under ",[154,3289,3290],{},"\u002Frun\u002Fsecrets\u002F"," and granted only to services that require them. (",[28,3293,3012],{"href":3294,"rel":3295},"https:\u002F\u002Fdocs.docker.com\u002Fcompose\u002Fhow-tos\u002Fuse-secrets\u002F?utm_source=chatgpt.com",[32],[16,3297,3298],{},"The deeper principle is simple: configuration may change between environments, while the application image should not need to contain the credentials for those environments.",[11,3300,3302],{"id":3301},"limit-container-privileges","Limit Container Privileges",[16,3304,3305],{},"Containers provide isolation, but they are not an excuse to ignore host security.",[16,3307,3308,3309,3312,3313,34],{},"Access to the Docker daemon is especially sensitive. Docker's documentation warns that users capable of controlling the normal rootful Docker daemon can effectively obtain root-level capabilities on the host. Membership in the ",[154,3310,3311],{},"docker"," group therefore needs to be treated as privileged access. (",[28,3314,3012],{"href":3315,"rel":3316},"https:\u002F\u002Fdocs.docker.com\u002Fengine\u002Fsecurity\u002F?utm_source=chatgpt.com",[32],[16,3318,3319],{},"For web applications:",[789,3321,3322,3325,3332,3335,3338,3344],{},[649,3323,3324],{},"run the application as a non-root user when possible;",[649,3326,3327,3328,3331],{},"avoid ",[154,3329,3330],{},"privileged: true",";",[649,3333,3334],{},"drop capabilities the application does not require;",[649,3336,3337],{},"retain Docker's default seccomp protection unless there is a specific, understood reason to change it;",[649,3339,3340,3341,3331],{},"consider ",[154,3342,3343],{},"no-new-privileges",[649,3345,3346],{},"consider Rootless Docker where its operational limitations are acceptable.",[16,3348,3349,3350,34],{},"Docker's rootless mode runs both the daemon and containers without root privileges, reducing the impact of some daemon or runtime vulnerabilities. (",[28,3351,3012],{"href":3352,"rel":3353},"https:\u002F\u002Fdocs.docker.com\u002Fengine\u002Fsecurity\u002Frootless\u002F?utm_source=chatgpt.com",[32],[16,3355,3356,3357,34],{},"Docker also recommends removing unnecessary Linux capabilities rather than adding broad privileges. (",[28,3358,3012],{"href":3315,"rel":3359},[32],[11,3361,3363],{"id":3362},"control-cpu-and-memory","Control CPU and Memory",[16,3365,3366,3367,34],{},"A container has no resource constraints by default. Unless limits are configured, it can consume as much CPU or memory as the host allows. One runaway application can therefore affect other containers running on the same machine. (",[28,3368,3012],{"href":3369,"rel":3370},"https:\u002F\u002Fdocs.docker.com\u002Fengine\u002Fcontainers\u002Fresource_constraints\u002F?utm_source=chatgpt.com",[32],[16,3372,3373],{},"Compose supports controls such as:",[196,3375,3379],{"className":3376,"code":3377,"language":3378,"meta":201,"style":201},"language-yaml shiki shiki-themes github-light github-dark","services:\n  app:\n    image: registry.example.com\u002Fapp:1.4.0\n\n    cpus: 1.0\n    mem_limit: 512m\n","yaml",[154,3380,3381,3389,3396,3406,3410,3420],{"__ignoreMap":201},[205,3382,3383,3386],{"class":207,"line":208},[205,3384,3385],{"class":215},"services",[205,3387,3388],{"class":211},":\n",[205,3390,3391,3394],{"class":207,"line":381},[205,3392,3393],{"class":215},"  app",[205,3395,3388],{"class":211},[205,3397,3398,3401,3403],{"class":207,"line":387},[205,3399,3400],{"class":215},"    image",[205,3402,1280],{"class":211},[205,3404,3405],{"class":225},"registry.example.com\u002Fapp:1.4.0\n",[205,3407,3408],{"class":207,"line":393},[205,3409,3032],{"emptyLinePlaceholder":914},[205,3411,3412,3415,3417],{"class":207,"line":1241},[205,3413,3414],{"class":215},"    cpus",[205,3416,1280],{"class":211},[205,3418,3419],{"class":1277},"1.0\n",[205,3421,3422,3425,3427],{"class":207,"line":1252},[205,3423,3424],{"class":215},"    mem_limit",[205,3426,1280],{"class":211},[205,3428,3429],{"class":225},"512m\n",[16,3431,3432],{},"Those numbers should not be copied blindly. Measure normal workload, expected traffic, runtime memory behavior and failure conditions first. A PHP-FPM service, JVM application, Node.js process and PostgreSQL server can require very different limits.",[16,3434,3435],{},"The purpose of limits is isolation and predictable failure behavior, not simply making every container use less memory.",[11,3437,3439],{"id":3438},"persist-important-data","Persist Important Data",[16,3441,3442,3443,34],{},"The writable container filesystem is temporary. When the container is removed, data stored only in that writable layer disappears. (",[28,3444,3012],{"href":3445,"rel":3446},"https:\u002F\u002Fdocs.docker.com\u002Fengine\u002Fstorage?utm_source=chatgpt.com",[32],[16,3448,3449],{},"Persistent application data should instead live in Docker volumes, suitable bind mounts, object storage, or external database\u002Fstorage services.",[16,3451,3452,3453,34],{},"Docker describes volumes as its preferred mechanism for persistent container data in many scenarios. Volumes exist independently of an individual container and can be backed up, restored and migrated. (",[28,3454,3012],{"href":3455,"rel":3456},"https:\u002F\u002Fdocs.docker.com\u002Fengine\u002Fstorage\u002Fvolumes\u002F?utm_source=chatgpt.com",[32],[16,3458,3459],{},"That creates an important architectural distinction:",[16,3461,3462],{},[23,3463,3464],{},"Container = replaceable application runtime",[16,3466,3467],{},[23,3468,3469],{},"Volume or external service = persistent state",[16,3471,3472],{},"A volume alone is not a backup. Production systems still need scheduled backups and, more importantly, tested restoration procedures.",[16,3474,3475],{},[205,3476,3477],{},"INTERNAL LINK: Docker Volumes Explained",[11,3479,3481],{"id":3480},"health-and-recovery","Health and Recovery",[16,3483,3484],{},"A process can still be running while the application itself is unusable.",[16,3486,3487,3488,3491,3492,1405,3495,697,3498,478,3501,34],{},"Docker's ",[154,3489,3490],{},"HEALTHCHECK"," instruction allows an image to define a command that tests whether the application is actually functioning. Docker then exposes states such as ",[154,3493,3494],{},"starting",[154,3496,3497],{},"healthy",[154,3499,3500],{},"unhealthy",[28,3502,3012],{"href":3503,"rel":3504},"https:\u002F\u002Fdocs.docker.com\u002Freference\u002Fdockerfile?utm_source=chatgpt.com",[32],[16,3506,3507,3508,3511],{},"For a web service, ",[154,3509,3510],{},"\u002Fhealth"," might verify that the HTTP application can answer requests. More advanced readiness checks may also verify dependencies, although a health endpoint should avoid becoming so complex that a temporary external failure creates unnecessary restart loops.",[16,3513,3514,3515,3518,3519,34],{},"Compose can also wait for a dependency marked ",[154,3516,3517],{},"service_healthy"," before starting another service. (",[28,3520,3012],{"href":3521,"rel":3522},"https:\u002F\u002Fdocs.docker.com\u002Fcompose\u002Fhow-tos\u002Fstartup-order\u002F?utm_source=chatgpt.com",[32],[16,3524,3525],{},"Restart policies solve a related problem:",[196,3527,3529],{"className":3376,"code":3528,"language":3378,"meta":201,"style":201},"restart: unless-stopped\n",[154,3530,3531],{"__ignoreMap":201},[205,3532,3533,3536,3538],{"class":207,"line":208},[205,3534,3535],{"class":215},"restart",[205,3537,1280],{"class":211},[205,3539,3540],{"class":225},"unless-stopped\n",[16,3542,3543,3544,1405,3547,697,3550,3553,3554,34],{},"Docker documents ",[154,3545,3546],{},"always",[154,3548,3549],{},"unless-stopped",[154,3551,3552],{},"on-failure"," policies for automatically restarting containers after exits or daemon restarts. (",[28,3555,3012],{"href":3556,"rel":3557},"https:\u002F\u002Fdocs.docker.com\u002Fengine\u002Fcontainers\u002Fstart-containers-automatically\u002F?utm_source=chatgpt.com",[32],[16,3559,3560],{},"A restart policy improves recovery from process failure. It does not replace monitoring or fix an application that continuously crashes.",[11,3562,3564],{"id":3563},"control-network-exposure","Control Network Exposure",[16,3566,3567],{},"Published Docker ports require deliberate attention.",[16,3569,366],{},[196,3571,3575],{"className":3572,"code":3573,"language":3574,"meta":201,"style":201},"language-bash shiki shiki-themes github-light github-dark","docker run -p 3000:3000 myapp\n","bash",[154,3576,3577],{"__ignoreMap":201},[205,3578,3579,3581,3584,3587,3590],{"class":207,"line":208},[205,3580,3311],{"class":218},[205,3582,3583],{"class":225}," run",[205,3585,3586],{"class":1277}," -p",[205,3588,3589],{"class":225}," 3000:3000",[205,3591,3592],{"class":225}," myapp\n",[16,3594,3595,3596,34],{},"publishes the port on all host interfaces by default. Docker documentation explicitly notes that such published ports can become externally accessible. (",[28,3597,3012],{"href":3598,"rel":3599},"https:\u002F\u002Fdocs.docker.com\u002Freference\u002Fcli\u002Fdocker\u002Fcontainer\u002Frun?utm_source=chatgpt.com",[32],[16,3601,3602],{},"If a reverse proxy on the same server is the only service that should reach the application, binding to loopback can reduce unnecessary exposure:",[196,3604,3606],{"className":3376,"code":3605,"language":3378,"meta":201,"style":201},"ports:\n  - \"127.0.0.1:3000:3000\"\n",[154,3607,3608,3615],{"__ignoreMap":201},[205,3609,3610,3613],{"class":207,"line":208},[205,3611,3612],{"class":215},"ports",[205,3614,3388],{"class":211},[205,3616,3617,3620],{"class":207,"line":381},[205,3618,3619],{"class":211},"  - ",[205,3621,3622],{"class":225},"\"127.0.0.1:3000:3000\"\n",[16,3624,3625],{},"Databases, Redis instances and internal queues usually should not be publicly published merely because they run in Docker.",[16,3627,3628],{},[205,3629,3630],{},"INTERNAL LINK: Reverse Proxy Architecture Explained",[11,3632,3634],{"id":3633},"do-not-ignore-logs","Do Not Ignore Logs",[16,3636,3637,3638,3641,3642,3645,3646,34],{},"Docker's default ",[154,3639,3640],{},"json-file"," logging driver does not perform log rotation by default. A noisy application can therefore consume significant disk space over time. Docker recommends considering the ",[154,3643,3644],{},"local"," logging driver to help prevent disk exhaustion. (",[28,3647,3012],{"href":3648,"rel":3649},"https:\u002F\u002Fdocs.docker.com\u002Fengine\u002Flogging\u002Fconfigure\u002F?utm_source=chatgpt.com",[32],[16,3651,3652],{},"A production setup should deliberately choose between:",[789,3654,3655,3658,3661],{},[649,3656,3657],{},"local logs with rotation;",[649,3659,3660],{},"a logging driver sending logs elsewhere;",[649,3662,3663],{},"an external observability system.",[16,3665,3666],{},"Whatever method is selected, logs should survive long enough to investigate failures without eventually filling the server's disk.",[11,3668,3670],{"id":3669},"a-practical-compose-baseline","A Practical Compose Baseline",[16,3672,3673],{},"A hardened application service might begin with something like:",[196,3675,3677],{"className":3376,"code":3676,"language":3378,"meta":201,"style":201},"services:\n  app:\n    image: registry.example.com\u002Fmyapp:1.4.0\n    restart: unless-stopped\n\n    ports:\n      - \"127.0.0.1:3000:3000\"\n\n    cpus: 1.0\n    mem_limit: 512m\n\n    read_only: true\n\n    tmpfs:\n      - \u002Ftmp\n\n    security_opt:\n      - no-new-privileges:true\n\n    cap_drop:\n      - ALL\n\n    logging:\n      driver: local\n",[154,3678,3679,3685,3691,3700,3709,3713,3720,3727,3731,3739,3747,3751,3760,3764,3771,3778,3782,3789,3796,3800,3807,3814,3818,3825],{"__ignoreMap":201},[205,3680,3681,3683],{"class":207,"line":208},[205,3682,3385],{"class":215},[205,3684,3388],{"class":211},[205,3686,3687,3689],{"class":207,"line":381},[205,3688,3393],{"class":215},[205,3690,3388],{"class":211},[205,3692,3693,3695,3697],{"class":207,"line":387},[205,3694,3400],{"class":215},[205,3696,1280],{"class":211},[205,3698,3699],{"class":225},"registry.example.com\u002Fmyapp:1.4.0\n",[205,3701,3702,3705,3707],{"class":207,"line":393},[205,3703,3704],{"class":215},"    restart",[205,3706,1280],{"class":211},[205,3708,3540],{"class":225},[205,3710,3711],{"class":207,"line":1241},[205,3712,3032],{"emptyLinePlaceholder":914},[205,3714,3715,3718],{"class":207,"line":1252},[205,3716,3717],{"class":215},"    ports",[205,3719,3388],{"class":211},[205,3721,3722,3725],{"class":207,"line":1700},[205,3723,3724],{"class":211},"      - ",[205,3726,3622],{"class":225},[205,3728,3729],{"class":207,"line":1712},[205,3730,3032],{"emptyLinePlaceholder":914},[205,3732,3733,3735,3737],{"class":207,"line":1724},[205,3734,3414],{"class":215},[205,3736,1280],{"class":211},[205,3738,3419],{"class":1277},[205,3740,3741,3743,3745],{"class":207,"line":1733},[205,3742,3424],{"class":215},[205,3744,1280],{"class":211},[205,3746,3429],{"class":225},[205,3748,3749],{"class":207,"line":3072},[205,3750,3032],{"emptyLinePlaceholder":914},[205,3752,3753,3756,3758],{"class":207,"line":3078},[205,3754,3755],{"class":215},"    read_only",[205,3757,1280],{"class":211},[205,3759,1730],{"class":1277},[205,3761,3762],{"class":207,"line":3083},[205,3763,3032],{"emptyLinePlaceholder":914},[205,3765,3766,3769],{"class":207,"line":3088},[205,3767,3768],{"class":215},"    tmpfs",[205,3770,3388],{"class":211},[205,3772,3773,3775],{"class":207,"line":3094},[205,3774,3724],{"class":211},[205,3776,3777],{"class":225},"\u002Ftmp\n",[205,3779,3780],{"class":207,"line":3099},[205,3781,3032],{"emptyLinePlaceholder":914},[205,3783,3784,3787],{"class":207,"line":3104},[205,3785,3786],{"class":215},"    security_opt",[205,3788,3388],{"class":211},[205,3790,3791,3793],{"class":207,"line":3109},[205,3792,3724],{"class":211},[205,3794,3795],{"class":225},"no-new-privileges:true\n",[205,3797,3798],{"class":207,"line":3115},[205,3799,3032],{"emptyLinePlaceholder":914},[205,3801,3802,3805],{"class":207,"line":3120},[205,3803,3804],{"class":215},"    cap_drop",[205,3806,3388],{"class":211},[205,3808,3809,3811],{"class":207,"line":3125},[205,3810,3724],{"class":211},[205,3812,3813],{"class":225},"ALL\n",[205,3815,3816],{"class":207,"line":3131},[205,3817,3032],{"emptyLinePlaceholder":914},[205,3819,3820,3823],{"class":207,"line":3136},[205,3821,3822],{"class":215},"    logging",[205,3824,3388],{"class":211},[205,3826,3827,3830,3832],{"class":207,"line":3142},[205,3828,3829],{"class":215},"      driver",[205,3831,1280],{"class":211},[205,3833,3834],{"class":225},"local\n",[16,3836,3837,3838,3841,3842,3845,3846,3849,3850,34],{},"This is a starting point, not a universal template. ",[154,3839,3840],{},"read_only: true"," can break applications that expect writable directories, and dropping every capability can break software that genuinely needs one. Production hardening should therefore follow ",[23,3843,3844],{},"least privilege",", not ",[23,3847,3848],{},"maximum restriction regardless of application behavior",". Compose supports these service-level controls directly. (",[28,3851,3012],{"href":3852,"rel":3853},"https:\u002F\u002Fdocs.docker.com\u002Freference\u002Fcompose-file\u002Fservices\u002F?utm_source=chatgpt.com",[32],[11,3855,3857],{"id":3856},"common-production-mistakes","Common Production Mistakes",[16,3859,3860,3861,3864],{},"The most common Docker production problems are rarely caused by containers themselves. They usually come from deployment choices: running as root unnecessarily, using mutable ",[154,3862,3863],{},"latest"," tags without controlled updates, storing database data inside the container layer, publishing internal ports publicly, having no memory limit, placing credentials in images, allowing logs to grow indefinitely, or treating container restart as a substitute for monitoring.",[16,3866,3867,3868,34],{},"Another common mistake is mounting the application source directory from the host in production. Docker's production Compose guidance specifically suggests removing development-oriented code bind mounts so deployed application code remains inside the image. (",[28,3869,3012],{"href":3870,"rel":3871},"https:\u002F\u002Fdocs.docker.com\u002Fcompose\u002Fhow-tos\u002Fproduction\u002F?utm_source=chatgpt.com",[32],[11,3873,3875],{"id":3874},"when-compose-is-enough","When Compose Is Enough",[16,3877,3878],{},"Docker Compose is a reasonable production option when one host is sufficient and the team can tolerate that host as an infrastructure boundary.",[16,3880,3881],{},"A setup consisting of a reverse proxy, application containers, Redis and perhaps a database can remain operationally simple this way.",[16,3883,3884],{},"The requirements change when you need automatic scheduling across machines, node-level failover, large-scale service discovery, coordinated rolling deployments or extensive horizontal scaling. At that point the question is no longer whether Docker works in production. It is which orchestration platform should manage the containers.",[16,3886,3887],{},[205,3888,3889],{},"INTERNAL LINK: Docker Compose vs Container Orchestration",[11,3891,690],{"id":689},[16,3893,3894],{},"Treat Docker production deployment as a system rather than a Dockerfile.",[16,3896,3897],{},"The minimum useful production model is:",[16,3899,3900],{},[23,3901,3902],{},"source code → CI build and test → immutable image → registry → controlled deployment → health verification → monitoring → rollback",[16,3904,3905],{},"Keep persistent state outside replaceable application containers. Restrict privileges and exposed ports. Define resource limits based on measurement. Protect credentials independently from images. Automate backups and test restores.",[16,3907,3908],{},"Docker simplifies packaging. Production engineering is what makes that package reliable.",[11,3910,719],{"id":718},[721,3912,3914],{"id":3913},"is-docker-compose-safe-for-production","Is Docker Compose safe for production?",[16,3916,3917],{},"It can be. Docker officially documents Compose for production and single-host deployments. Whether it is appropriate depends on the application's availability, scaling and operational requirements.",[721,3919,3921],{"id":3920},"should-containers-run-as-root","Should containers run as root?",[16,3923,3924,3925,3927,3928,34],{},"Only when the application genuinely requires those privileges. Docker recommends using ",[154,3926,3216],{}," for services that can operate without root. (",[28,3929,3012],{"href":3220,"rel":3930},[32],[721,3932,3934,3935,3937],{"id":3933},"should-i-use-latest-in-production","Should I use ",[154,3936,3863],{}," in production?",[16,3939,3940,3941,34],{},"A mutable tag makes exact deployment reproduction harder. Versioned tags or digest pinning provide greater control, provided updates are actively maintained. (",[28,3942,3012],{"href":3220,"rel":3943},[32],[721,3945,3947],{"id":3946},"do-docker-volumes-need-backups","Do Docker volumes need backups?",[16,3949,3950],{},"Yes. Volumes provide persistence outside the container lifecycle; they do not automatically provide disaster recovery.",[721,3952,3954,3955,3958],{"id":3953},"does-restart-always-make-an-application-highly-available","Does ",[154,3956,3957],{},"restart: always"," make an application highly available?",[16,3960,3961],{},"No. It can restart a failed container on the same Docker host. It does not protect against host failure and does not diagnose why the application failed.",[11,3963,771],{"id":770},[16,3965,3966],{},"Docker is not production-ready because a container starts successfully. It becomes part of a production-ready system when images are reproducible, privileges and resources are controlled, state is protected, failures are detectable, logs are managed, network exposure is deliberate, and deployments can be recovered or rolled back.",[16,3968,3969],{},"The container is the replaceable part. The production architecture around it is what provides reliability.",[11,3971,787],{"id":786},[646,3973,3974,3984,3993,4001,4010,4019,4028,4037,4047,4056],{},[649,3975,3976,3977,1936,3980],{},"Docker — ",[795,3978,3979],{},"Building best practices",[28,3981,3983],{"href":3010,"rel":3982},[32],"Docker Build best practices",[649,3985,3976,3986,1936,3989],{},[795,3987,3988],{},"Use Compose in production",[28,3990,3992],{"href":3870,"rel":3991},[32],"Compose in production",[649,3994,3976,3995,1936,3998],{},[795,3996,3997],{},"Docker Engine security",[28,3999,3997],{"href":3315,"rel":4000},[32],[649,4002,3976,4003,1936,4006],{},[795,4004,4005],{},"Rootless mode",[28,4007,4009],{"href":3352,"rel":4008},[32],"Docker Rootless mode",[649,4011,3976,4012,1936,4015],{},[795,4013,4014],{},"Resource constraints",[28,4016,4018],{"href":3369,"rel":4017},[32],"Docker resource constraints",[649,4020,3976,4021,1936,4024],{},[795,4022,4023],{},"Configure logging drivers",[28,4025,4027],{"href":3648,"rel":4026},[32],"Docker logging drivers",[649,4029,3976,4030,1936,4033],{},[795,4031,4032],{},"Volumes",[28,4034,4036],{"href":3455,"rel":4035},[32],"Docker volumes",[649,4038,3976,4039,1936,4042],{},[795,4040,4041],{},"Build secrets",[28,4043,4046],{"href":4044,"rel":4045},"https:\u002F\u002Fdocs.docker.com\u002Fbuild\u002Fbuilding\u002Fsecrets\u002F?utm_source=chatgpt.com",[32],"Docker build secrets",[649,4048,3976,4049,1936,4052],{},[795,4050,4051],{},"Dockerfile reference",[28,4053,4051],{"href":4054,"rel":4055},"https:\u002F\u002Fdocs.docker.com\u002Freference\u002Fdockerfile\u002F?utm_source=chatgpt.com",[32],[649,4057,3976,4058,1936,4061],{},[795,4059,4060],{},"Port publishing and mapping",[28,4062,4065],{"href":4063,"rel":4064},"https:\u002F\u002Fdocs.docker.com\u002Fengine\u002Fnetwork\u002Fport-publishing\u002F?utm_source=chatgpt.com",[32],"Docker port publishing",[890,4067,4068],{},"html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .s9eBZ, html code.shiki .s9eBZ{--shiki-default:#22863A;--shiki-dark:#85E89D}html pre.shiki code .sVt8B, html code.shiki .sVt8B{--shiki-default:#24292E;--shiki-dark:#E1E4E8}html pre.shiki code .sZZnC, html code.shiki .sZZnC{--shiki-default:#032F62;--shiki-dark:#9ECBFF}html pre.shiki code .sj4cs, html code.shiki .sj4cs{--shiki-default:#005CC5;--shiki-dark:#79B8FF}html pre.shiki code .sScJk, html code.shiki .sScJk{--shiki-default:#6F42C1;--shiki-dark:#B392F0}",{"title":201,"searchDepth":381,"depth":381,"links":4070},[4071,4072,4073,4074,4077,4078,4079,4080,4081,4082,4083,4084,4085,4086,4087,4088,4089,4090],{"id":2880,"depth":381,"text":2881},{"id":37,"depth":381,"text":38},{"id":2902,"depth":381,"text":2903},{"id":3000,"depth":381,"text":3001,"children":4075},[4076],{"id":3224,"depth":387,"text":3225},{"id":3266,"depth":381,"text":3267},{"id":3301,"depth":381,"text":3302},{"id":3362,"depth":381,"text":3363},{"id":3438,"depth":381,"text":3439},{"id":3480,"depth":381,"text":3481},{"id":3563,"depth":381,"text":3564},{"id":3633,"depth":381,"text":3634},{"id":3669,"depth":381,"text":3670},{"id":3856,"depth":381,"text":3857},{"id":3874,"depth":381,"text":3875},{"id":689,"depth":381,"text":690},{"id":718,"depth":381,"text":719},{"id":770,"depth":381,"text":771},{"id":786,"depth":381,"text":787},"Web Development","Learn how to run Docker web applications in production with secure images, resource limits, persistent storage, health checks, logging, secrets and reliable deployment practices.","\u002Fdocker-web.png","Image of Docker",{},"\u002Fblog\u002Fen\u002Fdocker-production",{"title":2875,"description":4092},"docker-production","blog\u002Fen\u002Fdocker-production","DiW-Qq1mTWnO4SFF7Ls7ISnLtG7TJsbLoI2OaUyxDDo",{"id":4102,"title":4103,"author":6,"body":4104,"category":4933,"description":4934,"draft":912,"extension":913,"featured":914,"image":4935,"imageAlt":4936,"locale":917,"meta":4937,"navigation":914,"path":4938,"publishedAt":920,"seo":4939,"slug":4940,"stem":4941,"translationKey":4940,"updatedAt":920,"__hash__":4942},"blog\u002Fblog\u002Fen\u002Feligibility-audit.md","ChatGPT Search Eligibility Audit: Practical Checklist",{"type":8,"value":4105,"toc":4915},[4106,4110,4117,4131,4133,4136,4162,4168,4172,4269,4273,4284,4287,4302,4305,4332,4338,4359,4364,4368,4374,4389,4391,4416,4422,4432,4436,4439,4449,4456,4459,4475,4478,4497,4504,4508,4637,4647,4651,4654,4660,4670,4673,4678,4682,4688,4697,4704,4707,4711,4717,4720,4729,4731,4734,4739,4745,4748,4750,4754,4760,4764,4770,4774,4785,4789,4800,4804,4810,4812,4818,4821,4823,4912],[11,4107,4109],{"id":4108},"chatgpt-search-eligibility-audit-a-practical-checklist","ChatGPT Search Eligibility Audit: A Practical Checklist",[16,4111,4112,4113,4116],{},"A website can be technically healthy in Google and still be inaccessible to ChatGPT Search. The reason is simple: ChatGPT Search has its own crawler, ",[154,4114,4115],{},"OAI-SearchBot",", and your robots.txt, CDN, WAF, firewall, or bot-protection system can block it independently of Googlebot.",[16,4118,4119,4120,4122,4123,4125,4126,34],{},"OpenAI’s current guidance identifies two core technical requirements for search eligibility: allow ",[154,4121,4115],{}," to crawl the site, and make sure your hosting or CDN does not block traffic from OpenAI’s published SearchBot IP ranges. Passing those checks makes a site eligible to appear; it does ",[23,4124,412],{}," guarantee that ChatGPT will select or rank it for a particular query. (",[28,4127,4130],{"href":4128,"rel":4129},"https:\u002F\u002Fhelp.openai.com\u002Fen\u002Farticles\u002F9237897-chatgpt-search%3F.avif",[32],"help.openai.com",[11,4132,38],{"id":37},[16,4134,4135],{},"To audit a website for ChatGPT Search eligibility, verify that:",[646,4137,4138,4141,4146,4149,4152],{},[649,4139,4140],{},"the content is publicly reachable;",[649,4142,4143,4145],{},[154,4144,4115],{}," is not blocked by robots.txt;",[649,4147,4148],{},"your CDN, firewall, WAF, or bot protection accepts legitimate OAI-SearchBot traffic from OpenAI’s published IP ranges;",[649,4150,4151],{},"pages return usable HTTP responses rather than authentication, CAPTCHA, challenge, 403, or rate-limit barriers;",[649,4153,4154,4155,4158,4159,4161],{},"you have not confused ",[154,4156,4157],{},"GPTBot"," controls with ",[154,4160,4115],{}," controls.",[16,4163,4164,4165,34],{},"OpenAI says search placement uses multiple factors related to relevance and reliability, and placement is not guaranteed. Eligibility is therefore the first technical gate, not a ranking strategy. (",[28,4166,4130],{"href":4128,"rel":4167},[32],[11,4169,4171],{"id":4170},"eligibility-checklist","Eligibility Checklist",[70,4173,4174,4187],{},[73,4175,4176],{},[76,4177,4178,4181,4184],{},[79,4179,4180],{},"Check",[79,4182,4183],{},"Desired result",[79,4185,4186],{},"If it fails",[89,4188,4189,4200,4221,4232,4242,4258],{},[76,4190,4191,4194,4197],{},[94,4192,4193],{},"Public URL",[94,4195,4196],{},"Page loads without authentication",[94,4198,4199],{},"Make the intended public content reachable",[76,4201,4202,4206,4211],{},[94,4203,4204],{},[154,4205,509],{},[94,4207,4208,4210],{},[154,4209,4115],{}," can crawl the required paths",[94,4212,4213,4214,1358,4217,4220],{},"Correct the matching ",[154,4215,4216],{},"Allow",[154,4218,4219],{},"Disallow"," rules",[76,4222,4223,4226,4229],{},[94,4224,4225],{},"CDN \u002F WAF",[94,4227,4228],{},"Verified SearchBot traffic is accepted",[94,4230,4231],{},"Update bot rules or IP allowlists",[76,4233,4234,4236,4239],{},[94,4235,2560],{},[94,4237,4238],{},"Normal page response instead of 403\u002F429\u002Fchallenge",[94,4240,4241],{},"Inspect server, CDN and security logs",[76,4243,4244,4247,4252],{},[94,4245,4246],{},"Search vs training",[94,4248,4249,4250],{},"Search access controlled with ",[154,4251,4115],{},[94,4253,4254,4255,4257],{},"Do not use ",[154,4256,4157],{}," as the Search control",[76,4259,4260,4263,4266],{},[94,4261,4262],{},"Post-change check",[94,4264,4265],{},"Configuration remains accessible after propagation",[94,4267,4268],{},"Recheck logs after OpenAI systems refresh",[11,4270,4272],{"id":4271},"check-oai-searchbot","Check OAI-SearchBot",[16,4274,4275,4276,4278,4279,34],{},"OpenAI identifies ",[154,4277,4115],{}," as the crawler used to surface websites in ChatGPT search features. Its documentation explicitly recommends allowing the crawler in robots.txt and allowing requests from OpenAI’s published SearchBot IP ranges. (",[28,4280,4283],{"href":4281,"rel":4282},"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fbots",[32],"developers.openai.com",[16,4285,4286],{},"A minimal configuration is:",[196,4288,4290],{"className":2314,"code":4289,"language":2316,"meta":201,"style":201},"User-agent: OAI-SearchBot\nAllow: \u002F\n",[154,4291,4292,4297],{"__ignoreMap":201},[205,4293,4294],{"class":207,"line":208},[205,4295,4296],{},"User-agent: OAI-SearchBot\n",[205,4298,4299],{"class":207,"line":381},[205,4300,4301],{},"Allow: \u002F\n",[16,4303,4304],{},"If you want ChatGPT Search access but do not want your site crawled by GPTBot for potential model training, the two controls can be separated:",[196,4306,4308],{"className":2314,"code":4307,"language":2316,"meta":201,"style":201},"User-agent: OAI-SearchBot\nAllow: \u002F\n\nUser-agent: GPTBot\nDisallow: \u002F\n",[154,4309,4310,4314,4318,4322,4327],{"__ignoreMap":201},[205,4311,4312],{"class":207,"line":208},[205,4313,4296],{},[205,4315,4316],{"class":207,"line":381},[205,4317,4301],{},[205,4319,4320],{"class":207,"line":387},[205,4321,3032],{"emptyLinePlaceholder":914},[205,4323,4324],{"class":207,"line":393},[205,4325,4326],{},"User-agent: GPTBot\n",[205,4328,4329],{"class":207,"line":1241},[205,4330,4331],{},"Disallow: \u002F\n",[16,4333,4334,4335,34],{},"OpenAI documents these settings as independent. Allowing Search does not require allowing GPTBot. (",[28,4336,4283],{"href":4281,"rel":4337},[32],[16,4339,4340,4341,697,4343,4345,4346,4348,4349,4351,4352,4355,4356,34],{},"This distinction matters because ",[154,4342,4157],{},[154,4344,4115],{}," have different purposes. ",[154,4347,4157],{}," relates to crawling that may be used for training OpenAI’s generative AI foundation models. ",[154,4350,4115],{}," controls automatic crawling for Search. ",[154,4353,4354],{},"ChatGPT-User",", meanwhile, represents certain user-triggered visits and is not the crawler used to determine Search inclusion. (",[28,4357,4283],{"href":4281,"rel":4358},[32],[16,4360,4361],{},[205,4362,4363],{},"INTERNAL LINK: OAI-SearchBot Explained",[11,4365,4367],{"id":4366},"audit-robotstxt-carefully","Audit robots.txt Carefully",[16,4369,4370,4371,4373],{},"Do not only search your robots.txt file for the literal text ",[154,4372,4115],{},". Evaluate the rules that actually apply to it.",[16,4375,4376,4377,1516,4379,4381,4382,4385,4386,34],{},"The Robots Exclusion Protocol defines crawler rules through user-agent groups and ",[154,4378,4216],{},[154,4380,4219],{}," path rules. When no specific group matches a crawler, a ",[154,4383,4384],{},"User-agent: *"," group may apply. More-specific path rules take precedence over less-specific matching rules. (",[28,4387,2340],{"href":2338,"rel":4388},[32],[16,4390,366],{},[196,4392,4394],{"className":2314,"code":4393,"language":2316,"meta":201,"style":201},"User-agent: *\nDisallow: \u002F\n\nUser-agent: OAI-SearchBot\nAllow: \u002F\n",[154,4395,4396,4400,4404,4408,4412],{"__ignoreMap":201},[205,4397,4398],{"class":207,"line":208},[205,4399,2323],{},[205,4401,4402],{"class":207,"line":381},[205,4403,4331],{},[205,4405,4406],{"class":207,"line":387},[205,4407,3032],{"emptyLinePlaceholder":914},[205,4409,4410],{"class":207,"line":393},[205,4411,4296],{},[205,4413,4414],{"class":207,"line":1241},[205,4415,4301],{},[16,4417,4418,4419,4421],{},"A dedicated ",[154,4420,4115],{}," group can therefore express a different policy from the general crawler policy.",[16,4423,4424,4425,4428,4429,34],{},"Also verify that ",[154,4426,4427],{},"\u002Frobots.txt"," itself works reliably. RFC 9309 distinguishes an unavailable robots file from one that is unreachable because of server or network errors. A persistent 5xx or connectivity problem can therefore have very different consequences from simply having no robots file. (",[28,4430,2340],{"href":2338,"rel":4431},[32],[11,4433,4435],{"id":4434},"check-the-infrastructure-layer","Check the Infrastructure Layer",[16,4437,4438],{},"A correct robots.txt does not prove that OpenAI can actually fetch the page.",[16,4440,4441,4442,4445,4446,34],{},"OpenAI specifically tells publishers to confirm that their host or CDN accepts traffic from its published SearchBot IP addresses. The current ranges are maintained in OpenAI’s ",[154,4443,4444],{},"searchbot.json"," file rather than being a fixed list you should copy permanently into documentation. (",[28,4447,4130],{"href":4128,"rel":4448},[32],[16,4450,4451,4452,34],{},"This matters when a site uses Cloudflare, Akamai, a managed WAF, custom firewall rules, rate limiting, or anti-bot systems. OpenAI notes that crawler traffic can be blocked by 403 responses, automated bot mitigation, JavaScript challenges, CAPTCHAs, authentication checks, or rate limiting. (",[28,4453,4130],{"href":4454,"rel":4455},"https:\u002F\u002Fhelp.openai.com\u002Fen\u002Farticles\u002F20001243-advertiser-guidance-for-allowing-openai-web-crawlers",[32],[16,4457,4458],{},"A useful server-side audit therefore checks both:",[196,4460,4462],{"className":3572,"code":4461,"language":3574,"meta":201,"style":201},"curl -I https:\u002F\u002Fexample.com\u002Fpage\n",[154,4463,4464],{"__ignoreMap":201},[205,4465,4466,4469,4472],{"class":207,"line":208},[205,4467,4468],{"class":218},"curl",[205,4470,4471],{"class":1277}," -I",[205,4473,4474],{"class":225}," https:\u002F\u002Fexample.com\u002Fpage\n",[16,4476,4477],{},"and:",[196,4479,4481],{"className":3572,"code":4480,"language":3574,"meta":201,"style":201},"curl -A \"OAI-SearchBot\" -I https:\u002F\u002Fexample.com\u002Fpage\n",[154,4482,4483],{"__ignoreMap":201},[205,4484,4485,4487,4490,4493,4495],{"class":207,"line":208},[205,4486,4468],{"class":218},[205,4488,4489],{"class":1277}," -A",[205,4491,4492],{"class":225}," \"OAI-SearchBot\"",[205,4494,4471],{"class":1277},[205,4496,4474],{"class":225},[16,4498,4499,4500,4503],{},"The second request can expose user-agent-based application rules, but it is ",[23,4501,4502],{},"not proof that genuine OpenAI traffic is allowed",". Your request does not originate from an OpenAI SearchBot IP. Confirm the real infrastructure behavior through CDN\u002FWAF configuration and logs using OpenAI’s published IP ranges.",[11,4505,4507],{"id":4506},"diagnose-failed-access","Diagnose Failed Access",[70,4509,4510,4529],{},[73,4511,4512],{},[76,4513,4514,4517,4520,4523,4526],{},[79,4515,4516],{},"Symptom",[79,4518,4519],{},"Measure",[79,4521,4522],{},"Likely cause",[79,4524,4525],{},"Confirmation",[79,4527,4528],{},"Fix",[89,4530,4531,4550,4569,4586,4603,4620],{},[76,4532,4533,4538,4541,4544,4547],{},[94,4534,4535,4537],{},[154,4536,4115],{}," never reaches pages",[94,4539,4540],{},"CDN\u002FWAF logs",[94,4542,4543],{},"Edge-level block",[94,4545,4546],{},"Check rejected bot\u002FIP events",[94,4548,4549],{},"Allow verified SearchBot traffic",[76,4551,4552,4557,4560,4563,4566],{},[94,4553,4554,4556],{},[154,4555,4427],{}," is fetched but pages are not",[94,4558,4559],{},"robots.txt rules",[94,4561,4562],{},"Crawl restriction",[94,4564,4565],{},"Evaluate matching user-agent group",[94,4567,4568],{},"Correct rules",[76,4570,4571,4574,4577,4580,4583],{},[94,4572,4573],{},"Requests receive 403",[94,4575,4576],{},"HTTP\u002Fserver logs",[94,4578,4579],{},"Firewall or bot protection",[94,4581,4582],{},"Inspect security event",[94,4584,4585],{},"Adjust WAF policy",[76,4587,4588,4591,4594,4597,4600],{},[94,4589,4590],{},"Requests receive 429",[94,4592,4593],{},"Rate-limit logs",[94,4595,4596],{},"Automated throttling",[94,4598,4599],{},"Match timestamps and crawler traffic",[94,4601,4602],{},"Tune legitimate-bot limits",[76,4604,4605,4608,4611,4614,4617],{},[94,4606,4607],{},"Browser works, crawler fails",[94,4609,4610],{},"Challenge\u002FCAPTCHA behavior",[94,4612,4613],{},"Human-verification layer",[94,4615,4616],{},"Reproduce bot request path",[94,4618,4619],{},"Exempt legitimate crawler",[76,4621,4622,4625,4628,4631,4634],{},[94,4623,4624],{},"Config was just changed",[94,4626,4627],{},"Time since robots update",[94,4629,4630],{},"Systems have not refreshed",[94,4632,4633],{},"Recheck later",[94,4635,4636],{},"Allow propagation",[16,4638,4639,4640,4643,4644,34],{},"OpenAI notes that Search systems may take approximately ",[23,4641,4642],{},"24 hours after a robots.txt update"," to adjust. That is an operational estimate, not a promise that the page will appear in search after 24 hours. (",[28,4645,4283],{"href":4281,"rel":4646},[32],[11,4648,4650],{"id":4649},"eligibility-is-not-ranking","Eligibility Is Not Ranking",[16,4652,4653],{},"A successful audit establishes crawl eligibility. It does not establish visibility.",[16,4655,4656,4657,34],{},"OpenAI says ChatGPT Search ranks results using multiple factors intended to help users find relevant and reliable information, and explicitly states that placement is not guaranteed. OpenAI has not publicly documented a complete Search ranking algorithm or a fixed set of ranking-factor weights. (",[28,4658,4130],{"href":4128,"rel":4659},[32],[16,4661,4662,4663,4665,4666,4669],{},"This means several commonly discussed tactics should not be misrepresented as formal ChatGPT Search eligibility requirements. OpenAI’s current public eligibility guidance does ",[23,4664,412],{}," list XML sitemaps, ",[154,4667,4668],{},"llms.txt",", schema markup, GPTBot permission, or a special “AI SEO” meta tag as mandatory conditions for Search inclusion.",[16,4671,4672],{},"Those technologies may have other legitimate uses, but they should not be presented as requirements without supporting evidence.",[16,4674,4675],{},[205,4676,4677],{},"INTERNAL LINK: ChatGPT Search vs Traditional Search",[11,4679,4681],{"id":4680},"measure-real-traffic","Measure Real Traffic",[16,4683,4684,4685,4687],{},"Publishers that allow ",[154,4686,4115],{}," can also look for downstream evidence in analytics. OpenAI states that ChatGPT referral URLs automatically include:",[196,4689,4691],{"className":2314,"code":4690,"language":2316,"meta":201,"style":201},"utm_source=chatgpt.com\n",[154,4692,4693],{"__ignoreMap":201},[205,4694,4695],{"class":207,"line":208},[205,4696,4690],{},[16,4698,4699,4700,34],{},"This makes referral traffic from ChatGPT easier to isolate in analytics platforms. (",[28,4701,4130],{"href":4702,"rel":4703},"https:\u002F\u002Fhelp.openai.com\u002Fen\u002Farticles\u002F12627856-publishers-and-developers-faq%23%3A~%3Atext%3DChatGPT%2520automatically%2520includes%2520the%2520UTM%2520parameter%2520utm_source%253Dchatgpt.com%2520in%2520referral%2520URLs%252C%2520enabling%2520clear%2520tracking%2520and%2520analysis%2520of%2520inbound%2520traffic%2520from%2520ChatGPT%2520search%2520results.",[32],[16,4705,4706],{},"Referral traffic and crawler logs answer different questions. Logs tell you whether OpenAI can reach the site. Referral data tells you whether users actually clicked through from ChatGPT. Neither alone proves how often a page was considered, ranked, quoted, or omitted.",[11,4708,4710],{"id":4709},"common-mistakes","Common Mistakes",[16,4712,4713,4714,4716],{},"The most important mistake is treating ChatGPT Search access as identical to Google indexing. It is not. A website can permit Googlebot while blocking ",[154,4715,4115],{}," at robots.txt or infrastructure level.",[16,4718,4719],{},"Another mistake is allowing the user agent in robots.txt while a WAF silently rejects the same crawler. The reverse can also happen: the network permits the request, but robots.txt says not to crawl the content.",[16,4721,4722,4723,4725,4726,34],{},"Finally, blocking ",[154,4724,4157],{}," does not automatically opt a site out of ChatGPT Search. OpenAI intentionally separates the training and search controls. (",[28,4727,4283],{"href":4281,"rel":4728},[32],[11,4730,690],{"id":689},[16,4732,4733],{},"Treat the audit as two separate gates:",[16,4735,4736],{},[23,4737,4738],{},"Crawler policy → infrastructure access.",[16,4740,4741,4742,4744],{},"First establish that ",[154,4743,4115],{}," is permitted by robots.txt. Then establish that a legitimate request from OpenAI’s published SearchBot infrastructure can actually reach the page without security or application barriers.",[16,4746,4747],{},"Only after these checks pass should you investigate content relevance, authority, page quality, entity clarity, or other visibility questions. Otherwise, you may spend time “optimizing for ChatGPT” while the crawler cannot reliably access the site at all.",[11,4749,719],{"id":718},[1128,4751,4753],{"id":4752},"does-allowing-oai-searchbot-guarantee-chatgpt-visibility","Does allowing OAI-SearchBot guarantee ChatGPT visibility?",[16,4755,4756,4757,34],{},"No. It establishes eligibility for crawling and inclusion, but OpenAI says placement is not guaranteed. (",[28,4758,4130],{"href":4128,"rel":4759},[32],[721,4761,4763],{"id":4762},"do-i-need-to-allow-gptbot","Do I need to allow GPTBot?",[16,4765,4766,4767,34],{},"Not for ChatGPT Search eligibility. OpenAI documents GPTBot and OAI-SearchBot as independent controls. (",[28,4768,4283],{"href":4281,"rel":4769},[32],[721,4771,4773],{"id":4772},"can-i-block-training-but-allow-search","Can I block training but allow Search?",[16,4775,4776,4777,4779,4780,478,4782,34],{},"Yes. You can allow ",[154,4778,4115],{}," while disallowing ",[154,4781,4157],{},[28,4783,4283],{"href":4281,"rel":4784},[32],[721,4786,4788],{"id":4787},"should-i-hard-code-searchbot-ip-addresses","Should I hard-code SearchBot IP addresses?",[16,4790,4791,4792,4794,4795,34],{},"Prefer OpenAI’s published ",[154,4793,4444],{}," as the source of truth because crawler infrastructure can change. (",[28,4796,4799],{"href":4797,"rel":4798},"https:\u002F\u002Fopenai.com\u002Fsearchbot.json",[32],"openai.com",[721,4801,4803],{"id":4802},"how-quickly-do-robotstxt-changes-apply","How quickly do robots.txt changes apply?",[16,4805,4806,4807,34],{},"OpenAI says its Search systems may take approximately 24 hours to adjust after a robots.txt update. (",[28,4808,4283],{"href":4281,"rel":4809},[32],[11,4811,771],{"id":770},[16,4813,4814,4815],{},"A ChatGPT Search eligibility audit is primarily an access audit. The essential question is not “Have we added enough AI SEO markup?” It is: ",[23,4816,4817],{},"Can OAI-SearchBot legally and technically reach the content?",[16,4819,4820],{},"Check robots.txt, verify OpenAI’s current SearchBot IP ranges against your infrastructure policy, inspect WAF and server responses, keep GPTBot controls separate, and measure both crawler activity and referral traffic. Once those foundations work, search visibility becomes a relevance and selection problem rather than an access problem.",[11,4822,787],{"id":786},[646,4824,4825,4839,4853,4867,4881,4895],{},[649,4826,4827,4830,4831,1640,4836,34],{},[23,4828,4829],{},"OpenAI — “Searching the web with ChatGPT.”"," Updated August 2026. Eligibility guidance, ranking disclaimer, and SearchBot infrastructure requirement. ",[28,4832,4835],{"href":4833,"rel":4834},"https:\u002F\u002Fhelp.openai.com\u002Fen\u002Farticles\u002F9237897?utm_source=chatgpt.com",[32],"OpenAI: Searching the web with ChatGPT",[28,4837,4130],{"href":4128,"rel":4838},[32],[649,4840,4841,4844,4845,1640,4850,34],{},[23,4842,4843],{},"OpenAI — “Overview of OpenAI Crawlers.”"," Current developer documentation. Definitions and controls for OAI-SearchBot, GPTBot and ChatGPT-User; approximately 24-hour robots.txt adjustment note. ",[28,4846,4849],{"href":4847,"rel":4848},"https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fbots?utm_source=chatgpt.com",[32],"OpenAI Crawlers documentation",[28,4851,4283],{"href":4281,"rel":4852},[32],[649,4854,4855,4858,4859,1640,4864,34],{},[23,4856,4857],{},"OpenAI — “Publishers and Developers – FAQ.”"," Updated August 2026. Publisher discovery guidance and ChatGPT referral tracking. ",[28,4860,4863],{"href":4861,"rel":4862},"https:\u002F\u002Fhelp.openai.com\u002Fen\u002Farticles\u002F12627856-publishers-and-developers-faq?utm_source=chatgpt.com",[32],"OpenAI Publishers and Developers FAQ",[28,4865,4130],{"href":4702,"rel":4866},[32],[649,4868,4869,4872,4873,1640,4878,34],{},[23,4870,4871],{},"OpenAI — SearchBot published IP ranges."," Current machine-readable source for OAI-SearchBot network prefixes. ",[28,4874,4877],{"href":4875,"rel":4876},"https:\u002F\u002Fopenai.com\u002Fsearchbot.json?utm_source=chatgpt.com",[32],"OpenAI searchbot.json",[28,4879,4799],{"href":4797,"rel":4880},[32],[649,4882,4883,4886,4887,1640,4892,34],{},[23,4884,4885],{},"OpenAI — “Advertiser Guidance for Allowing OpenAI Web Crawlers.”"," Updated September 20, 2026. Practical crawler troubleshooting covering WAFs, CDNs, bot protection, CAPTCHAs, 403 responses and rate limiting. ",[28,4888,4891],{"href":4889,"rel":4890},"https:\u002F\u002Fhelp.openai.com\u002Fen\u002Farticles\u002F20001243-advertiser-guidance-for-allowing-openai-web-crawlers?utm_source=chatgpt.com",[32],"OpenAI crawler troubleshooting guidance",[28,4893,4130],{"href":4454,"rel":4894},[32],[649,4896,4897,4900,4901,1358,4903,4905,4906,1640,4909,34],{},[23,4898,4899],{},"IETF — RFC 9309: Robots Exclusion Protocol."," September 2022. Standards-track definition of robots.txt parsing, user-agent matching, ",[154,4902,4216],{},[154,4904,4219],{},", access behavior and caching. ",[28,4907,2334],{"href":2338,"rel":4908},[32],[28,4910,2340],{"href":2338,"rel":4911},[32],[890,4913,4914],{},"html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sScJk, html code.shiki .sScJk{--shiki-default:#6F42C1;--shiki-dark:#B392F0}html pre.shiki code .sj4cs, html code.shiki .sj4cs{--shiki-default:#005CC5;--shiki-dark:#79B8FF}html pre.shiki code .sZZnC, html code.shiki .sZZnC{--shiki-default:#032F62;--shiki-dark:#9ECBFF}",{"title":201,"searchDepth":381,"depth":381,"links":4916},[4917,4918,4919,4920,4921,4922,4923,4924,4925,4926,4927,4928,4931,4932],{"id":4108,"depth":381,"text":4109},{"id":37,"depth":381,"text":38},{"id":4170,"depth":381,"text":4171},{"id":4271,"depth":381,"text":4272},{"id":4366,"depth":381,"text":4367},{"id":4434,"depth":381,"text":4435},{"id":4506,"depth":381,"text":4507},{"id":4649,"depth":381,"text":4650},{"id":4680,"depth":381,"text":4681},{"id":4709,"depth":381,"text":4710},{"id":689,"depth":381,"text":690},{"id":718,"depth":381,"text":719,"children":4929},[4930],{"id":4752,"depth":387,"text":4753},{"id":770,"depth":381,"text":771},{"id":786,"depth":381,"text":787},"AI","Audit your website for ChatGPT Search eligibility. Check OAI-SearchBot, robots.txt, OpenAI IP ranges, CDN\u002FWAF access, HTTP responses and common crawler blocks.","\u002Fchatchpt-audit.png","Image of Eligibility Audit",{},"\u002Fblog\u002Fen\u002Feligibility-audit",{"title":4103,"description":4934},"eligibility-audit","blog\u002Fen\u002Feligibility-audit","YoyJOM7665oOAnSOgVvCqn-pQeBisgI_crB-_bMymlI",{"id":4944,"title":4945,"author":6,"body":4946,"category":4091,"description":5680,"draft":912,"extension":913,"featured":914,"image":5681,"imageAlt":5682,"locale":917,"meta":5683,"navigation":914,"path":5684,"publishedAt":920,"seo":5685,"slug":5001,"stem":5686,"translationKey":5687,"updatedAt":920,"__hash__":5688},"blog\u002Fblog\u002Fen\u002Fipv4-vs-ipv6.md","IPv4 vs IPv6: What Modern Websites Need to Know",{"type":8,"value":4947,"toc":5664},[4948,4952,4967,4978,4980,4992,4999,5003,5105,5112,5116,5119,5122,5145,5148,5154,5165,5170,5179,5193,5196,5202,5205,5209,5212,5215,5226,5229,5235,5238,5241,5245,5248,5251,5277,5283,5286,5291,5294,5298,5301,5308,5311,5317,5320,5325,5328,5333,5338,5342,5345,5352,5355,5358,5362,5368,5371,5377,5380,5405,5408,5423,5426,5440,5443,5450,5456,5458,5464,5467,5473,5475,5482,5489,5492,5495,5497,5501,5509,5513,5516,5520,5527,5531,5539,5543,5546,5548,5551,5554,5557,5559,5661],[11,4949,4951],{"id":4950},"ipv4-vs-ipv6-for-modern-websites","IPv4 vs IPv6 for Modern Websites",[16,4953,4954,4955,4958,4959,4962,4963,34],{},"IPv4 and IPv6 do the same fundamental job: they let packets travel between devices across IP networks. The important difference is that IPv4 uses ",[23,4956,4957],{},"32-bit addresses",", while IPv6 uses ",[23,4960,4961],{},"128-bit addresses"," and was designed as IPv4’s successor. That larger address space solves the long-term addressing limitation that has shaped much of today’s Internet infrastructure. (",[28,4964,2340],{"href":4965,"rel":4966},"https:\u002F\u002Fwww.rfc-editor.org\u002Finfo\u002Frfc791\u002F?utm_source=chatgpt.com",[32],[16,4968,4969,4970,4973,4974,4977],{},"For a modern website, however, the practical question is rarely ",[23,4971,4972],{},"“IPv4 or IPv6?”"," The better question is ",[23,4975,4976],{},"“Can users reliably reach the site over both?”"," In most public web deployments, supporting both protocols—directly or through a CDN, reverse proxy, or hosting platform—is the safest transition strategy.",[11,4979,38],{"id":37},[16,4981,4982,4983,4986,4987,34],{},"IPv4 is still widely used and should not normally be removed from a public website simply because IPv6 is available. IPv6 is the long-term successor to IPv4 and is already a significant part of Internet traffic: Cloudflare Radar currently reports roughly ",[23,4984,4985],{},"41% of HTTP requests"," on its worldwide network using IPv6, although that percentage varies significantly by network and country. (",[28,4988,4991],{"href":4989,"rel":4990},"https:\u002F\u002Fradar.cloudflare.com\u002F?utm_source=chatgpt.com",[32],"radar.cloudflare.com",[16,4993,4994,4995,4998],{},"For most websites, ",[23,4996,4997],{},"dual-stack connectivity","—making the site reachable through both IPv4 and IPv6—is the practical choice. Modern clients can then select an appropriate working path.",[11,5000,5002],{"id":5001},"ipv4-vs-ipv6","IPv4 vs IPv6",[70,5004,5005,5018],{},[73,5006,5007],{},[76,5008,5009,5012,5015],{},[79,5010,5011],{},"Characteristic",[79,5013,5014],{},"IPv4",[79,5016,5017],{},"IPv6",[89,5019,5020,5031,5046,5061,5072,5083,5094],{},[76,5021,5022,5025,5028],{},[94,5023,5024],{},"Address size",[94,5026,5027],{},"32 bits",[94,5029,5030],{},"128 bits",[76,5032,5033,5036,5041],{},[94,5034,5035],{},"Example",[94,5037,5038],{},[154,5039,5040],{},"192.0.2.10",[94,5042,5043],{},[154,5044,5045],{},"2001:db8::10",[76,5047,5048,5051,5056],{},[94,5049,5050],{},"DNS record",[94,5052,5053],{},[154,5054,5055],{},"A",[94,5057,5058],{},[154,5059,5060],{},"AAAA",[76,5062,5063,5066,5069],{},[94,5064,5065],{},"Address availability",[94,5067,5068],{},"Highly constrained",[94,5070,5071],{},"Vastly larger address space",[76,5073,5074,5077,5080],{},[94,5075,5076],{},"Broadcast",[94,5078,5079],{},"Supported",[94,5081,5082],{},"Replaced by multicast mechanisms",[76,5084,5085,5088,5091],{},[94,5086,5087],{},"Website support today",[94,5089,5090],{},"Essential in many environments",[94,5092,5093],{},"Increasingly important",[76,5095,5096,5099,5102],{},[94,5097,5098],{},"Typical deployment",[94,5100,5101],{},"IPv4 or dual-stack",[94,5103,5104],{},"Usually dual-stack for public websites",[16,5106,5107,5108,34],{},"IPv6 is not simply IPv4 with longer addresses. Its specification also changes parts of packet handling and simplifies the base header design. IPv6 supports unicast, multicast, and anycast addressing, and unlike IPv4 it does not define broadcast addresses. (",[28,5109,2340],{"href":5110,"rel":5111},"https:\u002F\u002Fwww.rfc-editor.org\u002Finfo\u002Frfc8200\u002F?utm_source=chatgpt.com",[32],[11,5113,5115],{"id":5114},"what-changes-for-a-website","What Changes for a Website?",[16,5117,5118],{},"At the application level, surprisingly little.",[16,5120,5121],{},"Your website can still use:",[789,5123,5124,5127,5130,5133,5136,5139,5142],{},[649,5125,5126],{},"HTTPS",[649,5128,5129],{},"HTTP\u002F2 or HTTP\u002F3",[649,5131,5132],{},"TLS",[649,5134,5135],{},"Nginx or Apache",[649,5137,5138],{},"Node.js, PHP, Python, Go, or another backend",[649,5140,5141],{},"CDNs and reverse proxies",[649,5143,5144],{},"ordinary domain names",[16,5146,5147],{},"The important change happens lower in the network stack.",[16,5149,5150,5151,5153],{},"For IPv4, DNS typically returns an ",[154,5152,5055],{}," record:",[196,5155,5159],{"className":5156,"code":5157,"language":5158,"meta":201,"style":201},"language-dns shiki shiki-themes github-light github-dark","example.com.    A       192.0.2.10\n","dns",[154,5160,5161],{"__ignoreMap":201},[205,5162,5163],{"class":207,"line":208},[205,5164,5157],{},[16,5166,5167,5168,5153],{},"For IPv6, DNS uses an ",[154,5169,5060],{},[196,5171,5173],{"className":5156,"code":5172,"language":5158,"meta":201,"style":201},"example.com.    AAAA    2001:db8::10\n",[154,5174,5175],{"__ignoreMap":201},[205,5176,5177],{"class":207,"line":208},[205,5178,5172],{},[16,5180,5181,5182,5184,5185,5187,5188,34],{},"A hostname can publish both records. Cloudflare's DNS documentation likewise defines ",[154,5183,5055],{}," records as mappings to IPv4 addresses and ",[154,5186,5060],{}," records as mappings to IPv6 addresses. (",[28,5189,5192],{"href":5190,"rel":5191},"https:\u002F\u002Fdevelopers.cloudflare.com\u002Fdns\u002Fmanage-dns-records\u002Freference\u002Fdns-record-types\u002F?utm_source=chatgpt.com",[32],"developers.cloudflare.com",[16,5194,5195],{},"This means the URL does not change:",[196,5197,5200],{"className":5198,"code":5199,"language":454,"meta":201},[452],"https:\u002F\u002Fexample.com\u002F\n",[154,5201,5199],{"__ignoreMap":201},[16,5203,5204],{},"The browser resolves the hostname and determines which network path to use.",[11,5206,5208],{"id":5207},"how-dual-stack-connections-work","How Dual-Stack Connections Work",[16,5210,5211],{},"A common misconception is that a browser simply tries IPv6 first and waits for it to fail before falling back to IPv4.",[16,5213,5214],{},"Modern networking is more sophisticated.",[16,5216,5217,5218,5221,5222,34],{},"RFC 8305 defines ",[23,5219,5220],{},"Happy Eyeballs Version 2",", an approach designed for hosts that may have multiple IPv4 and IPv6 addresses. Clients can attempt connection paths in a way that reduces visible delays when one address family is unavailable, broken, or substantially worse than another. (",[28,5223,2340],{"href":5224,"rel":5225},"https:\u002F\u002Fwww.rfc-editor.org\u002Frfc\u002Frfc8305.html?utm_source=chatgpt.com",[32],[16,5227,5228],{},"Conceptually:",[196,5230,5233],{"className":5231,"code":5232,"language":454,"meta":201},[452],"Browser\n   |\n   +---- IPv6 ----\\\n   |               > Website\n   +---- IPv4 ----\u002F\n",[154,5234,5232],{"__ignoreMap":201},[16,5236,5237],{},"The user should not have to understand which protocol ultimately succeeds.",[16,5239,5240],{},"This is one reason a broken IPv6 deployment can be worse than having no IPv6 deployment at all: advertising IPv6 connectivity that does not actually work introduces another potentially failing network path.",[11,5242,5244],{"id":5243},"is-ipv6-faster","Is IPv6 Faster?",[16,5246,5247],{},"Not inherently.",[16,5249,5250],{},"IPv6 can be faster on one network and slower on another. Actual performance depends on factors including:",[789,5252,5253,5256,5259,5262,5265,5268,5271,5274],{},[649,5254,5255],{},"ISP routing",[649,5257,5258],{},"peering",[649,5260,5261],{},"CDN topology",[649,5263,5264],{},"server location",[649,5266,5267],{},"packet loss",[649,5269,5270],{},"network congestion",[649,5272,5273],{},"IPv4 NAT infrastructure",[649,5275,5276],{},"IPv6 deployment quality",[16,5278,5279,5280,34],{},"Happy Eyeballs exists partly because IPv4 and IPv6 paths may have different connectivity and performance characteristics. (",[28,5281,2340],{"href":5224,"rel":5282},[32],[16,5284,5285],{},"Therefore:",[16,5287,5288],{},[23,5289,5290],{},"IPv6 support is not itself a performance optimization.",[16,5292,5293],{},"Measure the actual routes your users receive instead of assuming one protocol will always have lower latency.",[11,5295,5297],{"id":5296},"does-ipv6-improve-seo","Does IPv6 Improve SEO?",[16,5299,5300],{},"There is no documented basis for treating IPv6 itself as an SEO ranking advantage.",[16,5302,5303,5304,34],{},"Google's published technical requirements for Search focus on whether Googlebot can access the page, whether the server returns a successful HTTP status, and whether the page contains indexable content. IPv6 is not listed as a technical requirement there. (",[28,5305,33],{"href":5306,"rel":5307},"https:\u002F\u002Fdevelopers.google.com\u002Fsearch\u002Fdocs\u002Fessentials\u002Ftechnical?authuser=1&utm_source=chatgpt.com",[32],[16,5309,5310],{},"The SEO concern is therefore indirect.",[16,5312,5313,5314,34],{},"If a networking problem makes your website inaccessible, unstable, or slow for users or crawlers, that infrastructure problem can matter. Google explicitly identifies server and network problems as possible causes of crawling failures. (",[28,5315,33],{"href":30,"rel":5316},[32],[16,5318,5319],{},"So the useful SEO principle is not:",[415,5321,5322],{},[16,5323,5324],{},"Enable IPv6 to rank higher.",[16,5326,5327],{},"It is:",[415,5329,5330],{},[16,5331,5332],{},"Make every advertised network path reliable.",[16,5334,5335],{},[205,5336,5337],{},"INTERNAL LINK: How Google Crawling Works",[11,5339,5341],{"id":5340},"ipv6-only-networks","IPv6-Only Networks",[16,5343,5344],{},"IPv6-only networks also exist.",[16,5346,5347,5348,34],{},"When they need to reach IPv4-only destinations, translation technologies such as NAT64 and DNS64 may be used. DNS64 can synthesize IPv6 DNS answers from IPv4 records so IPv6-only clients can connect through a NAT64 gateway. (",[28,5349,5192],{"href":5350,"rel":5351},"https:\u002F\u002Fdevelopers.cloudflare.com\u002F1.1.1.1\u002Finfrastructure\u002Fipv6-networks\u002F?utm_source=chatgpt.com",[32],[16,5353,5354],{},"That compatibility layer is useful, but a website that supports IPv6 directly does not have to rely on every visitor's network successfully providing such translation.",[16,5356,5357],{},"This is another practical reason to make modern public services IPv6-capable while retaining IPv4 compatibility where needed.",[11,5359,5361],{"id":5360},"how-to-enable-ipv6-safely","How to Enable IPv6 Safely",[16,5363,5364,5365,5367],{},"Do not begin by adding an ",[154,5366,5060],{}," record.",[16,5369,5370],{},"First confirm that the entire path works:",[196,5372,5375],{"className":5373,"code":5374,"language":454,"meta":201},[452],"Internet\n   ↓\nDNS\n   ↓\nCDN \u002F Load Balancer\n   ↓\nFirewall\n   ↓\nReverse Proxy\n   ↓\nApplication\n",[154,5376,5374],{"__ignoreMap":201},[16,5378,5379],{},"Then verify:",[196,5381,5383],{"className":3572,"code":5382,"language":3574,"meta":201,"style":201},"dig A example.com\ndig AAAA example.com\n",[154,5384,5385,5396],{"__ignoreMap":201},[205,5386,5387,5390,5393],{"class":207,"line":208},[205,5388,5389],{"class":218},"dig",[205,5391,5392],{"class":225}," A",[205,5394,5395],{"class":225}," example.com\n",[205,5397,5398,5400,5403],{"class":207,"line":381},[205,5399,5389],{"class":218},[205,5401,5402],{"class":225}," AAAA",[205,5404,5395],{"class":225},[16,5406,5407],{},"Test IPv4 explicitly:",[196,5409,5411],{"className":3572,"code":5410,"language":3574,"meta":201,"style":201},"curl -4 https:\u002F\u002Fexample.com\u002F\n",[154,5412,5413],{"__ignoreMap":201},[205,5414,5415,5417,5420],{"class":207,"line":208},[205,5416,4468],{"class":218},[205,5418,5419],{"class":1277}," -4",[205,5421,5422],{"class":225}," https:\u002F\u002Fexample.com\u002F\n",[16,5424,5425],{},"Then IPv6:",[196,5427,5429],{"className":3572,"code":5428,"language":3574,"meta":201,"style":201},"curl -6 https:\u002F\u002Fexample.com\u002F\n",[154,5430,5431],{"__ignoreMap":201},[205,5432,5433,5435,5438],{"class":207,"line":208},[205,5434,4468],{"class":218},[205,5436,5437],{"class":1277}," -6",[205,5439,5422],{"class":225},[16,5441,5442],{},"Both should return the expected application response.",[16,5444,5445,5446,5449],{},"Also check monitoring, firewall rules, rate limiting, IP allowlists, application logs, fraud detection, and analytics systems. Software that assumes every client address looks like ",[154,5447,5448],{},"192.0.2.1"," can fail when it encounters an address such as:",[196,5451,5454],{"className":5452,"code":5453,"language":454,"meta":201},[452],"2001:db8:85a3::8a2e:370:7334\n",[154,5455,5453],{"__ignoreMap":201},[11,5457,4710],{"id":4709},[16,5459,5460,5461,5463],{},"The most dangerous mistake is publishing an ",[154,5462,5060],{}," record simply because the hosting dashboard displays an IPv6 address. DNS availability does not prove end-to-end connectivity.",[16,5465,5466],{},"Another mistake is assuming NAT provides security. Firewall policy and exposure control should be deliberate regardless of which IP version is used.",[16,5468,5469,5470,34],{},"Finally, do not disable IPv4 merely to make an infrastructure stack appear “modern.” IPv6 adoption is substantial but incomplete. Cloudflare's current global measurements still show considerable traffic arriving over IPv4. (",[28,5471,4991],{"href":4989,"rel":5472},[32],[11,5474,690],{"id":689},[16,5476,5477,5478,5481],{},"For an ordinary public website in 2026, prefer ",[23,5479,5480],{},"tested dual-stack availability"," when your hosting architecture supports it reliably.",[16,5483,5484,5485,34],{},"Use IPv4 and IPv6 together, or let a capable CDN or edge platform provide both client-facing protocols. Cloudflare, for example, enables IPv6 compatibility for proxied domains by default and can advertise IPv6 connectivity alongside IPv4. (",[28,5486,5192],{"href":5487,"rel":5488},"https:\u002F\u002Fdevelopers.cloudflare.com\u002Fnetwork\u002Fipv6-compatibility\u002F?utm_source=chatgpt.com",[32],[16,5490,5491],{},"More importantly, treat IPv6 as a real production path: monitor it, test it during deployments, include it in firewall policy, and verify it from external networks.",[16,5493,5494],{},"Do not deploy IPv6 merely to check a box.",[11,5496,719],{"id":718},[721,5498,5500],{"id":5499},"is-ipv4-obsolete","Is IPv4 obsolete?",[16,5502,5503,5504,34],{},"No. IPv4 remains heavily used, even though its address-space limitations drove the development and adoption of IPv6. ARIN, for example, still operates a waiting-list process for limited returned IPv4 address space. (",[28,5505,5508],{"href":5506,"rel":5507},"https:\u002F\u002Fwww.arin.net\u002Fannouncements\u002F20260702\u002F?utm_source=chatgpt.com",[32],"arin.net",[721,5510,5512],{"id":5511},"should-every-website-support-ipv6","Should every website support IPv6?",[16,5514,5515],{},"It is increasingly useful, particularly for long-lived infrastructure. But working IPv4-only connectivity is preferable to a misconfigured IPv6 deployment.",[721,5517,5519],{"id":5518},"can-ipv4-and-ipv6-run-together","Can IPv4 and IPv6 run together?",[16,5521,5522,5523,5526],{},"Yes. This is normally called ",[23,5524,5525],{},"dual-stack networking",", and it is a common transition model.",[721,5528,5530],{"id":5529},"do-i-need-separate-domains","Do I need separate domains?",[16,5532,5533,5534,697,5536,5538],{},"No. The same hostname can have both ",[154,5535,5055],{},[154,5537,5060],{}," DNS records.",[721,5540,5542],{"id":5541},"will-enabling-ipv6-improve-core-web-vitals","Will enabling IPv6 improve Core Web Vitals?",[16,5544,5545],{},"Not automatically. IPv6 may produce a different network route, but the resulting latency depends on the actual ISP, routing, peering, CDN, and server path.",[11,5547,771],{"id":770},[16,5549,5550],{},"IPv6 is not a new version of your website. It is another way for traffic to reach it.",[16,5552,5553],{},"IPv4 remains important, while IPv6 has become too widely deployed to treat as an experimental technology. The practical architecture for most modern websites is therefore not an ideological choice between the two.",[16,5555,5556],{},"Support both where possible, advertise only connectivity that actually works, and measure IPv4 and IPv6 as separate network paths.",[11,5558,787],{"id":786},[646,5560,5561,5571,5581,5592,5603,5612,5621,5631,5641,5651],{},[649,5562,5563,5566,5567],{},[23,5564,5565],{},"IETF \u002F RFC Editor — RFC 8200: Internet Protocol, Version 6 (IPv6) Specification",", July 2017. ",[28,5568,5570],{"href":5110,"rel":5569},[32],"RFC 8200",[649,5572,5573,5576,5577],{},[23,5574,5575],{},"IETF \u002F RFC Editor — RFC 791: Internet Protocol",", September 1981. ",[28,5578,5580],{"href":4965,"rel":5579},[32],"RFC 791",[649,5582,5583,5586,5587],{},[23,5584,5585],{},"IETF \u002F RFC Editor — RFC 4291: IP Version 6 Addressing Architecture",", February 2006. ",[28,5588,5591],{"href":5589,"rel":5590},"https:\u002F\u002Fwww.rfc-editor.org\u002Finfo\u002Frfc4291\u002F?utm_source=chatgpt.com",[32],"RFC 4291",[649,5593,5594,5597,5598],{},[23,5595,5596],{},"IETF \u002F RFC Editor — RFC 8305: Happy Eyeballs Version 2",", December 2017. ",[28,5599,5602],{"href":5600,"rel":5601},"https:\u002F\u002Fwww.rfc-editor.org\u002Finfo\u002Frfc8305\u002F?utm_source=chatgpt.com",[32],"RFC 8305",[649,5604,5605,1936,5608],{},[23,5606,5607],{},"Google Search Central — Google Search Technical Requirements",[28,5609,5611],{"href":5306,"rel":5610},[32],"Google Search technical requirements",[649,5613,5614,1936,5617],{},[23,5615,5616],{},"Google Search Central — How Google Search Works",[28,5618,5620],{"href":30,"rel":5619},[32],"How Google Search works",[649,5622,5623,5626,5627],{},[23,5624,5625],{},"Cloudflare — IPv6 Compatibility",", updated August 25, 2026. ",[28,5628,5630],{"href":5487,"rel":5629},[32],"Cloudflare IPv6 compatibility",[649,5632,5633,5636,5637],{},[23,5634,5635],{},"Cloudflare — DNS Record Types",", updated June 2, 2026. ",[28,5638,5640],{"href":5190,"rel":5639},[32],"Cloudflare DNS record types",[649,5642,5643,5646,5647],{},[23,5644,5645],{},"Cloudflare Radar — Worldwide Adoption & Usage",", accessed September 20, 2026. ",[28,5648,5650],{"href":4989,"rel":5649},[32],"Cloudflare Radar",[649,5652,5653,5656,5657],{},[23,5654,5655],{},"ARIN — IPv4 Waiting List Distribution",", July 2, 2026. ",[28,5658,5660],{"href":5506,"rel":5659},[32],"ARIN IPv4 Waiting List Distribution",[890,5662,5663],{},"html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sScJk, html code.shiki .sScJk{--shiki-default:#6F42C1;--shiki-dark:#B392F0}html pre.shiki code .sZZnC, html code.shiki .sZZnC{--shiki-default:#032F62;--shiki-dark:#9ECBFF}html pre.shiki code .sj4cs, html code.shiki .sj4cs{--shiki-default:#005CC5;--shiki-dark:#79B8FF}",{"title":201,"searchDepth":381,"depth":381,"links":5665},[5666,5667,5668,5669,5670,5671,5672,5673,5674,5675,5676,5677,5678,5679],{"id":4950,"depth":381,"text":4951},{"id":37,"depth":381,"text":38},{"id":5001,"depth":381,"text":5002},{"id":5114,"depth":381,"text":5115},{"id":5207,"depth":381,"text":5208},{"id":5243,"depth":381,"text":5244},{"id":5296,"depth":381,"text":5297},{"id":5340,"depth":381,"text":5341},{"id":5360,"depth":381,"text":5361},{"id":4709,"depth":381,"text":4710},{"id":689,"depth":381,"text":690},{"id":718,"depth":381,"text":719},{"id":770,"depth":381,"text":771},{"id":786,"depth":381,"text":787},"Understand IPv4 vs IPv6 for modern websites, including DNS, dual-stack hosting, performance, SEO implications, testing, and deployment best practices.","\u002Fipv4-vs-ipv6.png","Image of IPv6 and IPv6",{},"\u002Fblog\u002Fen\u002Fipv4-vs-ipv6",{"title":4945,"description":5680},"blog\u002Fen\u002Fipv4-vs-ipv6","ipv4-vs-ipv6.md","71QWXD9OPDjblsbzNeVafH0MAw0RPrvR6Mm2yk3SMcY",{"id":5690,"title":5691,"author":6,"body":5692,"category":4091,"description":6928,"draft":912,"extension":913,"featured":914,"image":6929,"imageAlt":6930,"locale":917,"meta":6931,"navigation":914,"path":6932,"publishedAt":6933,"seo":6934,"slug":6935,"stem":6936,"translationKey":6937,"updatedAt":6933,"__hash__":6938},"blog\u002Fblog\u002Fen\u002Fcsp-guide.md","Content Security Policy (CSP): Practical Engineering Guide",{"type":8,"value":5693,"toc":6907},[5694,5698,5706,5717,5721,5728,5739,5746,5749,5879,5906,5910,5913,5944,5947,5950,5955,5958,5963,5966,5972,5975,5984,5996,6000,6003,6028,6034,6037,6071,6074,6083,6086,6094,6097,6101,6104,6114,6120,6129,6132,6142,6145,6153,6156,6159,6162,6171,6178,6180,6189,6191,6222,6229,6250,6253,6257,6262,6264,6321,6324,6336,6342,6345,6352,6355,6364,6367,6370,6401,6404,6492,6510,6519,6523,6526,6529,6555,6562,6565,6570,6573,6577,6588,6620,6635,6638,6645,6648,6684,6687,6701,6705,6719,6725,6727,6730,6745,6748,6751,6753,6757,6763,6770,6775,6779,6785,6789,6792,6796,6799,6801,6804,6807,6809,6904],[11,5695,5697],{"id":5696},"content-security-policy-a-practical-engineering-guide","Content Security Policy: A Practical Engineering Guide",[16,5699,5700,5701,34],{},"Content Security Policy (CSP) is a browser-enforced security mechanism that lets a website define which resources may load or execute and which security-sensitive behaviors are permitted. Its most important practical use is reducing the damage caused by cross-site scripting (XSS): even if malicious HTML reaches a page, a strong CSP can prevent the injected JavaScript from executing. CSP Level 3 is the current W3C specification line; as of September 2026, it remains a Working Draft, with the current W3C draft dated August 13, 2026. (",[28,5702,5705],{"href":5703,"rel":5704},"https:\u002F\u002Fwww.w3.org\u002FTR\u002FCSP\u002Fall\u002F?utm_source=chatgpt.com",[32],"w3.org",[16,5707,5708,5709,5712,5713,34],{},"CSP should not be treated as a replacement for proper escaping, sanitization, secure templating, or fixing XSS vulnerabilities. It is ",[23,5710,5711],{},"defense in depth",": an additional enforcement layer provided by the browser. (",[28,5714,958],{"href":5715,"rel":5716},"https:\u002F\u002Fweb.dev\u002Farticles\u002Fstrict-csp?utm_source=chatgpt.com",[32],[11,5718,5720],{"id":5719},"what-is-csp","What Is CSP?",[16,5722,5723,5724,5727],{},"A Content Security Policy is usually sent through the HTTP ",[154,5725,5726],{},"Content-Security-Policy"," response header:",[196,5729,5733],{"className":5730,"code":5731,"language":5732,"meta":201,"style":201},"language-http shiki shiki-themes github-light github-dark","Content-Security-Policy: default-src 'self'\n","http",[154,5734,5735],{"__ignoreMap":201},[205,5736,5737],{"class":207,"line":208},[205,5738,5731],{},[16,5740,5741,5742,5745],{},"This tells the browser that resources governed by ",[154,5743,5744],{},"default-src"," should normally come from the same origin as the page.",[16,5747,5748],{},"A policy can contain many directives, each controlling a different capability:",[70,5750,5751,5761],{},[73,5752,5753],{},[76,5754,5755,5758],{},[79,5756,5757],{},"Directive",[79,5759,5760],{},"Controls",[89,5762,5763,5773,5783,5792,5805,5815,5825,5835,5845,5859,5869],{},[76,5764,5765,5770],{},[94,5766,5767],{},[154,5768,5769],{},"script-src",[94,5771,5772],{},"JavaScript execution and loading",[76,5774,5775,5780],{},[94,5776,5777],{},[154,5778,5779],{},"style-src",[94,5781,5782],{},"CSS loading and inline styles",[76,5784,5785,5790],{},[94,5786,5787],{},[154,5788,5789],{},"img-src",[94,5791,2922],{},[76,5793,5794,5799],{},[94,5795,5796],{},[154,5797,5798],{},"connect-src",[94,5800,5801,5804],{},[154,5802,5803],{},"fetch()",", XHR, WebSocket and similar connections",[76,5806,5807,5812],{},[94,5808,5809],{},[154,5810,5811],{},"font-src",[94,5813,5814],{},"Fonts",[76,5816,5817,5822],{},[94,5818,5819],{},[154,5820,5821],{},"frame-src",[94,5823,5824],{},"Frames the page may load",[76,5826,5827,5832],{},[94,5828,5829],{},[154,5830,5831],{},"worker-src",[94,5833,5834],{},"Workers and service workers",[76,5836,5837,5842],{},[94,5838,5839],{},[154,5840,5841],{},"object-src",[94,5843,5844],{},"Plugin\u002Fobject resources",[76,5846,5847,5852],{},[94,5848,5849],{},[154,5850,5851],{},"base-uri",[94,5853,5854,5855,5858],{},"Allowed ",[154,5856,5857],{},"\u003Cbase>"," URLs",[76,5860,5861,5866],{},[94,5862,5863],{},[154,5864,5865],{},"form-action",[94,5867,5868],{},"Form submission destinations",[76,5870,5871,5876],{},[94,5872,5873],{},[154,5874,5875],{},"frame-ancestors",[94,5877,5878],{},"Sites allowed to embed the page",[16,5880,5881,5883,5884,5886,5887,5889,5890,5892,5893,1405,5895,1412,5897,5899,5900,478,5902,34],{},[154,5882,5744],{}," acts as a fallback for many fetch directives. For example, if ",[154,5885,5789],{}," is absent, images can fall back to ",[154,5888,5744],{},". This does ",[23,5891,412],{}," apply universally: ",[154,5894,5875],{},[154,5896,5865],{},[154,5898,5851],{},", for example, do not inherit from ",[154,5901,5744],{},[28,5903,5705],{"href":5904,"rel":5905},"https:\u002F\u002Fwww.w3.org\u002FTR\u002FCSP\u002F?utm_source=chatgpt.com",[32],[11,5907,5909],{"id":5908},"why-csp-matters","Why CSP Matters",[16,5911,5912],{},"Consider a vulnerable page that accidentally renders attacker-controlled HTML:",[196,5914,5916],{"className":198,"code":5915,"language":200,"meta":201,"style":201},"\u003Cscript>\n  stealSession();\n\u003C\u002Fscript>\n",[154,5917,5918,5927,5935],{"__ignoreMap":201},[205,5919,5920,5922,5925],{"class":207,"line":208},[205,5921,212],{"class":211},[205,5923,5924],{"class":215},"script",[205,5926,234],{"class":211},[205,5928,5929,5932],{"class":207,"line":381},[205,5930,5931],{"class":218},"  stealSession",[205,5933,5934],{"class":211},"();\n",[205,5936,5937,5940,5942],{"class":207,"line":387},[205,5938,5939],{"class":211},"\u003C\u002F",[205,5941,5924],{"class":215},[205,5943,234],{"class":211},[16,5945,5946],{},"Without additional protection, the browser may execute it.",[16,5948,5949],{},"A strong CSP changes the question from:",[415,5951,5952],{},[16,5953,5954],{},"“Is this valid JavaScript?”",[16,5956,5957],{},"to:",[415,5959,5960],{},[16,5961,5962],{},"“Has this page explicitly authorized this JavaScript?”",[16,5964,5965],{},"That distinction is why CSP can materially reduce the impact of many XSS vulnerabilities.",[16,5967,5968,5969,257],{},"The difficult part is deciding ",[23,5970,5971],{},"how scripts become trusted",[16,5973,5974],{},"Older CSP configurations commonly relied on domain allowlists:",[196,5976,5978],{"className":5730,"code":5977,"language":5732,"meta":201,"style":201},"script-src 'self' https:\u002F\u002Fcdn.example.com\n",[154,5979,5980],{"__ignoreMap":201},[205,5981,5982],{"class":207,"line":208},[205,5983,5977],{},[16,5985,5986,5987,5990,5991,34],{},"This is better than allowing arbitrary scripts, but large host-based allowlists can become difficult to reason about and may contain origins that themselves provide ways to execute attacker-controlled code. Modern CSP guidance therefore favors nonce- or hash-based ",[23,5988,5989],{},"strict CSP"," for script execution. (",[28,5992,5995],{"href":5993,"rel":5994},"https:\u002F\u002Fdeveloper.mozilla.org\u002Fen-US\u002Fdocs\u002FWeb\u002FHTTP\u002FGuides\u002FCSP?utm_source=chatgpt.com",[32],"developer.mozilla.org",[11,5997,5999],{"id":5998},"strict-csp","Strict CSP",[16,6001,6002],{},"A basic nonce-based strict policy can look like this:",[196,6004,6006],{"className":5730,"code":6005,"language":5732,"meta":201,"style":201},"Content-Security-Policy:\n  script-src 'nonce-RANDOM_VALUE' 'strict-dynamic';\n  object-src 'none';\n  base-uri 'none';\n",[154,6007,6008,6013,6018,6023],{"__ignoreMap":201},[205,6009,6010],{"class":207,"line":208},[205,6011,6012],{},"Content-Security-Policy:\n",[205,6014,6015],{"class":207,"line":381},[205,6016,6017],{},"  script-src 'nonce-RANDOM_VALUE' 'strict-dynamic';\n",[205,6019,6020],{"class":207,"line":387},[205,6021,6022],{},"  object-src 'none';\n",[205,6024,6025],{"class":207,"line":393},[205,6026,6027],{},"  base-uri 'none';\n",[16,6029,6030,6031,257],{},"The important part is the ",[23,6032,6033],{},"nonce",[16,6035,6036],{},"The server generates a fresh unpredictable value for each response:",[196,6038,6040],{"className":198,"code":6039,"language":200,"meta":201,"style":201},"\u003Cscript nonce=\"RANDOM_VALUE\" src=\"\u002Fapp.js\">\u003C\u002Fscript>\n",[154,6041,6042],{"__ignoreMap":201},[205,6043,6044,6046,6048,6051,6053,6056,6059,6061,6064,6067,6069],{"class":207,"line":208},[205,6045,212],{"class":211},[205,6047,5924],{"class":215},[205,6049,6050],{"class":218}," nonce",[205,6052,222],{"class":211},[205,6054,6055],{"class":225},"\"RANDOM_VALUE\"",[205,6057,6058],{"class":218}," src",[205,6060,222],{"class":211},[205,6062,6063],{"class":225},"\"\u002Fapp.js\"",[205,6065,6066],{"class":211},">\u003C\u002F",[205,6068,5924],{"class":215},[205,6070,234],{"class":211},[16,6072,6073],{},"The same value appears in the CSP header:",[196,6075,6077],{"className":5730,"code":6076,"language":5732,"meta":201,"style":201},"script-src 'nonce-RANDOM_VALUE'\n",[154,6078,6079],{"__ignoreMap":201},[205,6080,6081],{"class":207,"line":208},[205,6082,6076],{},[16,6084,6085],{},"The browser executes the script because the values match. An injected script without the correct nonce is blocked.",[16,6087,6088,6089,478,6091,34],{},"For this design to provide meaningful protection, the nonce must be unpredictable and regenerated for every response. web.dev recommends a cryptographically strong value, ideally at least ",[23,6090,5030],{},[28,6092,958],{"href":5715,"rel":6093},[32],[16,6095,6096],{},"Do not generate one nonce during application startup and reuse it indefinitely. A nonce that remains constant stops functioning as a meaningful one-time authorization token.",[11,6098,6100],{"id":6099},"nonces-vs-hashes","Nonces vs Hashes",[16,6102,6103],{},"Nonces and hashes solve similar problems but suit different architectures.",[16,6105,6106,6109,6110,6113],{},[23,6107,6108],{},"Nonces are usually easier for dynamically rendered HTML."," The server generates a fresh value during each request and injects it into approved ",[154,6111,6112],{},"\u003Cscript>"," elements.",[16,6115,6116,6119],{},[23,6117,6118],{},"Hashes work well for stable or statically generated HTML."," Instead of generating a random value, you calculate a cryptographic hash of an authorized script:",[196,6121,6123],{"className":5730,"code":6122,"language":5732,"meta":201,"style":201},"script-src 'sha256-AbCdEf...'\n",[154,6124,6125],{"__ignoreMap":201},[205,6126,6127],{"class":207,"line":208},[205,6128,6122],{},[16,6130,6131],{},"The browser hashes the script and executes it only if the value matches the policy.",[16,6133,6134,6135,6138,6139,34],{},"CSP supports SHA-256, SHA-384, and SHA-512 hash source expressions. Changing even a small part of an inline script changes its hash, so build systems using hash-based CSP generally need to regenerate the policy when script content changes. MDN also documents additional requirements when hashes are used to authorize external scripts, including the corresponding ",[154,6136,6137],{},"integrity"," attribute. (",[28,6140,5995],{"href":5993,"rel":6141},[32],[16,6143,6144],{},"For an SSR application, a nonce is often the simpler engineering choice. For static HTML where per-response mutation is undesirable, hashes may fit better.",[11,6146,6148,6149,6152],{"id":6147},"what-strict-dynamic-does","What ",[154,6150,6151],{},"strict-dynamic"," Does",[16,6154,6155],{},"Modern applications frequently have a trusted bootstrap script that loads other scripts dynamically.",[16,6157,6158],{},"Without additional handling, those secondary scripts may be blocked.",[16,6160,6161],{},"Adding:",[196,6163,6165],{"className":5730,"code":6164,"language":5732,"meta":201,"style":201},"'strict-dynamic'\n",[154,6166,6167],{"__ignoreMap":201},[205,6168,6169],{"class":207,"line":208},[205,6170,6164],{},[16,6172,6173,6174,34],{},"allows trust established by a valid nonce or hash to propagate to scripts loaded by that trusted script. (",[28,6175,5995],{"href":6176,"rel":6177},"https:\u002F\u002Fdeveloper.mozilla.org\u002Fen-US\u002Fdocs\u002FWeb\u002FHTTP\u002FReference\u002FHeaders\u002FContent-Security-Policy\u002Fscript-src?utm_source=chatgpt.com",[32],[16,6179,366],{},[196,6181,6183],{"className":5730,"code":6182,"language":5732,"meta":201,"style":201},"script-src 'nonce-abc123' 'strict-dynamic'\n",[154,6184,6185],{"__ignoreMap":201},[205,6186,6187],{"class":207,"line":208},[205,6188,6182],{},[16,6190,4477],{},[196,6192,6194],{"className":198,"code":6193,"language":200,"meta":201,"style":201},"\u003Cscript nonce=\"abc123\" src=\"\u002Fbootstrap.js\">\u003C\u002Fscript>\n",[154,6195,6196],{"__ignoreMap":201},[205,6197,6198,6200,6202,6204,6206,6209,6211,6213,6216,6218,6220],{"class":207,"line":208},[205,6199,212],{"class":211},[205,6201,5924],{"class":215},[205,6203,6050],{"class":218},[205,6205,222],{"class":211},[205,6207,6208],{"class":225},"\"abc123\"",[205,6210,6058],{"class":218},[205,6212,222],{"class":211},[205,6214,6215],{"class":225},"\"\u002Fbootstrap.js\"",[205,6217,6066],{"class":211},[205,6219,5924],{"class":215},[205,6221,234],{"class":211},[16,6223,6224,6225,6228],{},"permit ",[154,6226,6227],{},"\u002Fbootstrap.js"," to execute and can allow scripts that it subsequently creates and loads.",[16,6230,6231,6232,1405,6235,6238,6239,6241,6242,6245,6246,34],{},"There is an important consequence: in browsers applying CSP Level 3 semantics, host expressions such as ",[154,6233,6234],{},"'self'",[154,6236,6237],{},"https:"," and explicit host allowlists in that ",[154,6240,5769],{}," directive are ignored when ",[154,6243,6244],{},"'strict-dynamic'"," is active with valid nonce\u002Fhash trust. That makes the trusted script chain itself an important security boundary. (",[28,6247,5995],{"href":6248,"rel":6249},"https:\u002F\u002Fdeveloper.mozilla.org\u002Fen-US\u002Fdocs\u002FWeb\u002FHTTP\u002FReference\u002FHeaders\u002FContent-Security-Policy?utm_source=chatgpt.com",[32],[16,6251,6252],{},"If trusted JavaScript dynamically constructs script URLs from attacker-controlled input, CSP cannot automatically repair that design.",[11,6254,6256],{"id":6255},"a-practical-policy","A Practical Policy",[16,6258,6259,6260,257],{},"A real application usually needs more than ",[154,6261,5769],{},[16,6263,366],{},[196,6265,6267],{"className":5730,"code":6266,"language":5732,"meta":201,"style":201},"Content-Security-Policy:\n  default-src 'self';\n  script-src 'nonce-{NONCE}' 'strict-dynamic';\n  style-src 'self';\n  img-src 'self' data: https:;\n  font-src 'self';\n  connect-src 'self' https:\u002F\u002Fapi.example.com;\n  object-src 'none';\n  base-uri 'none';\n  form-action 'self';\n  frame-ancestors 'none';\n",[154,6268,6269,6273,6278,6283,6288,6293,6298,6303,6307,6311,6316],{"__ignoreMap":201},[205,6270,6271],{"class":207,"line":208},[205,6272,6012],{},[205,6274,6275],{"class":207,"line":381},[205,6276,6277],{},"  default-src 'self';\n",[205,6279,6280],{"class":207,"line":387},[205,6281,6282],{},"  script-src 'nonce-{NONCE}' 'strict-dynamic';\n",[205,6284,6285],{"class":207,"line":393},[205,6286,6287],{},"  style-src 'self';\n",[205,6289,6290],{"class":207,"line":1241},[205,6291,6292],{},"  img-src 'self' data: https:;\n",[205,6294,6295],{"class":207,"line":1252},[205,6296,6297],{},"  font-src 'self';\n",[205,6299,6300],{"class":207,"line":1700},[205,6301,6302],{},"  connect-src 'self' https:\u002F\u002Fapi.example.com;\n",[205,6304,6305],{"class":207,"line":1712},[205,6306,6022],{},[205,6308,6309],{"class":207,"line":1724},[205,6310,6027],{},[205,6312,6313],{"class":207,"line":1733},[205,6314,6315],{},"  form-action 'self';\n",[205,6317,6318],{"class":207,"line":3072},[205,6319,6320],{},"  frame-ancestors 'none';\n",[16,6322,6323],{},"This should be treated as an architectural example, not a policy to paste blindly into every site.",[16,6325,6326,6329,6330,6332,6333,34],{},[154,6327,6328],{},"frame-ancestors 'none'",", for example, prevents other pages from embedding the document and can help defend against UI-redressing attacks. But an application intentionally embedded by customers may instead require specific parent origins. The directive does not inherit from ",[154,6331,5744],{},", so it must be declared separately when required. (",[28,6334,5705],{"href":5904,"rel":6335},[32],[16,6337,6338,6339,6341],{},"Similarly, ",[154,6340,5798],{}," must include APIs, WebSocket endpoints or other network destinations actually used by the application.",[16,6343,6344],{},"The goal is not to create the longest possible CSP. It is to describe the application's legitimate behavior as narrowly and accurately as practical.",[11,6346,6348,6349],{"id":6347},"avoid-unsafe-inline","Avoid ",[154,6350,6351],{},"unsafe-inline",[16,6353,6354],{},"A common response to CSP errors is:",[196,6356,6358],{"className":5730,"code":6357,"language":5732,"meta":201,"style":201},"script-src 'self' 'unsafe-inline'\n",[154,6359,6360],{"__ignoreMap":201},[205,6361,6362],{"class":207,"line":208},[205,6363,6357],{},[16,6365,6366],{},"That frequently defeats one of CSP's most valuable protections because arbitrary inline JavaScript may execute.",[16,6368,6369],{},"A better approach is to refactor patterns such as:",[196,6371,6373],{"className":198,"code":6372,"language":200,"meta":201,"style":201},"\u003Cbutton onclick=\"save()\">Save\u003C\u002Fbutton>\n",[154,6374,6375],{"__ignoreMap":201},[205,6376,6377,6379,6382,6384,6386,6388,6391,6394,6397,6399],{"class":207,"line":208},[205,6378,212],{"class":211},[205,6380,6381],{"class":215},"button",[205,6383,322],{"class":218},[205,6385,222],{"class":211},[205,6387,327],{"class":225},[205,6389,6390],{"class":218},"save",[205,6392,6393],{"class":225},"()\"",[205,6395,6396],{"class":211},">Save\u003C\u002F",[205,6398,6381],{"class":215},[205,6400,234],{"class":211},[16,6402,6403],{},"into JavaScript event registration:",[196,6405,6407],{"className":198,"code":6406,"language":200,"meta":201,"style":201},"\u003Cbutton id=\"save\">Save\u003C\u002Fbutton>\n\n\u003Cscript nonce=\"{NONCE}\">\ndocument\n  .getElementById('save')\n  .addEventListener('click', save);\n\u003C\u002Fscript>\n",[154,6408,6409,6429,6433,6448,6453,6469,6484],{"__ignoreMap":201},[205,6410,6411,6413,6415,6418,6420,6423,6425,6427],{"class":207,"line":208},[205,6412,212],{"class":211},[205,6414,6381],{"class":215},[205,6416,6417],{"class":218}," id",[205,6419,222],{"class":211},[205,6421,6422],{"class":225},"\"save\"",[205,6424,6396],{"class":211},[205,6426,6381],{"class":215},[205,6428,234],{"class":211},[205,6430,6431],{"class":207,"line":381},[205,6432,3032],{"emptyLinePlaceholder":914},[205,6434,6435,6437,6439,6441,6443,6446],{"class":207,"line":387},[205,6436,212],{"class":211},[205,6438,5924],{"class":215},[205,6440,6050],{"class":218},[205,6442,222],{"class":211},[205,6444,6445],{"class":225},"\"{NONCE}\"",[205,6447,234],{"class":211},[205,6449,6450],{"class":207,"line":393},[205,6451,6452],{"class":211},"document\n",[205,6454,6455,6458,6461,6463,6466],{"class":207,"line":1241},[205,6456,6457],{"class":211},"  .",[205,6459,6460],{"class":218},"getElementById",[205,6462,1465],{"class":211},[205,6464,6465],{"class":225},"'save'",[205,6467,6468],{"class":211},")\n",[205,6470,6471,6473,6476,6478,6481],{"class":207,"line":1252},[205,6472,6457],{"class":211},[205,6474,6475],{"class":218},"addEventListener",[205,6477,1465],{"class":211},[205,6479,6480],{"class":225},"'click'",[205,6482,6483],{"class":211},", save);\n",[205,6485,6486,6488,6490],{"class":207,"line":1700},[205,6487,5939],{"class":211},[205,6489,5924],{"class":215},[205,6491,234],{"class":211},[16,6493,6494,6495,6498,6499,6502,6503,6506,6507,34],{},"Strict CSP also normally prevents JavaScript URLs such as ",[154,6496,6497],{},"href=\"javascript:...\""," and blocks string-to-code execution such as ",[154,6500,6501],{},"eval()"," unless ",[154,6504,6505],{},"'unsafe-eval'"," is explicitly permitted. (",[28,6508,958],{"href":5715,"rel":6509},[32],[16,6511,6512,6513,1516,6516,6518],{},"Adding ",[154,6514,6515],{},"'unsafe-inline'",[154,6517,6505],{}," simply to silence CSP errors should therefore trigger investigation rather than becoming the default fix.",[11,6520,6522],{"id":6521},"roll-out-with-report-only","Roll Out With Report-Only",[16,6524,6525],{},"Deploying a strict policy directly to production can break analytics, payment widgets, authentication flows, customer-support tools, API calls or application code that was never designed for CSP.",[16,6527,6528],{},"Use:",[196,6530,6532],{"className":5730,"code":6531,"language":5732,"meta":201,"style":201},"Content-Security-Policy-Report-Only:\n  default-src 'self';\n  script-src 'nonce-{NONCE}' 'strict-dynamic';\n  object-src 'none';\n  base-uri 'none';\n",[154,6533,6534,6539,6543,6547,6551],{"__ignoreMap":201},[205,6535,6536],{"class":207,"line":208},[205,6537,6538],{},"Content-Security-Policy-Report-Only:\n",[205,6540,6541],{"class":207,"line":381},[205,6542,6277],{},[205,6544,6545],{"class":207,"line":387},[205,6546,6282],{},[205,6548,6549],{"class":207,"line":393},[205,6550,6022],{},[205,6552,6553],{"class":207,"line":1241},[205,6554,6027],{},[16,6556,6557,6558,34],{},"Report-only mode evaluates the policy without enforcing the blocks. Browser console messages and CSP reports reveal what the proposed policy would reject. (",[28,6559,5995],{"href":6560,"rel":6561},"https:\u002F\u002Fdeveloper.mozilla.org\u002Fen-US\u002Fdocs\u002FWeb\u002FSecurity\u002FPractical_implementation_guides\u002FCSP?utm_source=chatgpt.com",[32],[16,6563,6564],{},"A practical rollout becomes:",[16,6566,6567],{},[23,6568,6569],{},"Observe → classify violations → fix legitimate dependencies → tighten the policy → enforce → continue monitoring.",[16,6571,6572],{},"Do not automatically add every reported hostname to an allowlist. A violation may reveal obsolete code, an unexpected third-party dependency, a browser extension, an attempted injection or a genuine configuration requirement.",[11,6574,6576],{"id":6575},"csp-reporting","CSP Reporting",[16,6578,6579,6580,6583,6584,6587],{},"Modern CSP reporting uses the Reporting API with a ",[154,6581,6582],{},"Reporting-Endpoints"," header and the CSP ",[154,6585,6586],{},"report-to"," directive:",[196,6589,6591],{"className":5730,"code":6590,"language":5732,"meta":201,"style":201},"Reporting-Endpoints:\n  csp=\"https:\u002F\u002Fexample.com\u002Fcsp-reports\"\n\nContent-Security-Policy:\n  default-src 'self';\n  report-to csp;\n",[154,6592,6593,6598,6603,6607,6611,6615],{"__ignoreMap":201},[205,6594,6595],{"class":207,"line":208},[205,6596,6597],{},"Reporting-Endpoints:\n",[205,6599,6600],{"class":207,"line":381},[205,6601,6602],{},"  csp=\"https:\u002F\u002Fexample.com\u002Fcsp-reports\"\n",[205,6604,6605],{"class":207,"line":387},[205,6606,3032],{"emptyLinePlaceholder":914},[205,6608,6609],{"class":207,"line":393},[205,6610,6012],{},[205,6612,6613],{"class":207,"line":1241},[205,6614,6277],{},[205,6616,6617],{"class":207,"line":1252},[205,6618,6619],{},"  report-to csp;\n",[16,6621,6622,6625,6626,6628,6629,6631,6632,34],{},[154,6623,6624],{},"report-uri"," is deprecated by CSP Level 3 in favor of ",[154,6627,6586],{},". However, current MDN guidance still shows both where compatibility with browsers lacking complete ",[154,6630,6586],{}," support is required. (",[28,6633,5705],{"href":5904,"rel":6634},[32],[16,6636,6637],{},"Reports should also be treated as untrusted input. Logging infrastructure should validate, rate-limit and safely store them rather than assuming every report is trustworthy.",[11,6639,6641,6642],{"id":6640},"header-vs-meta","Header vs ",[154,6643,6644],{},"\u003Cmeta>",[16,6646,6647],{},"CSP can also be delivered through:",[196,6649,6651],{"className":198,"code":6650,"language":200,"meta":201,"style":201},"\u003Cmeta\n  http-equiv=\"Content-Security-Policy\"\n  content=\"default-src 'self'\"\n>\n",[154,6652,6653,6660,6670,6680],{"__ignoreMap":201},[205,6654,6655,6657],{"class":207,"line":208},[205,6656,212],{"class":211},[205,6658,6659],{"class":215},"meta\n",[205,6661,6662,6665,6667],{"class":207,"line":381},[205,6663,6664],{"class":218},"  http-equiv",[205,6666,222],{"class":211},[205,6668,6669],{"class":225},"\"Content-Security-Policy\"\n",[205,6671,6672,6675,6677],{"class":207,"line":387},[205,6673,6674],{"class":218},"  content",[205,6676,222],{"class":211},[205,6678,6679],{"class":225},"\"default-src 'self'\"\n",[205,6681,6682],{"class":207,"line":393},[205,6683,234],{"class":211},[16,6685,6686],{},"but an HTTP header is generally preferable for production.",[16,6688,6689,6690,1405,6692,1412,6694,6697,6698,34],{},"Meta-delivered CSP has important limitations. It cannot provide report-only policies, and CSP Level 3 specifies that directives including ",[154,6691,5875],{},[154,6693,6624],{},[154,6695,6696],{},"sandbox"," are not supported through the meta mechanism. A meta policy also cannot retroactively control resources processed before the browser encounters it. (",[28,6699,5705],{"href":5904,"rel":6700},[32],[11,6702,6704],{"id":6703},"common-csp-mistakes","Common CSP Mistakes",[16,6706,6707,6708,6710,6711,6714,6715,697,6717,257],{},"The most common engineering mistakes are not syntax errors but trust-model errors: treating a huge hostname list as strong protection, reusing nonce values, automatically adding domains after every violation, enabling ",[154,6709,6515],{}," to make errors disappear, or assuming ",[154,6712,6713],{},"default-src 'none'"," also configures directives such as ",[154,6716,5875],{},[154,6718,5865],{},[16,6720,6721,6722,34],{},"Another subtle mistake is delivering multiple CSP policies and expecting the second one to loosen the first. Multiple enforced policies are applied together: a request must satisfy all applicable policies. A second header cannot simply override an earlier restrictive policy. (",[28,6723,5705],{"href":5904,"rel":6724},[32],[11,6726,690],{"id":689},[16,6728,6729],{},"Start from the application's real resource graph rather than copying a generic CSP generator result.",[16,6731,6732,6733,6735,6736,1405,6738,1405,6740,1412,6742,6744],{},"For dynamically rendered applications, prefer a properly generated per-response nonce and a strict ",[154,6734,5769],{},". For static applications, investigate a hash-based policy. Explicitly define security-sensitive directives such as ",[154,6737,5841],{},[154,6739,5851],{},[154,6741,5865],{},[154,6743,5875],{}," according to the product's actual requirements.",[16,6746,6747],{},"Deploy the proposed policy in report-only mode first, investigate violations, remove incompatible JavaScript patterns, then enable enforcement.",[16,6749,6750],{},"Most importantly, keep CSP in the correct place in the security model: it is a browser-enforced containment mechanism, not permission to leave XSS vulnerabilities unfixed.",[11,6752,719],{"id":718},[721,6754,6756],{"id":6755},"does-csp-prevent-all-xss","Does CSP prevent all XSS?",[16,6758,6759,6760,34],{},"No. CSP can substantially restrict script execution and reduce the impact of many XSS vulnerabilities, but bypasses remain possible when trusted scripts themselves expose exploitable behavior. Input handling, context-aware output encoding, sanitization and secure application design remain necessary. (",[28,6761,958],{"href":5715,"rel":6762},[32],[721,6764,6766,6767,6769],{"id":6765},"should-every-website-use-default-src-none","Should every website use ",[154,6768,6713],{},"?",[16,6771,6772,6773,257],{},"Not automatically. It is a strong starting posture because resources must then be deliberately permitted, but the resulting directives still need to match the application's architecture. Some directives do not inherit from ",[154,6774,5744],{},[721,6776,6778],{"id":6777},"should-i-use-a-nonce-or-a-hash","Should I use a nonce or a hash?",[16,6780,6781,6782,34],{},"Use a nonce when the server can generate and modify HTML for every response. Hashes are often more practical for stable static HTML. (",[28,6783,5995],{"href":5993,"rel":6784},[32],[721,6786,6788],{"id":6787},"can-csp-be-configured-in-nginx","Can CSP be configured in Nginx?",[16,6790,6791],{},"Yes. Nginx can send CSP headers, but nonce-based CSP usually requires coordination with the application or rendering layer because a fresh nonce must appear in both the response header and authorized HTML.",[721,6793,6795],{"id":6794},"how-do-i-know-whether-csp-works","How do I know whether CSP works?",[16,6797,6798],{},"Inspect the actual response headers, test expected application flows, watch browser DevTools for CSP violations, collect reports during report-only deployment, deliberately test prohibited resources, and repeat those tests after enforcement.",[11,6800,771],{"id":770},[16,6802,6803],{},"A useful CSP is not merely a list of trusted domains. It is an explicit browser-enforced trust model.",[16,6805,6806],{},"The strongest practical approach for many modern applications is a strict policy based on cryptographic nonces or hashes, supported by directives that constrain framing, form submissions, plugins and other resources. Deploy it gradually, measure violations before enforcement, and treat every exception as an architectural decision rather than another hostname to append.",[11,6808,787],{"id":786},[646,6810,6811,6824,6837,6849,6861,6873,6889],{},[649,6812,6813,6816,6817,6468,6820],{},[23,6814,6815],{},"W3C — Content Security Policy Level 3",", Working Draft, August 13, 2026. (",[28,6818,5705],{"href":5904,"rel":6819},[32],[28,6821,6823],{"href":5904,"rel":6822},[32],"W3C CSP Level 3 specification",[649,6825,6826,6829,6830,6468,6833],{},[23,6827,6828],{},"MDN Web Docs — Content Security Policy (CSP)",", accessed September 19, 2026. (",[28,6831,5995],{"href":5993,"rel":6832},[32],[28,6834,6836],{"href":5993,"rel":6835},[32],"MDN CSP Guide",[649,6838,6839,6829,6842,6468,6845],{},[23,6840,6841],{},"MDN Web Docs — Content-Security-Policy header",[28,6843,5995],{"href":6248,"rel":6844},[32],[28,6846,6848],{"href":6248,"rel":6847},[32],"MDN CSP Header Reference",[649,6850,6851,6829,6854,6468,6857],{},[23,6852,6853],{},"web.dev — Mitigate cross-site scripting (XSS) with a strict Content Security Policy (CSP)",[28,6855,958],{"href":5715,"rel":6856},[32],[28,6858,6860],{"href":5715,"rel":6859},[32],"web.dev Strict CSP Guide",[649,6862,6863,6829,6866,6468,6869],{},[23,6864,6865],{},"MDN Web Docs — Content Security Policy implementation",[28,6867,5995],{"href":6560,"rel":6868},[32],[28,6870,6872],{"href":6560,"rel":6871},[32],"MDN CSP Implementation Guide",[649,6874,6875,6829,6881,6468,6885],{},[23,6876,6877,6878,6880],{},"MDN Web Docs — ",[154,6879,5875],{}," directive",[28,6882,5995],{"href":6883,"rel":6884},"https:\u002F\u002Fdeveloper.mozilla.org\u002Fen-US\u002Fdocs\u002FWeb\u002FHTTP\u002FReference\u002FHeaders\u002FContent-Security-Policy\u002Fframe-ancestors?utm_source=chatgpt.com",[32],[28,6886,6888],{"href":6883,"rel":6887},[32],"MDN frame-ancestors Reference",[649,6890,6891,6829,6896,6468,6900],{},[23,6892,6877,6893],{},[154,6894,6895],{},"Content-Security-Policy-Report-Only",[28,6897,5995],{"href":6898,"rel":6899},"https:\u002F\u002Fdeveloper.mozilla.org\u002Fen-US\u002Fdocs\u002FWeb\u002FHTTP\u002FReference\u002FHeaders\u002FContent-Security-Policy-Report-Only?utm_source=chatgpt.com",[32],[28,6901,6903],{"href":6898,"rel":6902},[32],"MDN CSP Report-Only Reference",[890,6905,6906],{},"html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sVt8B, html code.shiki .sVt8B{--shiki-default:#24292E;--shiki-dark:#E1E4E8}html pre.shiki code .s9eBZ, html code.shiki .s9eBZ{--shiki-default:#22863A;--shiki-dark:#85E89D}html pre.shiki code .sScJk, html code.shiki .sScJk{--shiki-default:#6F42C1;--shiki-dark:#B392F0}html pre.shiki code .sZZnC, html code.shiki .sZZnC{--shiki-default:#032F62;--shiki-dark:#9ECBFF}",{"title":201,"searchDepth":381,"depth":381,"links":6908},[6909,6910,6911,6912,6913,6914,6916,6917,6919,6920,6921,6923,6924,6925,6926,6927],{"id":5696,"depth":381,"text":5697},{"id":5719,"depth":381,"text":5720},{"id":5908,"depth":381,"text":5909},{"id":5998,"depth":381,"text":5999},{"id":6099,"depth":381,"text":6100},{"id":6147,"depth":381,"text":6915},"What strict-dynamic Does",{"id":6255,"depth":381,"text":6256},{"id":6347,"depth":381,"text":6918},"Avoid unsafe-inline",{"id":6521,"depth":381,"text":6522},{"id":6575,"depth":381,"text":6576},{"id":6640,"depth":381,"text":6922},"Header vs \u003Cmeta>",{"id":6703,"depth":381,"text":6704},{"id":689,"depth":381,"text":690},{"id":718,"depth":381,"text":719},{"id":770,"depth":381,"text":771},{"id":786,"depth":381,"text":787},"Learn how Content Security Policy works, how strict CSP uses nonces and hashes, how to deploy it safely, diagnose violations, and avoid common CSP mistakes.","\u002Fcsp-guide.png","Image of CSP",{},"\u002Fblog\u002Fen\u002Fcsp-guide","2026-09-19",{"title":5691,"description":6928},"csp-guide","blog\u002Fen\u002Fcsp-guide","content-security-policy","8JqZxZsLmTafoA3nSncdbeBRdng4dtViqE3fp9iX5GY",{"id":6940,"title":6941,"author":6,"body":6942,"category":4091,"description":7661,"draft":912,"extension":913,"featured":914,"image":7662,"imageAlt":7663,"locale":917,"meta":7664,"navigation":914,"path":7665,"publishedAt":6933,"seo":7666,"slug":7667,"stem":7668,"translationKey":7667,"updatedAt":6933,"__hash__":7669},"blog\u002Fblog\u002Fen\u002Fhsts-explained.md","HSTS Explained: Benefits, Risks and Safe Deployment",{"type":8,"value":6943,"toc":7644},[6944,6948,6951,6966,6976,6978,6981,6984,6993,7006,7009,7011,7078,7092,7096,7099,7105,7112,7115,7121,7124,7127,7132,7136,7139,7148,7157,7164,7167,7171,7174,7177,7183,7190,7198,7208,7218,7222,7225,7228,7237,7240,7243,7252,7255,7263,7269,7280,7284,7287,7295,7316,7319,7328,7337,7341,7344,7355,7376,7382,7386,7389,7403,7418,7421,7429,7435,7437,7443,7449,7464,7470,7472,7475,7487,7490,7492,7496,7499,7503,7509,7513,7516,7525,7531,7535,7541,7543,7546,7549,7558,7560,7642],[11,6945,6947],{"id":6946},"hsts-explained-security-benefit-and-deployment-risk","HSTS Explained: Security Benefit and Deployment Risk",[16,6949,6950],{},"HSTS is one of the simplest HTTP security mechanisms to configure—and one of the easiest to deploy too aggressively.",[16,6952,6953,6954,6957,6958,6961,6962,34],{},"HTTP Strict Transport Security, or ",[23,6955,6956],{},"HSTS",", tells a browser that a domain must be accessed only over HTTPS. Once the browser has learned that policy, an attempt to open ",[154,6959,6960],{},"http:\u002F\u002Fexample.com"," is upgraded to HTTPS before an insecure HTTP request is sent. HSTS also prevents users from bypassing certificate errors for that host. (",[28,6963,2340],{"href":6964,"rel":6965},"https:\u002F\u002Fwww.rfc-editor.org\u002Finfo\u002Frfc6797\u002F?utm_source=chatgpt.com",[32],[16,6967,6968,6969,1405,6972,6975],{},"The security benefit is significant: HSTS reduces the opportunity for HTTPS downgrade and SSL-stripping attacks. The deployment risk is equally important: a long ",[154,6970,6971],{},"max-age",[154,6973,6974],{},"includeSubDomains",", or HSTS preloading can make misconfigured or HTTP-only hosts inaccessible until the underlying HTTPS problem is fixed.",[11,6977,38],{"id":37},[16,6979,6980],{},"HSTS is an HTTP response header that tells supporting browsers to use HTTPS for a domain for a specified period.",[16,6982,6983],{},"A typical policy looks like this:",[196,6985,6987],{"className":5730,"code":6986,"language":5732,"meta":201,"style":201},"Strict-Transport-Security: max-age=31536000; includeSubDomains\n",[154,6988,6989],{"__ignoreMap":201},[205,6990,6991],{"class":207,"line":208},[205,6992,6986],{},[16,6994,6995,6996,6999,7000,7002,7003,34],{},"Here, ",[154,6997,6998],{},"max-age=31536000"," means the browser remembers the HSTS policy for approximately one year. ",[154,7001,6974],{}," extends that policy to subdomains. Browsers only accept the HSTS header over a secure connection; an HSTS header received over plain HTTP is ignored. (",[28,7004,2340],{"href":6964,"rel":7005},[32],[16,7007,7008],{},"HSTS strengthens HTTPS deployment. It does not replace HTTPS, TLS certificates, redirects, or correct server configuration.",[11,7010,68],{"id":67},[70,7012,7013,7026],{},[73,7014,7015],{},[76,7016,7017,7020,7023],{},[79,7018,7019],{},"Feature",[79,7021,7022],{},"What It Does",[79,7024,7025],{},"Main Risk",[89,7027,7028,7040,7052,7065],{},[76,7029,7030,7034,7037],{},[94,7031,7032],{},[154,7033,6971],{},[94,7035,7036],{},"Stores the HSTS policy for a number of seconds",[94,7038,7039],{},"Mistakes can persist until the policy expires",[76,7041,7042,7046,7049],{},[94,7043,7044],{},[154,7045,6974],{},[94,7047,7048],{},"Extends HSTS to subdomains",[94,7050,7051],{},"HTTP-only subdomains can become inaccessible",[76,7053,7054,7059,7062],{},[94,7055,7056],{},[154,7057,7058],{},"preload",[94,7060,7061],{},"Signals intent to participate in browser preload programs",[94,7063,7064],{},"Creates a longer-term domain-wide commitment",[76,7066,7067,7072,7075],{},[94,7068,7069],{},[154,7070,7071],{},"max-age=0",[94,7073,7074],{},"Removes a dynamically learned HSTS policy",[94,7076,7077],{},"Browser must first reach the site securely to receive it",[16,7079,7080,7081,697,7083,7085,7086,7088,7089,34],{},"RFC 6797 defines ",[154,7082,6971],{},[154,7084,6974],{},". The ",[154,7087,7058],{}," mechanism is an additional browser ecosystem feature rather than part of the HSTS specification itself. (",[28,7090,2340],{"href":6964,"rel":7091},[32],[11,7093,7095],{"id":7094},"why-hsts-matters","Why HSTS Matters",[16,7097,7098],{},"Consider a website that redirects HTTP visitors to HTTPS:",[196,7100,7103],{"className":7101,"code":7102,"language":454,"meta":201},[452],"http:\u002F\u002Fexample.com\n        ↓\n301 redirect\n        ↓\nhttps:\u002F\u002Fexample.com\n",[154,7104,7102],{"__ignoreMap":201},[16,7106,7107,7108,34],{},"That redirect helps normal users reach HTTPS, but the initial HTTP request is still unencrypted. An attacker controlling the network could potentially interfere before the HTTPS connection is established. MDN describes this as the first-connection window in which SSL stripping remains possible. (",[28,7109,5995],{"href":7110,"rel":7111},"https:\u002F\u002Fdeveloper.mozilla.org\u002Fen-US\u002Fdocs\u002FWeb\u002FSecurity\u002FDefenses\u002FTransport_Layer_Security?utm_source=chatgpt.com",[32],[16,7113,7114],{},"After a browser learns an HSTS policy, the sequence changes:",[196,7116,7119],{"className":7117,"code":7118,"language":454,"meta":201},[452],"User requests http:\u002F\u002Fexample.com\n        ↓\nBrowser sees stored HSTS policy\n        ↓\nBrowser changes request to HTTPS\n        ↓\nHTTPS connection\n",[154,7120,7118],{"__ignoreMap":201},[16,7122,7123],{},"The insecure request is avoided.",[16,7125,7126],{},"This distinction matters: an HTTP-to-HTTPS redirect happens after an HTTP request reaches the server, while HSTS can cause the browser to upgrade the request locally before sending it.",[16,7128,7129],{},[205,7130,7131],{},"INTERNAL LINK: How HTTPS and TLS Work",[11,7133,7135],{"id":7134},"how-hsts-works","How HSTS Works",[16,7137,7138],{},"When an HTTPS response contains:",[196,7140,7142],{"className":5730,"code":7141,"language":5732,"meta":201,"style":201},"Strict-Transport-Security: max-age=31536000\n",[154,7143,7144],{"__ignoreMap":201},[205,7145,7146],{"class":207,"line":208},[205,7147,7141],{},[16,7149,7150,7151,7153,7154,34],{},"the browser records that host as an HSTS host. The ",[154,7152,6971],{}," value acts as a time-to-live measured from when the browser receives the header. Future qualifying HTTP requests are upgraded to HTTPS. Each later HSTS response can refresh the expiration time. (",[28,7155,2340],{"href":6964,"rel":7156},[32],[16,7158,7159,7160,34],{},"There is another important behavior: TLS certificate errors become non-bypassable for an HSTS host. A user normally presented with a certificate warning may sometimes have an option to continue. HSTS intentionally removes that escape route because allowing the user through would undermine the security policy. (",[28,7161,5995],{"href":7162,"rel":7163},"https:\u002F\u002Fdeveloper.mozilla.org\u002Fen-US\u002Fdocs\u002FWeb\u002FHTTP\u002FReference\u002FHeaders\u002FStrict-Transport-Security?utm_source=chatgpt.com",[32],[16,7165,7166],{},"That is useful during an attack—but painful during an operational mistake.",[11,7168,7170],{"id":7169},"the-deployment-risk","The Deployment Risk",[16,7172,7173],{},"The biggest HSTS mistake is treating the strongest configuration as the default starting point.",[16,7175,7176],{},"Imagine this domain structure:",[196,7178,7181],{"className":7179,"code":7180,"language":454,"meta":201},[452],"example.com\nwww.example.com\napi.example.com\nlegacy.example.com\ninternal.example.com\n",[154,7182,7180],{"__ignoreMap":201},[16,7184,7185,7186,7189],{},"Suppose ",[154,7187,7188],{},"legacy.example.com"," still works only over HTTP. Enabling this immediately on the parent domain would be dangerous:",[196,7191,7192],{"className":5730,"code":6986,"language":5732,"meta":201,"style":201},[154,7193,7194],{"__ignoreMap":201},[205,7195,7196],{"class":207,"line":208},[205,7197,6986],{},[16,7199,7200,7201,7204,7205,7207],{},"A browser that receives the policy can begin requiring HTTPS for descendants of ",[154,7202,7203],{},"example.com",". If ",[154,7206,7188],{}," cannot serve valid HTTPS, users may no longer be able to access it.",[16,7209,7210,7211,7213,7214,34],{},"This is why ",[154,7212,6974],{}," should be enabled only after the relevant subdomain inventory has been checked and HTTPS support has been verified. MDN specifically warns that the directive can disable access to subdomains that do not yet support HTTPS. (",[28,7215,5995],{"href":7216,"rel":7217},"https:\u002F\u002Fdeveloper.mozilla.org\u002Fen-US\u002Fdocs\u002FWeb\u002FSecurity\u002FPractical_implementation_guides\u002FTLS?utm_source=chatgpt.com",[32],[11,7219,7221],{"id":7220},"safer-deployment","Safer Deployment",[16,7223,7224],{},"A safer rollout is progressive rather than immediate.",[16,7226,7227],{},"Start by confirming that the main domain works correctly over HTTPS. Then use a short HSTS lifetime, for example:",[196,7229,7231],{"className":5730,"code":7230,"language":5732,"meta":201,"style":201},"Strict-Transport-Security: max-age=300\n",[154,7232,7233],{"__ignoreMap":201},[205,7234,7235],{"class":207,"line":208},[205,7236,7230],{},[16,7238,7239],{},"This gives a five-minute policy window.",[16,7241,7242],{},"After confirming certificate renewal, redirects, CDN behavior, application routes, error responses and other infrastructure, increase the duration gradually:",[196,7244,7246],{"className":5730,"code":7245,"language":5732,"meta":201,"style":201},"Strict-Transport-Security: max-age=86400\n",[154,7247,7248],{"__ignoreMap":201},[205,7249,7250],{"class":207,"line":208},[205,7251,7245],{},[16,7253,7254],{},"Then, after further validation:",[196,7256,7257],{"className":5730,"code":7141,"language":5732,"meta":201,"style":201},[154,7258,7259],{"__ignoreMap":201},[205,7260,7261],{"class":207,"line":208},[205,7262,7141],{},[16,7264,7265,7266,7268],{},"Only add ",[154,7267,6974],{}," when HTTPS is reliably supported throughout the intended subdomain tree.",[16,7270,7271,7272,7274,7275,34],{},"This gradual increase is a SeoNest deployment recommendation rather than a requirement of RFC 6797. The current HSTS preload service also advises operators to ramp up ",[154,7273,6971],{}," before submitting a domain for preloading. (",[28,7276,7279],{"href":7277,"rel":7278},"https:\u002F\u002Fhstspreload.org\u002F?domain=pocketbase.io&utm_source=chatgpt.com",[32],"hstspreload.org",[11,7281,7283],{"id":7282},"hsts-preloading","HSTS Preloading",[16,7285,7286],{},"Normal HSTS has a limitation: a browser must usually receive the HSTS header before it knows the policy. A new browser profile therefore still has an initial connection window.",[16,7288,7289,7290,34],{},"HSTS preloading addresses this by shipping a list of HSTS domains with browsers. Chromium documents that Chrome maintains such a preload list and that other browsers use lists based on it. (",[28,7291,7294],{"href":7292,"rel":7293},"https:\u002F\u002Fwww.chromium.org\u002Fhsts\u002F?utm_source=chatgpt.com",[32],"chromium.org",[16,7296,7297,7298,7300,7301,1405,7303,7305,7306,7308,7309,7312,7313,34],{},"The current submission requirements at ",[154,7299,7279],{}," include a valid certificate, HTTP-to-HTTPS redirection on the same host when HTTP is served, HTTPS support across subdomains, ",[154,7302,6974],{},[154,7304,7058],{},", and a ",[154,7307,6971],{}," of at least ",[154,7310,7311],{},"31536000"," seconds. (",[28,7314,7279],{"href":7277,"rel":7315},[32],[16,7317,7318],{},"A typical preload-ready header is:",[196,7320,7322],{"className":5730,"code":7321,"language":5732,"meta":201,"style":201},"Strict-Transport-Security: max-age=63072000; includeSubDomains; preload\n",[154,7323,7324],{"__ignoreMap":201},[205,7325,7326],{"class":207,"line":208},[205,7327,7321],{},[16,7329,7330,7331,7333,7334,34],{},"But preloading should not be enabled casually. The preload service explicitly warns projects not to enable ",[154,7332,7058],{}," by default and notes that removal can be slow. Its current guidance recommends HSTS itself while taking a more cautious position on HSTS preloading. (",[28,7335,7279],{"href":7277,"rel":7336},[32],[11,7338,7340],{"id":7339},"nginx-example","Nginx Example",[16,7342,7343],{},"For Nginx:",[196,7345,7349],{"className":7346,"code":7347,"language":7348,"meta":201,"style":201},"language-nginx shiki shiki-themes github-light github-dark","add_header Strict-Transport-Security \"max-age=31536000\" always;\n","nginx",[154,7350,7351],{"__ignoreMap":201},[205,7352,7353],{"class":207,"line":208},[205,7354,7347],{},[16,7356,1098,7357,7359,7360,7363,7364,1516,7367,7370,7371,34],{},[154,7358,3546],{}," parameter makes Nginx add the header regardless of response status. Nginx also has specific inheritance behavior for ",[154,7361,7362],{},"add_header",", so nested ",[154,7365,7366],{},"server",[154,7368,7369],{},"location"," configuration should be reviewed rather than assuming the header is inherited everywhere. (",[28,7372,7375],{"href":7373,"rel":7374},"https:\u002F\u002Fnginx.org\u002Fen\u002Fdocs\u002Fhttp\u002Fngx_http_headers_module.html?utm_source=chatgpt.com",[32],"nginx.org",[16,7377,7378,7379,34],{},"Do not send HSTS from an HTTP-only endpoint expecting the browser to trust it. Browsers intentionally ignore HSTS headers delivered over insecure HTTP. (",[28,7380,5995],{"href":7162,"rel":7381},[32],[11,7383,7385],{"id":7384},"verify-the-deployment","Verify the Deployment",[16,7387,7388],{},"Check the HTTPS response headers directly:",[196,7390,7392],{"className":3572,"code":7391,"language":3574,"meta":201,"style":201},"curl -I https:\u002F\u002Fexample.com\n",[154,7393,7394],{"__ignoreMap":201},[205,7395,7396,7398,7400],{"class":207,"line":208},[205,7397,4468],{"class":218},[205,7399,4471],{"class":1277},[205,7401,7402],{"class":225}," https:\u002F\u002Fexample.com\n",[16,7404,7405,7408,7409,7412,7413,34],{},[154,7406,7407],{},"curl -I"," retrieves the HTTP response headers, allowing you to confirm that ",[154,7410,7411],{},"Strict-Transport-Security"," is actually present. (",[28,7414,7417],{"href":7415,"rel":7416},"https:\u002F\u002Fcurl.se\u002Fdocs\u002Ftutorial.html?utm_source=chatgpt.com",[32],"curl.se",[16,7419,7420],{},"Look for:",[196,7422,7423],{"className":5730,"code":7141,"language":5732,"meta":201,"style":201},[154,7424,7425],{"__ignoreMap":201},[205,7426,7427],{"class":207,"line":208},[205,7428,7141],{},[16,7430,7431,7432,7434],{},"Also test redirects, error responses, important subdomains and certificate validity. If you plan to use ",[154,7433,6974],{},", testing only the apex domain is not enough.",[11,7436,1750],{"id":1749},[16,7438,7439,7442],{},[23,7440,7441],{},"HSTS redirects HTTP to HTTPS on the server.","\nNot exactly. Once the policy is known, the browser can upgrade the request before making the insecure HTTP connection.",[16,7444,7445,7448],{},[23,7446,7447],{},"HSTS fixes an expired certificate.","\nNo. It makes certificate failures stricter. A broken certificate can therefore make an HSTS-protected site completely inaccessible until the certificate problem is fixed.",[16,7450,7451,7454,7455,7457,7458,7460,7461,34],{},[23,7452,7453],{},"Removing the header immediately disables HSTS.","\nNo. A previously stored policy remains active until its ",[154,7456,6971],{}," expires. Sending ",[154,7459,7071],{}," removes a dynamic HSTS policy when the browser successfully receives that response over HTTPS. (",[28,7462,2340],{"href":6964,"rel":7463},[32],[16,7465,7466,7469],{},[23,7467,7468],{},"Every HTTPS site should immediately use preload.","\nHSTS and HSTS preloading are separate decisions. Preloading creates a stronger operational commitment and should follow a deliberate review of the entire domain namespace.",[11,7471,690],{"id":689},[16,7473,7474],{},"Enable HSTS after HTTPS is already stable—not as a way to make an unstable HTTPS deployment secure.",[16,7476,7477,7478,7480,7481,7483,7484,7486],{},"Start with the main hostname and a short ",[154,7479,6971],{},". Validate certificates, redirects, CDN behavior, application errors and renewal automation. Increase ",[154,7482,6971],{}," gradually. Add ",[154,7485,6974],{}," only after verifying the relevant subdomains. Treat preloading as a separate infrastructure decision because its consequences extend beyond a normal response header.",[16,7488,7489],{},"The goal is not to configure the strongest-looking header. It is to create an HTTPS policy your infrastructure can reliably honor.",[11,7491,719],{"id":718},[721,7493,7495],{"id":7494},"does-hsts-improve-seo","Does HSTS improve SEO?",[16,7497,7498],{},"HSTS is primarily a transport-security mechanism. Google has not documented HSTS itself as a direct ranking factor in the sources used for this article. Its value should therefore be evaluated mainly in terms of HTTPS security and deployment reliability, not assumed ranking improvements.",[721,7500,7502],{"id":7501},"does-hsts-affect-the-first-visit","Does HSTS affect the first visit?",[16,7504,7505,7506,34],{},"Ordinary dynamically learned HSTS cannot fully protect a browser that has never learned the site's policy. Preloading can remove that initial gap for included domains. (",[28,7507,5995],{"href":7110,"rel":7508},[32],[721,7510,7512],{"id":7511},"can-hsts-be-disabled","Can HSTS be disabled?",[16,7514,7515],{},"For a dynamically stored policy, the server can send:",[196,7517,7519],{"className":5730,"code":7518,"language":5732,"meta":201,"style":201},"Strict-Transport-Security: max-age=0\n",[154,7520,7521],{"__ignoreMap":201},[205,7522,7523],{"class":207,"line":208},[205,7524,7518],{},[16,7526,7527,7528,34],{},"over HTTPS. The browser then removes that host's stored HSTS policy as defined by RFC 6797. (",[28,7529,2340],{"href":6964,"rel":7530},[32],[721,7532,7534],{"id":7533},"should-apis-use-hsts","Should APIs use HSTS?",[16,7536,7537,7538,7540],{},"If an API hostname is accessed by user agents that implement HSTS, it can benefit from the same transport policy. Whether ",[154,7539,6974],{}," should be applied at a parent domain still depends on the HTTPS readiness of the wider domain tree.",[11,7542,771],{"id":770},[16,7544,7545],{},"HSTS closes an important weakness in ordinary HTTP-to-HTTPS redirection by telling browsers to require HTTPS in future connections. Its strength comes from persistence: browsers remember the policy and refuse insecure fallback.",[16,7547,7548],{},"That persistence is also the deployment risk.",[16,7550,7551,7552,7554,7555,7557],{},"Use HSTS deliberately. Stabilize HTTPS first, start with a manageable ",[154,7553,6971],{},", expand coverage only after testing, and approach ",[154,7556,6974],{}," and preloading as infrastructure commitments rather than harmless header options.",[11,7559,787],{"id":786},[646,7561,7562,7576,7585,7594,7603,7612,7626],{},[649,7563,7564,7567,7568,1405,7570,7572,7573,34],{},[23,7565,7566],{},"RFC Editor — RFC 6797: HTTP Strict Transport Security (HSTS)",", November 2012. Defines HSTS processing, ",[154,7569,6971],{},[154,7571,6974],{},", expiration and removal behavior. (",[28,7574,2340],{"href":6964,"rel":7575},[32],[649,7577,7578,7581,7582,34],{},[23,7579,7580],{},"MDN Web Docs — Strict-Transport-Security header."," Practical browser behavior, syntax, certificate handling, subdomains and preload context. (",[28,7583,5995],{"href":7162,"rel":7584},[32],[649,7586,7587,7590,7591,34],{},[23,7588,7589],{},"MDN Web Docs — Transport Layer Security."," HTTPS upgrade behavior, SSL stripping and the first-connection limitation of dynamically learned HSTS. (",[28,7592,5995],{"href":7110,"rel":7593},[32],[649,7595,7596,7599,7600,34],{},[23,7597,7598],{},"Chromium — HTTP Strict Transport Security."," Chromium's description of HSTS behavior and browser preload lists. (",[28,7601,7294],{"href":7292,"rel":7602},[32],[649,7604,7605,7608,7609,34],{},[23,7606,7607],{},"HSTS Preload List Submission — hstspreload.org."," Current preload requirements, operational warnings and submission guidance. (",[28,7610,7279],{"href":7277,"rel":7611},[32],[649,7613,7614,7617,7618,1405,7620,7622,7623,34],{},[23,7615,7616],{},"NGINX — ngx_http_headers_module."," Official documentation for ",[154,7619,7362],{},[154,7621,3546],{}," and header inheritance. (",[28,7624,7375],{"href":7373,"rel":7625},[32],[649,7627,7628,7631,7632,1358,7635,7638,7639,34],{},[23,7629,7630],{},"curl — Tutorial."," Official documentation for using ",[154,7633,7634],{},"-I",[154,7636,7637],{},"--head"," to inspect HTTP headers. (",[28,7640,7417],{"href":7415,"rel":7641},[32],[890,7643,4914],{},{"title":201,"searchDepth":381,"depth":381,"links":7645},[7646,7647,7648,7649,7650,7651,7652,7653,7654,7655,7656,7657,7658,7659,7660],{"id":6946,"depth":381,"text":6947},{"id":37,"depth":381,"text":38},{"id":67,"depth":381,"text":68},{"id":7094,"depth":381,"text":7095},{"id":7134,"depth":381,"text":7135},{"id":7169,"depth":381,"text":7170},{"id":7220,"depth":381,"text":7221},{"id":7282,"depth":381,"text":7283},{"id":7339,"depth":381,"text":7340},{"id":7384,"depth":381,"text":7385},{"id":1749,"depth":381,"text":1750},{"id":689,"depth":381,"text":690},{"id":718,"depth":381,"text":719},{"id":770,"depth":381,"text":771},{"id":786,"depth":381,"text":787},"Learn how HSTS forces HTTPS, prevents downgrade attacks, how max-age, includeSubDomains and preload work, and why careless deployment can break access to a site.","\u002Fhsts-explained.png","Image of HSTS",{},"\u002Fblog\u002Fen\u002Fhsts-explained",{"title":6941,"description":7661},"hsts-explained","blog\u002Fen\u002Fhsts-explained","4znvyUGbUeSMoZa-B-mt5xGC8yoQxZAWhl4hwun0RF4",{"id":7671,"title":7672,"author":6,"body":7673,"category":910,"description":8348,"draft":912,"extension":913,"featured":914,"image":8349,"imageAlt":8350,"locale":917,"meta":8351,"navigation":914,"path":8352,"publishedAt":6933,"seo":8353,"slug":7729,"stem":8354,"translationKey":7729,"updatedAt":6933,"__hash__":8355},"blog\u002Fblog\u002Fen\u002Fkeywords-vs-entities.md","Keywords vs Entities: What Is the Difference in SEO?",{"type":8,"value":7674,"toc":8328},[7675,7679,7686,7696,7699,7701,7706,7721,7724,7727,7731,7813,7816,7818,7831,7838,7841,7845,7848,7851,7854,7857,7862,7865,7888,7891,7898,7902,7905,7908,7913,7924,7927,7932,7935,7938,7943,7947,7950,7953,7956,7959,7964,7967,7978,7981,7984,7988,7991,7994,7996,8058,8064,8070,8075,8079,8082,8089,8103,8109,8116,8119,8124,8126,8130,8133,8137,8140,8143,8147,8150,8154,8160,8163,8165,8168,8171,8174,8177,8183,8185,8189,8192,8196,8199,8203,8215,8219,8222,8226,8229,8231,8237,8243,8246,8252,8257,8259,8325],[11,7676,7678],{"id":7677},"keywords-vs-entities-what-is-the-difference","Keywords vs Entities: What Is the Difference?",[16,7680,7681,7682,7685],{},"SEO discussions increasingly use the word ",[23,7683,7684],{},"entity",", sometimes as if entities have replaced keywords. That creates a false choice.",[16,7687,7688,7689,7692,7693,7695],{},"Keywords and entities describe different things. A ",[23,7690,7691],{},"keyword"," is a word or phrase people use to express a search need or that appears in content. An ",[23,7694,7684],{}," is a distinct thing or concept that can be identified and connected to other things: a person, company, product, location, event, organization, or similar subject.",[16,7697,7698],{},"Modern search systems use both language and meaning. Google still advises publishers to consider the words people may search for, while also documenting systems that understand concepts, intent, and real-world entities.",[11,7700,38],{"id":37},[16,7702,7703],{},[23,7704,7705],{},"Keywords represent language. Entities represent meaning and identity.",[16,7707,7708,7709,7712,7713,7716,7717,7720],{},"For example, ",[154,7710,7711],{},"apple laptop"," is a keyword phrase. ",[23,7714,7715],{},"Apple Inc."," is an entity, ",[23,7718,7719],{},"MacBook Pro"," is another entity, and the relationship between them can be expressed as Apple manufacturing the MacBook Pro.",[16,7722,7723],{},"A search engine does not have to rely only on exact word matching. It can analyze the words in a query, infer their meaning, identify relevant concepts or entities, and retrieve pages that satisfy the search intent.",[16,7725,7726],{},"That does not make keywords obsolete. It means exact wording is only one part of understanding relevance.",[11,7728,7730],{"id":7729},"keywords-vs-entities","Keywords vs Entities",[70,7732,7733,7745],{},[73,7734,7735],{},[76,7736,7737,7739,7742],{},[79,7738],{},[79,7740,7741],{},"Keywords",[79,7743,7744],{},"Entities",[89,7746,7747,7758,7770,7780,7791,7802],{},[76,7748,7749,7752,7755],{},[94,7750,7751],{},"Represents",[94,7753,7754],{},"Words or phrases",[94,7756,7757],{},"Identifiable things or concepts",[76,7759,7760,7762,7767],{},[94,7761,5035],{},[94,7763,7764],{},[154,7765,7766],{},"iphone repair london",[94,7768,7769],{},"iPhone, Apple Inc., London",[76,7771,7772,7775,7777],{},[94,7773,7774],{},"Depends on wording",[94,7776,99],{},[94,7778,7779],{},"Identity can remain the same across different names",[76,7781,7782,7785,7788],{},[94,7783,7784],{},"Can have relationships",[94,7786,7787],{},"Mainly through language\u002Fcontext",[94,7789,7790],{},"Yes, explicitly or implicitly",[76,7792,7793,7796,7799],{},[94,7794,7795],{},"Main SEO use",[94,7797,7798],{},"Search demand, terminology, page relevance",[94,7800,7801],{},"Topic clarity, identity, context, relationships",[76,7803,7804,7807,7810],{},[94,7805,7806],{},"Structured data required?",[94,7808,7809],{},"No",[94,7811,7812],{},"No, although structured data can provide explicit information",[16,7814,7815],{},"The distinction matters because the same entity can be described with several different strings.",[16,7817,366],{},[16,7819,7820,1405,7823,7826,7827,7830],{},[23,7821,7822],{},"International Business Machines",[23,7824,7825],{},"IBM",", and potentially context-dependent references such as ",[23,7828,7829],{},"the company"," can all refer to the same organization.",[16,7832,7833,7834,7837],{},"Conversely, the same keyword can have different meanings. ",[154,7835,7836],{},"Java"," could refer to a programming language, an Indonesian island, or coffee depending on the query.",[16,7839,7840],{},"This ambiguity is one reason search systems need more than literal string matching.",[11,7842,7844],{"id":7843},"how-keywords-work","How Keywords Work",[16,7846,7847],{},"Keywords help connect the language used by a searcher with the language and subject matter of a page.",[16,7849,7850],{},"Google's SEO Starter Guide explicitly advises site owners to think about the terms different users might search for. An expert and a beginner may describe the same subject differently. However, Google also says publishers do not need to anticipate every possible variation because its language-matching systems can relate pages to queries even when the exact terms do not appear.",[16,7852,7853],{},"This changes how keyword optimization should be approached.",[16,7855,7856],{},"A page about HTTP caching does not need to repeat:",[16,7858,7859],{},[154,7860,7861],{},"HTTP caching",[16,7863,7864],{},"in every heading and paragraph. It might naturally discuss:",[789,7866,7867,7870,7873,7876,7879,7882,7885],{},[649,7868,7869],{},"browser cache",[649,7871,7872],{},"Cache-Control",[649,7874,7875],{},"cached responses",[649,7877,7878],{},"freshness",[649,7880,7881],{},"validators",[649,7883,7884],{},"ETag",[649,7886,7887],{},"revalidation",[16,7889,7890],{},"These terms help explain the actual subject rather than artificially increasing the frequency of one phrase.",[16,7892,7893,7894,7897],{},"Keyword research therefore remains useful for understanding ",[23,7895,7896],{},"how people express demand",", but keyword repetition is not a substitute for useful content.",[11,7899,7901],{"id":7900},"how-entities-work","How Entities Work",[16,7903,7904],{},"Google introduced its Knowledge Graph in 2012 as a system for understanding real-world people, places, and things and the relationships between them rather than treating searches only as strings of characters.",[16,7906,7907],{},"Consider:",[16,7909,7910],{},[23,7911,7912],{},"Christopher Nolan → directed → Inception",[16,7914,7915,7916,7919,7920,7923],{},"The entity ",[23,7917,7918],{},"Christopher Nolan"," has an identity. ",[23,7921,7922],{},"Inception"," has another identity. The relationship between them carries information that neither name communicates by itself.",[16,7925,7926],{},"This creates something closer to a graph:",[16,7928,7929],{},[23,7930,7931],{},"Director → Movie → Actor → Character → Award",[16,7933,7934],{},"The connections add context.",[16,7936,7937],{},"Schema.org uses a similar graph-oriented model for structured data: entities have types and properties, and those properties can connect one entity to another.",[16,7939,7940],{},[205,7941,7942],{},"INTERNAL LINK: What Is Entity SEO?",[11,7944,7946],{"id":7945},"search-is-not-exact-matching","Search Is Not Exact Matching",[16,7948,7949],{},"The shift toward richer language understanding does not mean Google stopped matching words.",[16,7951,7952],{},"Instead, several mechanisms can operate together.",[16,7954,7955],{},"Google documents BERT as a system that helps understand how combinations of words express different meanings and intent. Its ranking-systems documentation also describes neural matching as helping relate concepts in queries to relevant pages.",[16,7957,7958],{},"That distinction explains searches such as:",[16,7960,7961],{},[23,7962,7963],{},"“laptop that lasts all day without charging”",[16,7965,7966],{},"A relevant page might primarily use terms such as:",[16,7968,7969,1405,7972,1434,7975],{},[23,7970,7971],{},"battery life",[23,7973,7974],{},"18-hour battery",[23,7976,7977],{},"power efficiency",[16,7979,7980],{},"rather than repeating the exact query.",[16,7982,7983],{},"The words still matter, but search systems can attempt to understand what those words mean.",[11,7985,7987],{"id":7986},"where-structured-data-fits","Where Structured Data Fits",[16,7989,7990],{},"Structured data is often associated with entity SEO, but the two should not be treated as synonyms.",[16,7992,7993],{},"Google describes structured data as a standardized way to provide explicit clues about the meaning and classification of page content. It can describe objects such as organizations, people, products, recipes, events, and their properties.",[16,7995,366],{},[196,7997,8001],{"className":7998,"code":7999,"language":8000,"meta":201,"style":201},"language-json shiki shiki-themes github-light github-dark","{\n  \"@context\": \"https:\u002F\u002Fschema.org\",\n  \"@type\": \"Organization\",\n  \"name\": \"Example Company\",\n  \"url\": \"https:\u002F\u002Fexample.com\"\n}\n","json",[154,8002,8003,8008,8020,8032,8044,8054],{"__ignoreMap":201},[205,8004,8005],{"class":207,"line":208},[205,8006,8007],{"class":211},"{\n",[205,8009,8010,8013,8015,8018],{"class":207,"line":381},[205,8011,8012],{"class":1277},"  \"@context\"",[205,8014,1280],{"class":211},[205,8016,8017],{"class":225},"\"https:\u002F\u002Fschema.org\"",[205,8019,1721],{"class":211},[205,8021,8022,8025,8027,8030],{"class":207,"line":387},[205,8023,8024],{"class":1277},"  \"@type\"",[205,8026,1280],{"class":211},[205,8028,8029],{"class":225},"\"Organization\"",[205,8031,1721],{"class":211},[205,8033,8034,8037,8039,8042],{"class":207,"line":393},[205,8035,8036],{"class":1277},"  \"name\"",[205,8038,1280],{"class":211},[205,8040,8041],{"class":225},"\"Example Company\"",[205,8043,1721],{"class":211},[205,8045,8046,8049,8051],{"class":207,"line":1241},[205,8047,8048],{"class":1277},"  \"url\"",[205,8050,1280],{"class":211},[205,8052,8053],{"class":225},"\"https:\u002F\u002Fexample.com\"\n",[205,8055,8056],{"class":207,"line":1252},[205,8057,1306],{"class":211},[16,8059,8060,8061,257],{},"This markup explicitly says that the described object is an ",[154,8062,8063],{},"Organization",[16,8065,8066,8067,8069],{},"But adding Schema.org markup does ",[23,8068,412],{}," automatically establish authority, guarantee a Knowledge Panel, or guarantee higher rankings. Google states that structured data can help it understand content and can make pages eligible for certain search features, but even valid markup does not guarantee those features will appear.",[16,8071,8072],{},[205,8073,8074],{},"INTERNAL LINK: Structured Data Explained",[11,8076,8078],{"id":8077},"should-you-optimize-for-keywords-or-entities","Should You Optimize for Keywords or Entities?",[16,8080,8081],{},"In practice, these are complementary rather than competing strategies.",[16,8083,8084,8085,8088],{},"Use ",[23,8086,8087],{},"keyword research"," to understand:",[789,8090,8091,8094,8097,8100],{},[649,8092,8093],{},"what people search for,",[649,8095,8096],{},"which terminology they use,",[649,8098,8099],{},"what questions they ask,",[649,8101,8102],{},"and what intent sits behind those searches.",[16,8104,8105,8106,257],{},"Then build content around the ",[23,8107,8108],{},"actual subject and its relationships",[16,8110,8111,8112,8115],{},"For example, a page targeting ",[154,8113,8114],{},"largest contentful paint"," should not simply repeat that phrase. A strong explanation will naturally establish relationships with Core Web Vitals, rendering, the LCP element, resource loading, images, fonts, servers, and performance measurement where those subjects are relevant.",[16,8117,8118],{},"That produces a more complete representation of the topic for readers and gives search systems more context to work with.",[16,8120,8121],{},[205,8122,8123],{},"INTERNAL LINK: Semantic SEO Explained",[11,8125,1750],{"id":1749},[1128,8127,8129],{"id":8128},"entities-replaced-keywords","“Entities replaced keywords”",[16,8131,8132],{},"No. Google still explicitly discusses the words people use when searching. Its systems have simply become more capable of understanding relationships between different expressions, concepts, and meanings.",[1128,8134,8136],{"id":8135},"mentioning-more-entities-improves-rankings","“Mentioning more entities improves rankings”",[16,8138,8139],{},"There is no documented rule saying that adding a larger number of entity names will improve rankings.",[16,8141,8142],{},"Unnecessary entity mentions can become another form of stuffing. Every person, product, organization, technology, or concept should appear because it improves the explanation.",[1128,8144,8146],{"id":8145},"structured-data-creates-entities","“Structured data creates entities”",[16,8148,8149],{},"Structured data describes information in a machine-readable format. It can clarify identity and relationships, but markup alone should not be treated as proof that a search engine will recognize something as a particular Knowledge Graph entity.",[1128,8151,8153],{"id":8152},"entity-seo-is-a-google-ranking-factor","“Entity SEO is a Google ranking factor”",[16,8155,8156,8157],{},"Google publicly documents entity-understanding technologies and systems such as the Knowledge Graph, but it does not document a standalone ranking factor named ",[23,8158,8159],{},"“entity SEO.”",[16,8161,8162],{},"Treat entity SEO as an industry framework for thinking about meaning, identity, relationships, and semantic clarity—not as a documented Google ranking score.",[11,8164,690],{"id":689},[16,8166,8167],{},"Do not choose between keywords and entities.",[16,8169,8170],{},"Start with search intent and keyword research to understand the user's language. Then explain the subject accurately enough that its important entities, attributes, and relationships become naturally clear.",[16,8172,8173],{},"Use structured data where it correctly describes visible page content and where the markup is relevant. Do not add entities merely to make a page appear “semantically optimized.”",[16,8175,8176],{},"The objective is not maximum keyword density or maximum entity density.",[16,8178,8179,8180,257],{},"It is ",[23,8181,8182],{},"clear, complete, useful information",[11,8184,719],{"id":718},[721,8186,8188],{"id":8187},"is-an-entity-the-same-as-a-keyword","Is an entity the same as a keyword?",[16,8190,8191],{},"No. A keyword is a word or phrase. An entity represents an identifiable subject. A keyword may refer to an entity, but the two concepts are not interchangeable.",[721,8193,8195],{"id":8194},"can-one-entity-have-several-keywords","Can one entity have several keywords?",[16,8197,8198],{},"Yes. Different names, abbreviations, spelling variations, and query phrases can refer to the same underlying entity.",[721,8200,8202],{"id":8201},"can-one-keyword-refer-to-several-entities","Can one keyword refer to several entities?",[16,8204,8205,8206,1405,8209,1434,8211,8214],{},"Yes. Words can be ambiguous. ",[154,8207,8208],{},"Apple",[154,8210,7836],{},[154,8212,8213],{},"Mercury",", for example, can refer to different subjects depending on context.",[721,8216,8218],{"id":8217},"are-keywords-still-important-for-seo","Are keywords still important for SEO?",[16,8220,8221],{},"Yes. Understanding the terminology users search with remains useful. Google itself advises considering different search terms while noting that exact wording for every query variation is unnecessary.",[721,8223,8225],{"id":8224},"does-schemaorg-improve-entity-seo","Does Schema.org improve entity SEO?",[16,8227,8228],{},"Schema.org can explicitly describe entities and their properties, which may make information easier for machines to interpret. However, valid structured data does not by itself guarantee rankings, rich results, or entity recognition.",[11,8230,771],{"id":770},[16,8232,8233,8234,257],{},"Keywords tell you ",[23,8235,8236],{},"how people talk about a subject",[16,8238,8239,8240,257],{},"Entities help represent ",[23,8241,8242],{},"what the subject actually is and how it relates to other things",[16,8244,8245],{},"Modern SEO therefore should not abandon keywords in favor of entities. It should combine user language, clear intent, accurate information, meaningful relationships, and technically sound machine-readable data where appropriate.",[16,8247,8248,8249,257],{},"The progression is not ",[23,8250,8251],{},"keywords → entities",[16,8253,8179,8254,257],{},[23,8255,8256],{},"strings plus meaning",[11,8258,787],{"id":786},[646,8260,8261,8272,8283,8294,8305,8314],{},[649,8262,8263,8266,8267],{},[23,8264,8265],{},"Google Search Central — SEO Starter Guide"," — guidance on anticipating search terminology and Google's language-matching systems. ",[28,8268,8271],{"href":8269,"rel":8270},"https:\u002F\u002Fdevelopers.google.com\u002Fsearch\u002Fdocs\u002Ffundamentals\u002Fseo-starter-guide?utm_source=chatgpt.com",[32],"Google SEO Starter Guide",[649,8273,8274,8277,8278],{},[23,8275,8276],{},"Google — “Introducing the Knowledge Graph: things, not strings”"," — May 16, 2012. Introduction to Google's entity-and-relationship model for Search. ",[28,8279,8282],{"href":8280,"rel":8281},"https:\u002F\u002Fblog.google\u002Fproducts-and-platforms\u002Fproducts\u002Fsearch\u002Fintroducing-knowledge-graph-things-not\u002F?utm_source=chatgpt.com",[32],"Google Knowledge Graph announcement",[649,8284,8285,8288,8289],{},[23,8286,8287],{},"Google Search Central — A Guide to Google Search Ranking Systems"," — documentation covering systems including BERT and neural matching. ",[28,8290,8293],{"href":8291,"rel":8292},"https:\u002F\u002Fdevelopers.google.com\u002Fsearch\u002Fdocs\u002Fappearance\u002Franking-systems-guide?utm_source=chatgpt.com",[32],"Google Search ranking systems guide",[649,8295,8296,8299,8300],{},[23,8297,8298],{},"Google Search Central — Introduction to Structured Data Markup"," — documentation on structured data, page meaning, classification, and Search features. ",[28,8301,8304],{"href":8302,"rel":8303},"https:\u002F\u002Fdevelopers.google.com\u002Fsearch\u002Fdocs\u002Fappearance\u002Fstructured-data\u002Fintro-structured-data?utm_source=chatgpt.com",[32],"Google structured data documentation",[649,8306,8307,8310,8311],{},[23,8308,8309],{},"Google Search Central — In-depth Guide to How Google Search Works"," — documentation covering crawling, indexing, understanding page content, and serving relevant results. ",[28,8312,5620],{"href":30,"rel":8313},[32],[649,8315,8316,8319,8320],{},[23,8317,8318],{},"Schema.org — Data Model and Style Guide"," — documentation describing types, properties, entities, and graph relationships. ",[28,8321,8324],{"href":8322,"rel":8323},"https:\u002F\u002Fschema.org\u002Fdocs\u002Fdatamodel.html?utm_source=chatgpt.com",[32],"Schema.org data model",[890,8326,8327],{},"html pre.shiki code .sVt8B, html code.shiki .sVt8B{--shiki-default:#24292E;--shiki-dark:#E1E4E8}html pre.shiki code .sj4cs, html code.shiki .sj4cs{--shiki-default:#005CC5;--shiki-dark:#79B8FF}html pre.shiki code .sZZnC, html code.shiki .sZZnC{--shiki-default:#032F62;--shiki-dark:#9ECBFF}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":201,"searchDepth":381,"depth":381,"links":8329},[8330,8331,8332,8333,8334,8335,8336,8337,8338,8344,8345,8346,8347],{"id":7677,"depth":381,"text":7678},{"id":37,"depth":381,"text":38},{"id":7729,"depth":381,"text":7730},{"id":7843,"depth":381,"text":7844},{"id":7900,"depth":381,"text":7901},{"id":7945,"depth":381,"text":7946},{"id":7986,"depth":381,"text":7987},{"id":8077,"depth":381,"text":8078},{"id":1749,"depth":381,"text":1750,"children":8339},[8340,8341,8342,8343],{"id":8128,"depth":387,"text":8129},{"id":8135,"depth":387,"text":8136},{"id":8145,"depth":387,"text":8146},{"id":8152,"depth":387,"text":8153},{"id":689,"depth":381,"text":690},{"id":718,"depth":381,"text":719},{"id":770,"depth":381,"text":771},{"id":786,"depth":381,"text":787},"Learn the difference between keywords and entities in SEO, how search engines use language and meaning, and why modern SEO needs both.","\u002Fkeywords-and-entities.png","Images of Keyword and entities",{},"\u002Fblog\u002Fen\u002Fkeywords-vs-entities",{"title":7672,"description":8348},"blog\u002Fen\u002Fkeywords-vs-entities","O4dR8wNIv8erjcpdJwc2KQrEjAqzMe6VjepB2fUEbVU",1789910357458]