← Back
technical seoagency websiteswebsite auditingaccessibilityemail authenticationwebsite security

Technical Checks for Agency Websites: 100-Site Austin Benchmark

A 100-site Austin agency benchmark shows that technical debt is common even on practitioner-built websites, with DMARC, consent, accessibility and security-header gaps leading the findings.

· 14 min read

One hundred web design and marketing agency sites in the Austin metro were put through 134 public technical checks on 28 September, and the median site still had 17 findings. These technical checks for agency websites show where agency owners can reduce security, email, privacy, accessibility and mobile risks with evidence rather than relying on an attractive homepage alone.

The benchmark matters because these are websites built or maintained by businesses that sell digital expertise. It should not be read as a census of all agencies: the sites came from public business listings in one metro area, the scanner and its score weighting were created by the study author, and the test represents one point in time. The useful part is the transparent count of recurring failures—and the practical order in which to address them. (reddit.com)

What the 100-site benchmark tested

The original Reddit benchmark examined 100 Austin-area web design and marketing agency websites using 134 public checks. Its categories covered Domain Name System (DNS) configuration, TLS/SSL certificates, email authentication, HTTP security headers, scripts and cookies loading before consent, automated WCAG accessibility signals, and responsive mobile layouts. (reddit.com)

That range is important. A conventional technical SEO crawl can identify broken links, redirects, metadata gaps and indexation problems, but it may not show whether a domain is protected against email impersonation or whether analytics begin collecting data before a visitor acts on a cookie banner. An agency website audit should connect these disciplines rather than treat them as unrelated tasks.

The benchmark author also removed one initially alarming signal: registrar delete and update locks. It appeared on 57 of the 100 domains, but a follow-up suggested the result mostly reflected registrar defaults rather than a deliberate owner decision. That is good audit practice: do not report a number simply because a scanner can produce it. Validate whether the check measures an actionable risk before escalating it to a client. (reddit.com)

For repeatable agency work, document four things alongside every finding:

  • the page, host or DNS record tested;
  • the exact test date and device or viewport used;
  • the evidence, such as a response header, screenshot or record lookup; and
  • the business impact and recommended owner, such as developer, hosting provider or email administrator.

This makes an audit a remediation plan rather than an undifferentiated list of warnings.

The headline findings from technical checks for agency websites

The custom weighted score ranged from 15 to 97 out of 100, with a median of 86. Since the weighting belongs to the benchmark author, it is better treated as a measure of spread than a universal quality score. The more portable figures are the raw counts: 13 critical findings, 176 high-severity findings and a median of 17 findings per site. (reddit.com)

The compact view below separates widespread issues from those that deserve the fastest response. “Impact” is a practical prioritisation judgment, not a claim that every instance has identical severity.

Issue found in the 100-site sampleFrequencyLikely impactFirst fix
No DNSSEC93 of 100DNS integrity hardening gap; relevance varies by DNS setupConfirm registrar and DNS host support, then plan signing carefully
Automated accessibility findings88 of 100Barriers for users; possible WCAG conformance issuesRun automated checks, then manually test key journeys
No Referrer-Policy84 of 100More referrer information may be disclosed than intendedSet and test an appropriate Referrer-Policy
DMARC absent or not enforcing79 of 100Brand impersonation and phishing exposureMonitor first, then progress toward enforcement
No Content-Security-Policy74 of 100Reduced browser-side protection against script injectionDeploy CSP in report-only mode before enforcement
Cookies without HttpOnly73 of 100Some cookies may be exposed to client-side scriptsReview cookies and add HttpOnly where appropriate
Tracking before consent67 of 100Privacy and consent-process riskBlock non-essential tags until consent is recorded
Horizontal mobile scrolling at 390px20 of 100Friction and reflow failure on narrow screensIdentify and constrain the overflowing element

The pattern is not that agencies cannot build websites. It is that configuration work tends to fall behind after launch: a tag manager is added before a consent platform, a new vendor is allowed by a script policy that never exists, or mail authentication stays in monitoring mode indefinitely.

Domain, DNS and TLS/SSL certificate checks

DNS and certificates were not equally problematic in this sample. Ninety-three of 100 sites had no DNSSEC, while the certificate category was the quietest: only 12 of 100 had any certificate finding, although three certificates were already expired on the date of the test. (reddit.com)

DNSSEC is a chain-of-trust mechanism for DNS answers. It is worth considering, especially for agencies that manage domains, email and client portals, but it is not a checkbox to enable blindly. DNS hosts, registrars and DNS providers need to coordinate DS records and key rotation. A broken DNSSEC rollout can make a domain unavailable to validating resolvers, so ownership and rollback procedures should be clear.

Expired TLS/SSL certificates are more straightforward. They can create browser warnings, destroy trust at the point of enquiry, and interrupt integrations. A reasonable agency baseline is automated renewal plus an independent monitoring alert before expiry. The audit should cover the canonical host, www variant where it resolves, campaign subdomains, staging environments exposed publicly, and any client portal.

A domain and DNS review should also confirm that:

  1. HTTP redirects consistently to the intended HTTPS canonical URL.
  2. Certificate names cover every public hostname in use.
  3. CAA, MX and TXT records are intentional rather than accumulated legacy entries.
  4. DNS provider access uses least privilege, multi-factor authentication and an ownership record.
  5. Email-related DNS records are reviewed with the systems that actually send mail.

The study did not publish separate pass/fail totals for SPF or DKIM. It did publish DMARC results, which makes that the evidence-backed email priority rather than an excuse to assume SPF or DKIM are correct.

Email authentication: make DMARC the first high-value fix

Seventy-nine of the 100 agency domains were not enforcing DMARC: 40 had no DMARC record and 39 used p=none. A p=none policy collects reports but does not request quarantine or rejection of unauthenticated mail, so it is a useful observation stage rather than the endpoint of a domain-protection programme. (reddit.com)

DMARC works alongside SPF and DKIM, applying alignment and publishing a policy for receiving mail systems. Its purpose is not to make every email deliverable; it helps receivers determine whether mail claiming to be from a domain is authenticated and how failures should be handled. (dmarc.org)

A safe progression is usually:

  1. Inventory every legitimate sender, including Google Workspace or Microsoft 365, CRM platforms, billing tools, help desks, newsletter systems and recruitment tools.
  2. Check SPF authorisation and DKIM signing for each sender.
  3. Publish a correctly formatted DMARC record with reporting and p=none if no record exists.
  4. Review aggregate reports long enough to identify legitimate sources that fail alignment.
  5. Move to p=quarantine, then consider p=reject when the report data supports it.

That process avoids breaking legitimate campaigns while addressing a common route for someone to forge an agency’s visible From domain. Audra’s guide to OpenAI crawlers and robots.txt covers a different DNS-adjacent governance concern: technical controls need to be tested against the real service behaviour, not just published as configuration.

The security-header results were consistently high-frequency: 84 of 100 sites lacked a Referrer-Policy, 74 lacked a Content-Security-Policy (CSP), 73 set cookies without HttpOnly, and 44 disclosed a software version in a response header. (reddit.com)

A Referrer-Policy controls how much referrer information the browser sends with requests. A CSP tells browsers which sources are allowed to provide scripts and other resources, helping limit certain classes of injection risk. Neither header should be copied from another site without testing: a restrictive CSP can break analytics, embedded forms, cookie platforms or video players if their approved sources are omitted. (developer.mozilla.org)

For cookies, HttpOnly prevents JavaScript from reading a cookie. It is not appropriate for every cookie and does not replace other controls, but it is a meaningful protection for applicable session-related cookies. Secure cookie configuration should also consider Secure, SameSite, narrow domain/path scope, and whether a cookie is needed at all. (developer.mozilla.org)

The consent result deserves separate attention: 67 of 100 sites loaded tracking before a user consented. The reported examples included tag managers, analytics, Meta pixels and advertising technology. This does not establish legal non-compliance for every site—requirements vary by visitor location, data purpose and jurisdiction—but it does show that a visible banner cannot be treated as proof that the underlying tags are controlled. (reddit.com)

A cookie consent audit should test a clean browser session and record network activity at three moments: before any choice, after rejection, and after acceptance. It should also test revisiting the site, withdrawal of consent, embedded third-party content, and every template that may use a different tag container.

For a deeper remediation sequence, see Security Headers for Websites: Configuration Guide. It is especially useful when headers must be introduced without breaking a production marketing stack.

Accessibility findings are a floor, not a full WCAG audit

An automated checker found accessibility issues on 88 of the 100 agency sites. The author explicitly cautioned that automation catches only a fraction of issues a real audit can find. That means 88% is not a prevalence figure for all accessibility failures; it is a minimum signal that the sampled sites need more investigation. (reddit.com)

Automated testing is still useful for repeatable detection of issues such as missing form labels, empty links, contrast signals, invalid ARIA patterns or document-structure problems. But a website accessibility audit needs manual checks of the journeys that create value: finding services, reading case studies, using a contact form, booking a call, downloading a lead magnet and managing cookie preferences.

Start with the user-facing paths

A practical first pass should include:

  • keyboard-only navigation, including visible focus and logical tab order;
  • menu, modal, carousel and cookie-banner behaviour with a keyboard;
  • form errors that are both clear and programmatically associated with fields;
  • alternative text and meaningful labels for icons and controls;
  • headings that explain the page hierarchy; and
  • zoom, text resize and narrow-screen reflow.

WCAG is the W3C accessibility standard family, and it addresses a broad range of disabilities rather than a single automated score. (w3.org) Agencies should avoid presenting an automated scan as a certification of WCAG conformance. Instead, report what the tool found, what humans tested, which success criteria may be implicated, and what remains outside the scope.

Mobile layout failures were visible at a 390px viewport

The benchmark found 20 of 100 sites that scrolled horizontally on a 390px-wide screen. The author’s observation was that this was commonly one overflowing element, not a complete failure to reflow, which makes it comparatively fast to correct once the culprit is isolated. (reddit.com)

Typical causes include a fixed-width testimonial card, a long unbroken URL, an embedded scheduler, a 100vw section inside a padded container, an off-canvas animation, or a wide table with no responsive treatment. Use browser DevTools to inspect overflow and test at 320px, 390px and intermediate widths—not only at familiar device presets.

The same study found 14 sites that disabled pinch zoom through user-scalable=no. W3C’s accessibility testing guidance maps a restrictive user-scalable value to WCAG text-resize requirements, so it should be removed unless there is an exceptional, well-tested reason. (reddit.com)

Responsive mobile layouts also matter for search. Google uses the mobile version of a site’s content for indexing and ranking under mobile-first indexing, and recommends a mobile-friendly experience with equivalent important content and metadata. (developers.google.com) A mobile audit should therefore check more than visual fit: navigation access, content parity, structured data, canonical behaviour, lazy-loaded content and conversion elements all need to work on a smartphone viewport.

SEO, performance and share-preview checks should not be ignored

The original benchmark’s most detailed published counts concern DNS, mail, headers, consent, accessibility and mobile layout. It does not provide a full frequency table for Core Web Vitals, crawlability, metadata or performance findings, so an honest interpretation should not invent one.

It did identify one useful low-effort visibility issue: 43 of 100 sites had no social preview image. When a homepage or case-study URL is shared in platforms such as LinkedIn or Slack, a missing Open Graph image can result in a generic preview rather than a recognisable brand asset. (reddit.com)

For agency websites, the technical SEO and performance layer should still include:

  • indexability, canonical tags, redirects and XML sitemap coverage;
  • title, description and social-preview metadata on key commercial pages;
  • render-blocking assets, image delivery, JavaScript weight and layout shift;
  • internal links to core services, sectors, case studies and contact paths; and
  • the consistency of desktop and mobile content.

Prioritisation is the key. A missing social image is worth fixing, but it should not displace an expired certificate, an unmonitored DMARC record, a broken conversion form, or a keyboard trap in the navigation. The framework in Technical SEO Audit Prioritization: What to Fix First helps separate urgent exposure from lower-impact polish.

For agencies adding AI answer-engine visibility to this work, technical foundations still come first. A page that cannot be reliably crawled, rendered, understood or used will not become robust merely because it is mentioned in an AI visibility report. A practical ChatGPT visibility audit workflow can sit alongside, rather than replace, the technical baseline.

A prioritised remediation checklist for agency owners

The benchmark supports a simple rule: fix issues by potential harm and certainty, not by how easy a tool makes them look. An agency can use the following 30-day order as a starting point.

Days 1–7: remove clear exposure

  1. Replace any expired TLS/SSL certificate and establish expiry monitoring.
  2. Publish or validate DMARC reporting; do not move to enforcement until legitimate senders are understood.
  3. Stop non-essential tags and pixels from firing before the consent workflow permits them.
  4. Remove user-scalable=no and fix horizontal overflow on key mobile templates.
  5. Correct high-confidence accessibility blockers in navigation, forms and consent controls.

Days 8–30: strengthen configuration and prove the fix

  1. Add and test Referrer-Policy, CSP and suitable cookie attributes.
  2. Review server headers that expose unnecessary software-version information.
  3. Decide whether DNSSEC is appropriate for the domain’s DNS provider and operational maturity.
  4. Run manual WCAG checks on the agency’s core conversion paths.
  5. Re-test from a clean browser profile, a mobile viewport and an external network.

Each issue should have a before-and-after artifact. For consultants and agencies, that evidence is also what turns a routine maintenance task into a client-ready deliverable. A local-first desktop workflow can preserve screenshots, response headers, crawl results and AI visibility observations without putting a recurring tracker subscription at the centre of every audit. Audra is designed for that combined evidence-gathering model across technical SEO, performance, accessibility, links and answer-engine visibility.

FAQ

What technical issues were most common across the 100 agency websites?

The five most common published findings were no DNSSEC (93 of 100), automated accessibility issues (88), no Referrer-Policy (84), no enforcing DMARC (79), no Content-Security-Policy (74), and cookies without HttpOnly (73). The study also found tracking before consent on 67 sites. These are benchmark results from one Austin-area sample, not industry-wide rates. (reddit.com)

What technical checks should be run on a web design or marketing agency website?

Run checks across DNS, TLS/SSL certificates, SPF, DKIM and DMARC; HTTPS redirects; HTTP security headers; cookie and consent behaviour; WCAG accessibility; responsive mobile layouts; crawlability; metadata; performance; and critical conversion forms. The Austin benchmark used 134 public checks, but the best audit also includes manual testing of navigation, forms and consent interactions. (reddit.com)

How many agency websites had problems with DNS, certificates or email authentication?

The benchmark reported no DNSSEC on 93 sites, some certificate finding on 12 sites, and expired certificates on three sites. For email authentication, 79 sites were not enforcing DMARC: 40 had no record and 39 used p=none. Separate totals for SPF and DKIM were not published, so they should not be inferred from the DMARC number. (reddit.com)

What should a typical marketing agency website include?

A typical marketing agency website should make its services, audience, proof of work, contact route and conversion offer easy to understand. Technically, it should also provide HTTPS, working forms, accessible navigation, responsive mobile layouts, intentional consent controls, and clear metadata. The exact content mix varies by agency model, but basic usability and trust controls should not be optional.

What are some of the best marketing agency websites?

This benchmark does not rank agencies or identify “best” sites. It measures technical signals from a single local sample, while design quality, strategy, branding and commercial performance require different evaluation criteria. A stronger selection process reviews relevant case studies, mobile usability, accessibility, speed, clarity of positioning and the agency’s ability to explain the technical decisions behind its own site.

Sources