How to Do Forensic SEO: A Step-by-Step Workflow

Doing forensic SEO well means following a fixed sequence: build a timeline, gather evidence, segment the problem, test hypotheses against the data, and only then move to remediation. Skipping straight to fixes — the instinct most site owners and even some agencies default to — is the single fastest way to waste weeks chasing the wrong cause. Below is the actual workflow we run at Salterra when a client comes to us with a traffic or ranking problem and no clear explanation.

Step 1: Define the Symptom Precisely

Before opening a single tool, write down exactly what happened, in specific terms. “Traffic is down” is not a symptom you can investigate. “Organic sessions to the blog fell 40% starting on a Tuesday roughly three weeks ago, while product pages held steady” is a symptom you can investigate. Pull the exact date range, the percentage change, and which segments of the site are and aren’t affected, using whatever data is on hand — even if it’s rough.

This step also means interviewing the client (or, if it’s your own site, interviewing yourself honestly) about anything that changed around that window: a redesign, a plugin update, a new CMS, a hosting migration, a link removal campaign, a change in content strategy, staff turnover on the content team. People routinely forget to mention changes they don’t think are “SEO-related,” and those are frequently the cause.

Step 2: Build the Master Timeline

This is the backbone of a forensic investigation. Create a single timeline — a spreadsheet works fine — with one row per event, spanning at least six months before the symptom appeared through the present. Populate it with three categories of events layered on top of each other:

  • Site-side changes. Redesigns, migrations, CMS switches, plugin updates, robots.txt or sitemap changes, content publishing or pruning, internal link restructuring — anything pulled from CMS revision history, deployment logs, or client interviews.
  • Search engine changes. Confirmed and unconfirmed Google algorithm updates (core updates, spam updates, product review updates), pulled from Google’s own update history and cross-referenced against industry tracking tools like Semrush’s Sensor or Search Engine Roundtable’s update tracker.
  • External changes. Backlink gains or losses, competitor moves (a competitor launching aggressive content or link campaigns), seasonal demand shifts, or news events affecting the industry.

Once all three layers sit on the same timeline, patterns usually start to surface just from visual inspection — before any deep data pull. If the drop lines up tightly with a site-side deployment rather than an algorithm update date, that reorders your entire investigation priority.

Step 3: Pull the Evidence

With hypotheses starting to form, pull the actual data rather than relying on dashboard summaries, which smooth over exactly the detail you need.

Search Console exports

Export Performance data at the query and page level for the full period, not just the default 16 months if you have access to more through the API or a connected BigQuery export. Compare impressions and clicks separately — a drop in clicks with stable impressions points toward a click-through or AI Overview issue, not a ranking loss.

Server log files

Pull raw access logs for Googlebot (identifiable by user agent, and ideally verified by reverse DNS lookup to rule out spoofed bots) covering the same window. A tool like Screaming Frog Log File Analyser or a straightforward command-line grep will show crawl frequency, status codes returned, and which URL patterns Google is and isn’t requesting. A crawl frequency collapse on a specific template is one of the clearest forensic signals available.

Historical crawls and Wayback snapshots

Prefer the guided path? This is one lesson from the Forensic SEO course — get the complete step-by-step system with every lesson and template.
Explore the course →

If a prior full-site crawl exists (from Screaming Frog, Sitebulb, or a previous audit), diff it against a current crawl. If not, use the Wayback Machine to spot-check key pages before and after the symptom date — title tags, meta robots, canonical tags, and visible content all get preserved in snapshots and are worth a manual comparison.

Backlink profile history

Pull historical backlink data from Ahrefs or Semrush, filtered to the relevant date range, looking specifically for large link losses (an expired referring domain, a directory shutting down) or suspicious link gains that might indicate a negative SEO attempt or an old, forgotten link-building campaign catching up with the site.

Step 4: Segment Before You Conclude

A single aggregate traffic number hides more than it reveals. Break the drop down by:

  • Page type or template — did only blog posts drop, or product pages too?
  • Query type — branded vs. non-branded, informational vs. transactional.
  • Device — mobile-specific drops often point to Core Web Vitals or mobile usability issues.
  • Search feature — check whether AI Overviews or featured snippets are now appearing on formerly-clicked queries, absorbing clicks without a ranking change.
  • Geography — a regional drop can indicate a local SEO or hreflang issue rather than a global ranking problem.

Segmentation frequently narrows a “the whole site is dying” panic down to “one template lost its internal links during the last deploy,” which is a completely different, far more tractable problem.

Step 5: Test Each Hypothesis Against the Evidence

By this point you should have two or three candidate explanations. Test each one specifically:

If the hypothesis is an algorithm update, check whether the affected pages share the quality characteristics that update has been associated with (thin content, aggressive ad placement, over-optimized anchor text) — don’t just accept the date correlation. If the hypothesis is a technical issue, verify it directly: check live pages for the suspected error (broken canonical, noindex tag, blocked robots.txt rule) rather than assuming it from indirect signals. If the hypothesis is a backlink loss, confirm the lost links were actually contributing meaningful authority (check their own authority metrics and whether the linking pages themselves were indexed and passing value) rather than assuming any link loss is causal.

Discipline here matters. It’s tempting to stop at the first explanation that fits the timeline. Forensic rigor means actively trying to disprove your leading hypothesis before accepting it.

Step 6: Document Findings With Evidence Attached

A forensic finding isn’t a paragraph of narrative — it’s a specific claim backed by a specific piece of evidence: a log file excerpt, a Search Console screenshot, a Wayback diff, a backlink export row. This matters for two reasons. First, it protects the credibility of the diagnosis if the client or another agency questions it. Second, and more importantly, it keeps the investigator honest — if you can’t point to the evidence for a claim, it’s still a hypothesis, not a finding.

Step 7: Build the Remediation Plan

Only after the cause is established does remediation planning start. The plan should map directly back to the diagnosed cause — a disavow-and-outreach plan for a toxic link problem, a template rollback or re-optimization for a deployment issue, a reconsideration request for a confirmed manual action, a content strategy overhaul for genuine content quality erosion. Resist the urge to bundle in unrelated “best practice” fixes at this stage; a forensic remediation plan should be traceable back to the specific findings, not a general site improvement wishlist.

Step 8: Monitor and Confirm

Once fixes are live, monitor the same segmented metrics used in Step 4, not just the top-line traffic number, to confirm the specific problem is resolving. Recovery timelines vary — a technical fix can show movement within days of recrawl, while a link-based algorithmic issue or a manual action reconsideration can take weeks to months. Set a realistic check-in cadence with the client up front so a slow recovery doesn’t get misread as a failed fix.

Frequently Asked Questions

What's the first thing I should do when I suspect a ranking problem?

Define the symptom precisely before touching any tool. Get the exact date range, the percentage change, and which parts of the site are affected. A vague sense that "traffic feels down" leads to an unfocused investigation; a specific, measurable symptom gives you something to actually test hypotheses against.

How far back should the timeline go?

At minimum six months before the symptom first appeared, though a year or more is better for sites with a history of gradual decline. Algorithm updates, content changes, and backlink shifts can have delayed effects, so a timeline that only covers the weeks immediately around the drop often misses the actual triggering event.

Do I need log file access to do forensic SEO properly?

Log files aren't strictly required for every case, but they're one of the highest-value evidence sources available, since they show exactly what Googlebot did rather than a summarized or delayed version of it. Cases involving crawl budget issues, indexing problems, or suspected technical errors are much harder to diagnose conclusively without them.

What if the evidence points to multiple causes at once?

This is common, especially with gradual declines. Sites rarely lose rankings for exactly one reason. Document each contributing cause separately with its own supporting evidence, and prioritize the remediation plan based on which cause has the largest measurable impact and the fastest realistic fix, rather than trying to solve everything simultaneously.

How do I know when the investigation is actually finished?

When you can state the cause as a specific, falsifiable claim backed by evidence, and that claim survives an honest attempt to disprove it with the data you've gathered. If you're still saying "it's probably" or "it might be," the investigation isn't finished — keep pulling evidence until the hypothesis either holds up or gets replaced by a better one.

Terry Samuels
Written by Terry Samuels

Terry has 30+ years in software and SEO. He’s the founder of Salterra Digital Services and SEO Spring Training, host of the Roundtable SEO Mastermind, and lead instructor at SEO University — teaching the exact tactics his team uses on client work.

Ready to master this?

This guide is one lesson from the Forensic SEO course. Get every lesson, framework and checklist — plus the full 38-course catalog — inside SEO University.