In this Episode

  • [02:32] – Patrick talks about the massive size of the IBM website. He then discusses some of the big issues in maintaining a site that big from an SEO perspective.
  • [04:58]ย – We hear why one should use hreflang tags on their website.
  • [07:05] – What are Patrickโ€™s preferred tools for crawling?
  • [07:44] – Stephan compares building a website without an SEO involved to building a house and then realizing you didnโ€™t specify that you needed electrical wiring.
  • [09:34] – What sorts of documents does Patrick use to get everyone on the same page? He and Stephan talk about the problems with having extensive documentation.
  • [14:26] – Patrick talks about the potential issues with HTTP, and explains why seeing ads on a site that doesnโ€™t normally have them is potentially really scary.
  • [17:09] – What are the reasons you need to go from HTTP to HTTPS even on your personal blogs?
  • [19:13] – HTTPS is a small ranking factor in SEO, Patrick explains, which is basically a tiebreaker between equal sites. He isnโ€™t sure whether its importance as a ranking factor will be increased.
  • [20:50] – What are some of the biggest mistakes that Patrick sees with HTTPS migrations?
  • [23:43] – Patrick talks about what content delivery networks (CDNs) he comes across most frequently, and which are his favorites.
  • [26:23] – Patrick defines service workers for marketers who are listening and may be unfamiliar with some of the geekier SEO terms. He then explains the benefits of minifying JavaScript.
  • [28:49] – What are some of Patrickโ€™s favorite features within the Chrome Developer Tools?
  • [33:05] – Stephan talks about the painful procedure that was involved in removing an SEO CDN, and talks about his invention, GravityStream.
  • [34:47] – Now that weโ€™ve covered HTTPS, Patrick moves on to talking about HTTP2. Its main benefit is that it makes things a lot faster.
  • [37:28] – Patrick and Stephan talk about server response headers, and Patrick offers some tips and tricks.
  • [42:58] – We hear about Patrickโ€™s use of Ryte.
  • [44:04] – Patrick elaborates on frameworks in SEO, discussing specifically React and AngularJS.
  • [46:57] – Stephan asks Patrick a question: what would be his SEO advice and best practice suggestions to a listener who is using infinite scrolling?
  • [48:12] – Are there any other server response header or redirect tips that Patrick wants to share with listeners?
  • [49:54] – Patrick and Stephan talk about Googleโ€™s SEO best practice document, and discuss whether H1 tags have an effect.
  • [52:57] – Stephan explains that he is very outcome-focused rather than activity-focused like most other SEOs.
  • [54:56] – Whatโ€™s an example of one of the scripts and tools that Patrick uses to automate and scale across the 50 million pages at IBM?
  • [57:25] – Patrick is pretty picky about side projects, but if you have a difficult problem that you canโ€™t quite figure out, he may be able to help. He directs listeners on where to find him.

Transcript

I hope youโ€™re ready because weโ€™re going to geek out on some technical SEO. You might think oh no, Iโ€™m just a marketer, I donโ€™t want to geek out. Stick around because this is a very valuable episode. For example, weโ€™re going to be talking about migrating to HTTPS. If you havenโ€™t already, you need to be on HTTPS. The Chrome error messages that users are going to get is just not worth staying on HTTP. Inaction is not an option. We also are going to be talking about HTTP/2 which is the evolution of HTTP and youโ€™re probably running on the old version and your website is running a lot slower than it should be because of that. Youโ€™re going to need to know about that and other pagespeed optimizations, things like minifying JavaScript and CSS, stuff that you may not do yourself but you need to ask your developer to do for you. This is all really valuable information, and the person whoโ€™s going to walk us through all this is Patrick Stox. Heโ€™s the technical SEO forย IBM, he writes for many search blogs, he speaks at many conferences. He just spoke atย PubConย which I also spoke at and we sat down at PubCon and geeked out about all this technical SEO goodness. Thatโ€™s what this episodeโ€™s all about. Patrick is an organizer of theย Raleigh SEO Meetupย which is the most successful in the US and it was founder of the technical SEO Slack group. Patrick, itโ€™s great to have you on the show.

Hey, thank you, itโ€™s great to be here.

Letโ€™s geek out, but before we do, letโ€™s set the stage so weโ€™re not scaring away all the non-technical marketers because theyโ€™re going to need to listen to this too so they know what to ask for from their developers, their systems administrators, their technical SEO for people. This is critical stuff. If you donโ€™t get the foundational stuff right, you donโ€™t have a platform to build upon and your SEO is going to suck. One of the things that you do at IBM is you figure out ways to scale across a very large website. Youโ€™re always looking for ways to shortcut things but in a good way, not shortcut as in getting stuff thatโ€™s not perfect but ways to scale so you donโ€™t have to touch manually hundreds of thousands or millions of pages. How big is the IBM website?

Thatโ€™s a good question. I would say north of 50 million pages, itโ€™s hard to get a good count.

Holy cow, thatโ€™s huge.

Thereโ€™s a lot of different subdomains that we donโ€™t have a lot of insight into so itโ€™s hard to say exactly how big it is.

Wow. 50 million pages, give or take millions, what are some of the big issues when maintaining a site like that from an SEO perspective? Are you having to do a lot of migrations, or are you having to just maintain things, redirects, and so forth? What are you up to?

All of the above. Itโ€™s a really complex system where thereโ€™s a lot of infrastructures, most people donโ€™t have to deal with more than one. Thereโ€™s really a ton of different CMS systems, JavaScript frameworks. I think Iโ€™ve counted 22 different CMS systems and a lot of those have multiple installs. A lot of the times, itโ€™s getting things to work together. We have a corporate redirect engine that works with most of the systems, not all. Thereโ€™s a lot of middleware to try and get systems to talk to each other. If we make a change in one, it can be across multiple systems.

Right. Just simple stuff like the order that you call different JavaScripts and CSS files with an HTML page can really drastically affect the page load speed which then affects SEO and conversion. When you say middleware, youโ€™re talking about things that are connecting different systems together like for example I connect up GoToMeeting with InfusionSoft using PlusThis. ย If I didnโ€™t have that middleware solution, I wouldnโ€™t be able to communicate between those two software packages.

Yeah, like imagine for hreflang tags for instance, trying to get that to work across multiple CMS systems, itโ€™s hard enough to get right in one system. People screw it up all the time. Trying to get it across multiple, you can either try a manual approach, that will never work, or set up some middleware so the systems can talk to each other. If you make a change in one, it rolls out to the other systems.

We need to defineย hreflangย for our listeners who are not familiar with it. The purpose of that is for internationalization. Why donโ€™t you describe why youโ€™d want to have hreflang tags in place on your website?

For the most part, itโ€™s to make sure that the language version, or if you have a specific country language version shows in the right geolocation.

French Canadian versus French French.

Right. French Canadian is always a hot topic because theyโ€™re legally required to have that one.

Yeah. If you get it wrong, youโ€™ll end up with the wrong version getting served up or maybe Google could get confused and see some of these different country versions as duplicate content.

Yeah, itโ€™s always fun when that happens if you donโ€™t actually localize them. Google basically folds the pages together and only one of them will really be in the index. You might be routing people to the wrong country, just one way you can route people to the wrong country.

Google basically folds the pages together and only one of them will really be in the index.

Right. Thereโ€™s also targeting international, targeting that you can do inside of Google Search Console. Are you doing that as well or are you recommending that to our listeners?

I would definitely recommend that as a best practice. But in reality if you have a lot of country language versions and hreflang tags, itโ€™s not going to help a lot, itโ€™s still going to show wrong versions if pages get folded together. Itโ€™s actually quite common on our side, unfortunately, it causes a lot of issues.

You probably have to run scripts or tools across this very large website and all its subdomains on a constant basis to make sure that things are not breaking or people didnโ€™t go in and undo some SEO goodness that you had created, right?

Yeah, itโ€™s never enough. We do run a lot of automated testing, lots and lots of crawls. We have lots of change monitoring systems because things arenโ€™t communicated as well as they could be usually.

Youโ€™re crawling your very large site and various subdomains of it using tools like what? ScreamingFrog,ย React,ย Botify, DeepCrawl. I use DeepCrawl for a lot of my client stuff. What are your preferred tools for crawling?

Pretty much all of the above. DeepCrawl for instance we use a lot but it breaks down on the JavaScript frameworks day. I think theyโ€™re adding JavaScript, the ability to crawl JavaScript, but they still donโ€™t have that. We have a lot of dynamically generated systems like our support center, we have a few different things like our marketplaces in React JS. It can handle React okay as long as itโ€™s done well, but certain parts of our site are not. Thereโ€™s another part that was built withย Meteorย JS which is Node JS framework. That, I donโ€™t think, should ever be a website but they did it anyway.

Yeah, trying to reign in people building these websites can be pretty hard when itโ€™s built in a very search engine unfriendly way. I use an analogy to convey to prospects and clients the danger of hiring somebody who doesnโ€™t understand SEO to build your website and not having an SEO involve in the process. Itโ€™s like building a house and then realizing after the fact that you didnโ€™t specify โ€œI need electrical wiringโ€ in the house and then you have to tear out the drywall, wire the electrical in so that you can turn the lights on, patcher up the drywall. Itโ€™s very expensive, and a very stupid mistake too. That happens all the time in regards to SEO and sight rebuilds or new site builds, itโ€™s a real mess.

We try to get in front of it and we have lots of standards, best practices. Thereโ€™s 10,000 different developers for IBM, so that makes it a little hard to get to everyone. With churn and everything, thereโ€™s no way that youโ€™re in front of everyone you need to be.

Right, so there must be a whole raft of guidelines, documents on best practices, and things to avoid.

Technical trainings, webinars, educational materials. We go speak and educate, but itโ€™s still such a large organization. A lot of times, people will talk, โ€œHey, go buy your dev pizza.โ€ I canโ€™t buy 10,000 devs pizza or beer.

Yeah, got it. What sort of documents do you use in order to get everybody on the same page? Iโ€™m sure it doesnโ€™t work across 10,000 developers because not everybody reads everything or watches every training video, but do you have the equivalent of branding guidelines or style guides for SEO?

Yeah, we have a lot of best practice documentation. Obviously, IBM will have their own style guides and branding guidelines as well for the content folks. We have probably too much documentation, maybe thatโ€™s part of the issue. Thereโ€™s so many rules, how can you remember everything?

I remember Bill Hunt sayingโ€”Bill, a fantastic SEO who also helped IBM out for a long time, he was also a previous guest on this podcast. Great episode, listeners, by the way, theย Bill Hunt episodeย if you want to geek out some more on SEO. He described how having these huge binders full of monthly reports that took 12 hours to create, human labor, 12 hours for a very talented SEO such as himself to create, and then nobody would read it. And then he would start to test this theory by inserting pictures of Mickey Mouse and stuff into the binders, into the reports. For 14 months, nobody would comment on this until one new person finally said, โ€œWhat are these Mickey Mouse things?โ€

Thatโ€™s great, I havenโ€™t heard that before.

Yeah, really funny. He said one of the solutions to get the upper management to consume the information is to find three big wins, three challenges, and three important actions to take and to put that into a three-minute video. Pretty genius, right? Then, he actually heard upper management talking about, parroting back some of these key initiatives. โ€œOkay, we really need to move on this project because itโ€™s been stalled for six months,โ€ or whatever. They would know that from the video. They have time to watch a three-minute video. These overwhelming documents just donโ€™t get read by anybody.

Yeah, we try not to overwhelm with the documents. Weโ€™ve used pretty simple dash boarding. I know for a fact that execs do look at those in detail every week.

Thatโ€™s awesome.

We try and do the wins also. Thatโ€™s always great. It helps not only us but other teams. If someone was willing to work with us and get things done, changed, then it was a success, we give as much credit as we can to them because that makes them look good also and theyโ€™re more willing to work with us in the future.

Another person you probably know from IBM isย Mike Moran, he worked there for many, many years, really great guy, co-author to Bill Hunt on Search Engine Marketing Inc. He said that he would create these dashboards and he called it management by embarrassment because the dashboards would have all this red if the business unit owner did not follow through on the SEO initiatives. They would complain to the developers or whatever, just make these red boxes go away because Iโ€™m sick of hearing this month after month in front of my peers at the monthly meeting. I love that, management by embarrassment. Have you heard that one before?

No. Mike still consults with us but thatโ€™s still kind of a thing. Thereโ€™s what we call top charts and basically itโ€™s like hereโ€™s how well each business unit is doing compared to the others. Itโ€™s not really a fair comparison if you think about it, something like Cloud is a lot different than analytics or services or something. Itโ€™s not great but it gets the point across, youโ€™re right.

Yeah. Letโ€™s geek out a bit on things like HTTP/2 which probably a lot of our listeners donโ€™t even know what that means. They should care, they should care about page speed, they should care about upgrading their systems to PHP7, the latest versions of their server software if theyโ€™re running Nginx or HTTP server. They need to know what to ask their systems administrators and developers. Letโ€™s start with HTTPS. Youโ€™re a big proponent of that, youโ€™ve written about this multiple times, I think you have a search engine journal article about HTTPS, is that right?

Search Engine Land, yeah.

Did you write for Search Engine Journal as well?

I think I wrote maybe something about HTTP/2 for them.

Thatโ€™s what Iโ€™m thinking of. HTTP/2 article on Search Engine Journal and the HTTPS one on Search Engine Land. Letโ€™s start with HTTPS because thereโ€™s a recent development where itโ€™s not really an SEO development but it really freaks people out now when theyโ€™re getting these messages, security messages in the Google Chrome browser that the siteโ€™s not secure. Letโ€™s talk about that because that can cause somebody to bounce out of your website, right?

Yeah, absolutely. Thereโ€™s a lot of scary stuff with HTTPS that people donโ€™t realize. Itโ€™s not really securing your website like people think, itโ€™s all about the trust of the connection. Thatโ€™s huge. Itโ€™s not going to prevent your website from being hacked or anything like that, but it can prevent things like hunt and injection. You see it a lot in hotels, airlines. If youโ€™re using their wifi, you might see ads on websites that donโ€™t have ads. That may not seem like a big deal to people, theyโ€™re like itโ€™s just an ad, I ignore it anyway. What happens if they change the content on that website? Weโ€™re in a highly political environment right now. What if companies decide that they want to change peopleโ€™s perception and they could influence a presidential campaign for instance, that would be a huge deal. People using their connections at airports, or if your home ISP wanted to, they can do this. Iโ€™ve seen it before, actually. My mom had an ad injected on Jennifer Sleggโ€™s site, the SEM post. Iโ€™m like there werenโ€™t ads on that site at the time. It was just to get a discount on blah, blah, blah. It was directly from her ISP. The ads donโ€™t really scare people, like I say. But if they do change content, they have full control over that page. You can inject new paragraphs, they can change the message. They could censor content, which is really scary if you think about it.

Right, but thereโ€™s also bad actors out there that could hijack the connection and ask for you to log in again, get your password, and then empty your bank account. Thatโ€™s if youโ€™ve already secured your site, thatโ€™s still a risk, secured it with HTTPS, itโ€™s not fully secured. Itโ€™s just the HTTPS protocol or SSL. Letโ€™s first start with if you donโ€™t have HTTPS at all, you should switch to HTTPS, right?

Absolutely, yes.

What are the reasons why you need to go from HTTP to HTTPS? The majority of websites on the internet are still on HTTP. Up until just recently, my regular personal blog was on HTTP, I just recently switched to HTTPS.ย stephanspencer.comย is now HTTPS. Why should peopleโ€™s personal blogs and their brochureware websites that donโ€™t have any ecommerce or any kind of need for credit card numbers to be inputted or any kind of secure information to be inputted, why do they need to switch to HTTPS?

Iโ€™m going to use your blog as an example. Would you care about the numbers on your blog for traffic and where that traffic is coming from?

Of course.

That is one of the main arguments I use for people to switch. Thereโ€™s all this rise of dark traffic, dark social, blah, blah, blah, not seeing the refer. The refer gets dropped is you switch from HTTPS to an HTTP. If the site that the person came from is on HTTPS and youโ€™re not, you canโ€™t really see where they came from. It shows in Google Analytics for instance as direct, other analytic platforms actually show it as no refer. Those numbers are important, you want to know where people came from.

Yeah. Essentially, youโ€™re removing optics, the optics that you have around where your traffic is coming from is now gone if the traffic is coming from HTTPS sites, secure sites, to your insecure HTTP site.

Absolutely.

Alright, thatโ€™s a very important reason. What about the scary messages that you get that youโ€™re entering a site thatโ€™s not secure?

Thatโ€™s new and I donโ€™t know that people are scared of that yet.

Okay.

Itโ€™s still gray and not very noticeable, but theyโ€™re going to put a big, red symbol up there soon, I think early next year.

This is something where itโ€™s going to get more and more alarming to just regular web users who are using certain browsers, I use Safari and Iโ€™m pretty sure theyโ€™re going to be rolling out changes there too to make it more alarming to users that, hey, youโ€™re entering an unsecure website now. Thereโ€™s user considerations, we want to make sure people are not freaked out, there are analytics considerations as we just discussed. What about SEO considerations? HTTPS is something that Google has been advising websites to migrate to for years now.

Yeah. It is a ranking factor, a small one.

Yeah. Small one. It doesnโ€™t really move the needle if you move from HTTP to HTTPS.

Yeah. The way they describe it is more of a tie breaker.

Yeah. Itโ€™s very minor signal and yet I would imagine that itโ€™s going to get dialed up over time, thatโ€™s not going to decrease in importance, as a ranking signal itโ€™s going to increase, right?

Yeah. Iโ€™m not sure if theyโ€™ll increase it or not. I think the stuff that the Chrome Browser Team is doing is going to be scary enough to make people switch. Maybe the search team doesnโ€™t need to increase that as a ranking factor.

Okay. Honestly, weโ€™re all conjecturing here. We donโ€™t know what Google engineers are planning. In fact if an SEO tells you that this is coming around the pipe, that Googleโ€™s going to implement it, turn and run. Theyโ€™re either just parroting something that has been posted, letโ€™s say the Google headmaster center blog and thatโ€™s okay as long as theyโ€™ve cited as like according to this comment from John Miller at Google or whatever, then thatโ€™s fine but if theyโ€™re conjecturing and theyโ€™re not saying this is conjecture, turn and run because an SEO who thinks they know what Googleโ€™s going to be doing, thatโ€™s a dangerous thing. HTTPS, really important. When you migrate from HTTP to HTTPS, you can create a whole lot of havoc if you donโ€™t do it right. If youโ€™re not thinking through the different SEO issues that you could end up creating inadvertently, that will create some havoc. What are some of the biggest mistakes that you see with HTTPS migrations?

Itโ€™s probably coming from common SEO recommendations to not switch to HTTPS until youโ€™re doing something else, like a full site redesign or migration or something else. You had more moving parts into the scenario and things are going to go wrong. Straight HTTP to HTTPS is pretty simple, it depends a lot on the system and that kind of thing, I donโ€™t want to say itโ€™s simple always because it was not simple on IBM. We just did that in early April finally but that was after planning for well over a year and a half just to get that done, and itโ€™s still not fully migrated over, so many different systems. For the most part, thereโ€™s a few things you might have to do in your CMS or server level and then do some redirects and thatโ€™s about it. As long as you donโ€™t screw up those redirects and thatโ€™s the only thing you did, youโ€™re not going to see much of a difference.

Redirects are going to be critical. What about going through and revising all the links on your site? If youโ€™re using absolute links that are HTTP, switching those to absolute HTTPS links.

Obviously I would do that but you can usually do that in bulk, thereโ€™s a lot of plugins for instance, a lot of people on WordPress, thereโ€™s Velvet Blues URLs that allow you to update all the URLs in bulk. I would be more concerned with images and resources polled through JavaScript and CSS, but thereโ€™s something really cool most people donโ€™t know about for that, itโ€™s called Content Security Policy. You can set that at the server or to your CDN level to say auto upgrade and secure request.

Okay. Tell me more about that. What happens when you do that?

Any image on your entire website that is linked in securely with HTTP will automatically be rewritten and upgraded before the user sees it.

Oh, nice. If you donโ€™t do that? Letโ€™s say an image loads or tries to load from HTTP because you didnโ€™t switch anything over and the page is on HTTPS, what happens?

Then youโ€™re going to get a warning, youโ€™re not fully secure.

Thatโ€™s not good. The userโ€™s going to see that error message and theyโ€™re going to freak out a little bit, maybe.

Right.

Okay. You mentioned CDN. Content Delivery Networks, wouldย Cloudflareย be considered as CDN in your mind?

Yeah, absolutely.

Okay. What CDNs d you come across most? Thereโ€™sย Akamai, thereโ€™s MaxCDN and Cloudflare and so forth, what are the ones youโ€™re most commonly addressing and which ones are your favorites?

There are so many. The common ones probably are Akamai and Cloudflare at this point, thereโ€™s a few others that you see see with different things likeย Fastly, with a lot of JavaScript stuff because they compile a lot of the stuff for you. Cloudflare is probably one of my favorites and I probably shouldnโ€™t say that because we actually use Akamai at IBM. Cloudflare does a lot of really cool stuff for you. You mentioned about the upgrade from HTTP to HTTPS, thereโ€™s a button for that, literally. I kind of hate this but I kind of love it also. They have what they call flexible SSL which makes the connection from Cloudflare to the user secure. You donโ€™t actually have to put that certificate on your server at that point, it still looks secure to everyone out there, itโ€™s not in the unsecure but for someoneโ€™s personal blog, you can do that, set a couple page rules and be done in five minutes.

You donโ€™t even need your own SSL Certificate for your website, you can just use Cloudflareโ€™s.

They actually do give you one and if you want to install it, I would recommend that but the flexible SSL will also pass all the sniff tests if you will, and itโ€™s a super easy setup for personal blogs, sure why not. If youโ€™re not taking anyoneโ€™s secure details or contact information or anything, do it.

Wow, cool. Alright. What are the benefits from an SEO perspective of using a CDN, a Content Delivery Network that will speed up your images and things loading because theyโ€™re coming from a more nearby data center and a more robust set of servers and connection and all that?

I think you hit it already, speed. Speed is the key. But they do so much other cool stuff too though a lot of times minify code or combine JavaScript CSS files. Thereโ€™s really a lot of different thing you can do. One of my personal favorites that I donโ€™t think itโ€™s used enough, itโ€™s actually just off loading your redirects to the CDN level. Rather than having your server process and read through files, you can cache those on the edge. It makes processing, that was a lot faster. Cloudflare actually releasedย service workersย which lets you run JavaScript on the edge now. Also, itโ€™s just really cool. Cloudflare Workers, I think they call it.

Remember we have some marketers on the show listening who are not familiar with some of the super geeky stuff like service workers, can you define that for our listeners?

It basically lets you run JavaScript to do anything. A lot of times SEOs might recommend something like Google Tag Manager to inject some code. That means tag manager has to load on the page and then rewrite things there. If it happens at the edge, with Cloudflare for instance, youโ€™re rewriting before the user ever sees it. You can run all sorts of cool scripts and stuff on that too.

Very cool, alright. You mentioned minifying JavaScript and combining JavaScript files and so forth together. Letโ€™s explain what that means because minifying, we know what that means, youโ€™re basically removing a lot of the unnecessary bloat in the code, youโ€™re abbreviating the JavaScript or you can do this with CSS as well, a cascading style sheet. Whatโ€™s the benefit? Is it a big benefit from a page speed perspective? And is that something our listeners should start with or have their developers start with to do some pagespeed optimizations?

Itโ€™s absolutely huge for page speed. One of the reasons websites are a lot slower to me than they used to be is because weโ€™ve bloated them, we have 10 different style sheets, 20 different JavaScript files code. Each one of those is a request back and forth, itโ€™s a handshake with the server to request that data. If you can reduce that to one, even though itโ€™s maybe still even the same size, itโ€™s going to get you a lot faster because itโ€™s not having to take the round trip time to request all the files.

You can see whatโ€™s happening in terms of all the back and forth and the waiting for one thing to finish before the next thing loads, thatโ€™s called the waterfall graph. What are some of your favorite tools for checking the waterfall?

Just Chrome DevTools or webpagetest.org.

Yes. Chrome has a built in tool for checking page speed stuff and doing a lot of different kinds of analysis, looking at the server response headers, whether itโ€™s a 301 or a 302, looking at if thereโ€™s a redirect chain, you can see all that inside of Chrome. Which is a browser most of our listeners are probably already using, they just havenโ€™t started exploring the developer tools section inside of there. What are some of your favorite features inside of DevTools, inside of Developer Tools?

For me, Iโ€™m usually troubleshooting. You mentioned the header response, that oneโ€™s huge. Also just being able to see where you got redirected to, you can actually stop the page from being redirected, turning off JavaScript obviously to make sure it works for people that have that disabled, which a lot of people do because of ad blockers and that kind of thing now.

Yup.

Thereโ€™s really just so much in there. Being able to read the DOM is the big one. The DOM is the Document Object Model. Everyone thinks youโ€™ve used the words, thatโ€™s the HTML, thatโ€™s whatโ€™s on the page, it is and it isnโ€™t. Thatโ€™s the code but the process code goes into the document object model. And being able to check that if you use Inspect, Inspect Element, is really huge because things can happen, like the head section can break, throwing a canonical tag into the body and it wonโ€™t work there. That happens all the time, people donโ€™t realize that but a lot of times a script in the head breaks or any number of things really can cause it. Being able to actually look at the DOM will tell you what happened.

Right. Back in the day, when I was doing a bit of coding myself, I wrote reversed proxy based software as a service, SEO platform. In the prototype, Iโ€™d used proxy based rewrite rules on our clientโ€™s web server to then call on our web server to do all this SEO goodness. We would rewrite URLs, weโ€™d do all sort of cool stuff that could take a year or two for them to implement if they were just going through the regular dev processes. Thereโ€™s so much bloat and red tape, bureaucracy in these large corporations. We did an end run around all that. In the first version that I wrote, the prototype, it just used regular expression, pattern matching, and search and replace process on the HTML but then we got more sophisticated, give it to my developers and then we processed the DOM, the Document Object Model, and we got even more sophisticated in the kinds of things we could accomplish for SEO without involving the developers over at our clientโ€™s side. That was really cool, in fact that was a big reason why my previous agency got acquired. We actually grew that side of our business to the majority of our revenue. It was on a pay per performance basis. So cost per click SEO, $0.15 a click and it was crazy how much money we were making off of that. An order of magnitude more in SEO revenue than we would have made just doing SEO consulting. Pretty cool.

Thatโ€™s awesome. You were really ahead of your time there because I feel like those types of systems are just now becoming more popular.ย [00:31:52]ย is one most people know but they pitched that weird, itโ€™s like an AB testing platform but it basically gives you full control of the website delivery before itโ€™s delivered.

Essentially a CDN with SEO capabilities.

Or it sits in between the CDN, yeah it could act as a CDN also depending on the system. I think RankSense is another one that can beย [00:32:13].

Yeah. Thatโ€™s Hamlet Batistaโ€™s platform, yup.ย RankSenseย is a CDN with SEO capabilities, for sure.

Even now, it really is cutting edge. It solves a lot of problems with dev cycles, being able to have that level of control is unreal but itโ€™s also scary. I think thatโ€™s maybe why they pitch it differently than I would but itโ€™s because they probably donโ€™t want to say, โ€œHey, youโ€™re giving your marketer full control of your website instead of your devs.โ€ Itโ€™s kind of a patch, too. Itโ€™s what happens when that gets removed? And then thereโ€™s going to be issues. I donโ€™t know if anyoneโ€™s really added permissions like only this person can change this one thing, that kind of thing. Thatโ€™s kind of the issues, those platforms they dissolved to get better at option.

It really was a painful procedure to remove an SEO-CDN like my platform,ย GravityStream, we did have an easy out option, but we charged for it. We would setup all the redirects from the optimized URLs that were in Google to their native pages which didnโ€™t have any of the SEOs, they turned off our platform, turned off GravityStream and they lose all the SEO goodness but at least if they went with this friendly advanced option for removal, then all the redirects would be mapped and they wouldnโ€™t lose any traffic, they wouldnโ€™t have to handle the redirects all on their own. Then there are other platforms that werenโ€™t so friendly about how youโ€™d remove. Youโ€™d feel like you were held hostage essentially, because if you turn that off, all the SEO goes away and you go from top of page one for a bunch of keywords to who knows where.

I wonder how some of the others handle that. I thinkย [00:34:13]ย just launched a new one too, un-something but I canโ€™t remember the name of that.

That was 14 years ago that I invented GravityStream and now itโ€™s becoming a thing.

Thatโ€™s incredible.

Yeah, alright. HTTPS we talked about, letโ€™s talk about HTTP/2. Because this is something that a lot of our listeners probably are unfamiliar with. Theyโ€™re running an HTTP/1.1 and they didnโ€™t even know it and they should be on HTTP/2. Letโ€™s talk about that.

Yeah. Itโ€™s basically a new internet protocol that makes everything a lot faster, thatโ€™s the main benefit. To get that benefit, one of the things is you have to go to HTTPS, right?

Yup. What happens when you move to HTTP/2, as far as what can load in parallel and so forth. Letโ€™s geek out a little bit about why itโ€™s so much faster being on HTTP/2.

Yeah. With HTTP/1, itโ€™s a lot of round trip request, with HTTP/2 itโ€™s like letโ€™s make a connection and now give me everything rather than requesting each one, enclosing that connection requesting the next one, closing the connection. Itโ€™s like request the connection, now give me the files.

Cool. Do you see many sites on HTTP/2 or is it still very uncommon?

I think itโ€™s becoming a lot more common. Cloudflare really probably tripled the size of the number of people on HTTP/2 last year, I think about this time, when they upgraded everyone on their CDN to HTTPS. They went HTTP/2 in a lot of the different DLS optimizations too, which has made things really a lot faster.

Cool. Are there any gotcha or potential landmines if youโ€™re migrating to HTTP/2?

Not really because there are fall backs. If a browser of a user for whatever reason doesnโ€™t support HTTP/2, itโ€™ll just load things like it was HTTP/1.

Alright, cool. Thatโ€™s definitely a must for our listeners to get that going and get that great search engine journal article about HTTP.

They can just go to Search Engine Land and search Engine Journal.

Okay, so you did a little repurposing.

Thatโ€™s a big proponent.

Okay, cool. When you migrate to the latest CMS version, letโ€™s say that youโ€™re running WordPress or whatever, you should be doing automated constant upgrades whenever a new release come out, you should be installing it. Otherwise youโ€™re opening yourself up to hackers.

WordPress usually handles that stuff for you. If youโ€™re on them, youโ€™re usually pretty well off.

Letโ€™s say that youโ€™re running an old version of PHP and youโ€™re on the latest WordPress, thatโ€™s an optimization opportunity if you upgrade to PHP 7, right?

It is, but thereโ€™s still tons of website out there that are on PHP 4, PHP 5.

Letโ€™s talk about server response headers again, because thereโ€™s some really cool things that you can do with server response headers and some things that are going to be important for SEO purposes. There are cases for example when youโ€™re going to want to use the Vary header. Thatโ€™s something most people donโ€™t even know exists as a server response header. Have you used the Vary header before?

Yeah. Thatโ€™s for dynamic serving websites. Actually, Alec Bertram from DeepCrawl sent me some great research that they did before a presentation I did earlier this year at SMX Advance, when I was talking about the mobile-first index moving to mobile. I think it was something like ย 96% of the websites that have a dynamically served website donโ€™t use the Vary header correctly.

Wow.

It was an incredible number and really shocking and eye opening.

Wow. Whenever youโ€™re dynamic serving for mobile, meaning that you have a different HTML version for mobile, on the same URL but the HTML is different, it varies. You should be sending a Vary header with a server response headers.

Yeah, absolutely.

Alright. In addition to the Vary header, what are some of the other server response header tricks and tips that you want to share?

Thereโ€™s Content Security Policy, which we talked a little bit already. Referral Policy is another big one. Itโ€™s important for your site to show that it sent traffic elsewhere. I said earlier that you could really keep the referral from an HTTPS to an HTTP site but thatโ€™s not necessarily true. Referral policy will actually let you still send that. If youโ€™re a directory, maybe Yellow Pages or something and you need to show that youโ€™re sending traffic to peopleโ€™s websites, you can still do it that way. The redirects also you mentioned are super important.ย Jon Henshawactually has a new proposal in or going in soon that I think is really cool, itโ€™ll show what system fired that redirect because itโ€™s getting really complex. Did the CDN fire, did some middleware system which go in the CDN and the server do it, did the server do it, did the CMS do it? Who fired that redirect? Sometimes thatโ€™s really difficult to figure out.

Jon Henshaw was at Raven Tools.

[00:39:29]ย new one.

Yeah. This is a tool thatโ€™s like a free plugin or is it a paid tool?

Heโ€™s putting in a standard proposal to say that if you do this redirect, you should identify your system, basically.

Got it. Okay, cool. Thatโ€™s the Referral Policy which is different from referrer. If youโ€™re trying to track a person from one website to another, thatโ€™s something youโ€™d show in your analytics.

Google for instance uses our overall policy of origin. You donโ€™t see the specific page on Google, it just shows, in that case, the domain. Youโ€™ll see that the traffic came from google.com. They went secure with their search but thatโ€™s how you still see everything in your analytics for them.

Yeah. But you donโ€™t see the keywords that were tracked.

No, because the origin ships everything but the domain name, it ships any sub pages or anything like that.

Thatโ€™s the issue that we all complained about as SEOs, for a long time the not provided going to 100% inside of Google Analytics and whatever analytics package, correct?

Yeah, absolutely. You can still get a lot of that data. I think it slips through peopleโ€™s mind that you can still get it Google Search Console, I think a lot of people complain about the limit there, but thereโ€™s plenty of tools, almost anything you want to use really, that will pull more than the standard data there.ย Search Analyticsย for Sheets, that oneโ€™s paid. You can do cool things like pull keywords for each page and make a quick pivot table and show that, and evenย Google Data Studioย has an export. You can pull tens of thousands, hundreds of thousands of keywords in one shot and export them.

[bctt tweet=”You can pull tens of thousands, hundreds of thousands of keywords in one shot and export them.” username=”mktg_speak”]

Right. There is a limit inside of Google Search Console when you just login to the tool, which is an amazing free tool. All you listeners need to be signed up with Google Search Console so you get this data. Inside of the Search Analytics reports, you can get a maximum of a thousand keywords or rows and you can only get a maximum of 90 days of data. Anything beyond that time period, you have no visibility into, unless youโ€™re using a tool thatโ€™s accessing this Search Analytics data through APIs and getting that data and then storing it over time. I useย Rank Rangerย which integrates with Google Search Console through the Google API so that it stores all that wonderful data over time inside of Rank Ranger. Also through the API, you can get much more than a thousand rows, you know what the limit is, at least 5000 rows but I donโ€™t recall.

Itโ€™s 5000 by default but they have a continuation function, so you can start at row 5001 and pull the next 5000 and do that indefinitely โ€˜til you have them all.

Wow. Thatโ€™s nifty, thatโ€™s ninja. Youโ€™re good at this stuff. Alright, we have Rank Ranger and what was the other tool? The one for sheets?

Search Analytics for Sheets and Google Data Studio also. Thereโ€™s a lot of them, the story that they actuallyย Ryteย fromย Marcus Tandlerย does, as well.

Yup, and youโ€™re using that as one of your spidering tools for looking for SEO issues, right?

Yeah, yeah. I personally like their crawler a lot, they also have the nifty TFIDF tool which I think is getting an overhaul soon. Really looking forward to see what they do with their content tool there.

We actually geeked out on that with Marcus, the founder of Ryte, which was called unpage.org previously. That was on an episode of Marketing Speak where we talked about TFIDF and we talked about some of the capabilities of the Ryte tool. Letโ€™s talk about JavaScripts because we briefly talked about it earlier in the episode and you mentioned some different frameworks like React. Some of these frameworks are more search engine friendly or search engine optimal than others. React, which is from Facebook, is actually ironically more search engine friendly than the latest version of Angularย which was developed by Google. I find that totally ironic, can you elaborate a bit on these frameworks and SEO?

Yeah. Angular to Angular Universal took a lot of those same stuff that React was doing well. Itโ€™s similar but React is probably the most search friendly depending on how itโ€™s done. By default, itโ€™s not really, you can start things like messy URLs, they actually have a really cool thing called React Router though, the basic tool that you set URLs however you want. You can do a lot of the rendering with the framework itself. One of the complaints with single page apps like that is it takes a while on the first load, youโ€™re loading the whole app and then the first page can be slow, after that it does really cool things. It does a dif on the DOM, it can determine what it needs to change only instead of rewriting the whole thing, itโ€™ll say, โ€œI need to change this stuff only.โ€ Itโ€™s really fast on page two, page three, etc. Thereโ€™s a lot of static versions of React, the initial load is Iโ€™ll put it as HTTP file. Works really, really well.

Cool. I remember there is a study that somebody did and they compared React and Angular 1, Angular 2 and I forget what else they compared in terms of SEO and how well does data that was being pulled through in asynchronous means would get crawled and indexed. Would links get explored that were inside of AJAX in React or Angular 1 or Angular 2? Do you remember the study?

Was that the one fromย [00:45:33]?

I think so. Itโ€™s a good write up. The bottomline was that Angular 2, he found to be less search engine friendly, harder for Googlebot to access that, the links inside of that and the content and then to index that.

Iโ€™m not sure if thatโ€™s necessarily true. That might be a difference in the developers. Any of them can be really, really unfriendly or really, really friendly. You have to really look out for things, this is why the DOM is important, you can view source and say hey, thereโ€™s not a link there, maybe there is but the DOM will tell you whether it loaded the link or you can monitor and see if it takes click action or something before whatever is loaded, Googleโ€™s never going to see that. I say never, not right now anyway. You have to be really careful with that kind of stuff. Any of them can be sort of friendly or sort of unfriendly. Vue is another one thatโ€™s becoming really popular right now, Veu.js and they all are okay. Iโ€™m still not completely sold, they have their uses. I think WordPress is going to use React actually after their licensing issues were resolved. I think theyโ€™re going to use it for the content editor for instance. Theyโ€™re still not going to switch the whole system over but maybe one day they will.

Yeah, okay. What would be your advice to somebody whoโ€™s listening whoโ€™s using infinite scrolling. Theyโ€™re using AJAX, Asynchronous JavaScript and XML, to pull data from their website asynchronously so itโ€™s an infinite scroll sort of situation just like youโ€™re scrolling through your Facebook news feed. What would be your SEO advice for somebody whoโ€™s doing that? Whatโ€™s your best practice suggestions?

Yeah. Youโ€™ll probably just want to set page state, separate points and then basically treat the reload as a whole new state. That new state can be the page. Those are a little tricky, and I usually donโ€™t recommend infinite scroll because Iโ€™ve rarely seen it done well.

If thereโ€™s no data, letโ€™s say the first 20 items arenโ€™t in the HTML, all of itโ€™s being pulled asynchronously, they run a risk of none of that being available to the spider to Googlebot thus not getting indexed.

Yeah, absolutely.

Cool, alright. Were there any other server response header type things or any redirect things that you wanted to share thatโ€™s ninja?

I think we covered a lot. Thereโ€™s a lot of stuff in the headers. Redirects can really, really be tricky. Like I said earlier, finding out where they come from, because they can really come from so many different locations these days. Then thereโ€™s the filing order too. We had one, this was a React base system. The redirects in the single page apps are handled themselves, but someone decided that they were going to send a location redirect like an HTTP header redirect, but they left the location blank. Basically Googlebot got redirected into nothingness before it ever solved the JavaScript redirect. You just have to be careful about that stuff, theyโ€™re not going see anything at that point.

Yup, alright. One server response header that I think we need to mention is xmeta robots. Because letโ€™s say you have a PDF document that you want no indexed, thereโ€™s a big difference between disallowing through robot.txt and no indexing a page or a document and you want it to not show up in the search results, you need to use a no index. Disallow only stops a spider from re-crawling the page and it still shows up in the search results. If weโ€™re dealing with a PDF document we want to drop from the index with a no index, thereโ€™s no meta tag that you can add because itโ€™s not HTML but you can use a server response header.

Yeah, absolutely. Thatโ€™s a good call. Canonical, very similar. You rarely ever see either of those in the head but they can be done and they can cause issues. Youโ€™re right, PDFs, thatโ€™s where people should use it but the number of times Iโ€™ve seen that actually happen is very rare, in fact theย Dan Sharpย ofย Screaming Frogย actually hijacked Googleโ€™s SEO best practice documents, because Google didnโ€™t actually have anything said either. They have a three or two redirect in place for this document and they didnโ€™t have a canonical tag, sad to say, this was the proper location. Just by having the duplicate content, Danโ€™s was treated as the source of truth and other people have done it before him. It was a running joke for a couple of years because most of the time peopleโ€™s SEO best practice document wasnโ€™t shown as google.com, it was shown as some other domain.

I cringe whenever I hear about that Google best practice document because there was ridiculous stuff in there advised about H1 tags and stuff. For years and years, itโ€™s been true that H1s have not improved rankings, you could switch all your H1s to a font tag and itโ€™ll have zero impact on your SEO.

Yeah. Thatโ€™s hard to say for sure but they probably take one in account, like font size and that kind of things these days. That would be an interesting test but I think it would be hard to get any kind of significant results from that test.

Iโ€™ve done some testing, Iโ€™ve gotten rid of H1 tags. The difference here is when somebody says I added H1 tags and it had an impact on my rankings, they added keyword rich headlines and they happen to warp that in an H1 container while they made multiple changes to the pages by doing that, they increase keyword prominence, they added some keyword rich copy high up in the rendered page with a large font size and they happened to use an h1 container. If they didnโ€™t use an H1 container, they would still have gotten their rankings benefit but they called it an H1 tag benefit but thereโ€™s multiple things going on. I think itโ€™s really important to do your SEO tests very strictly, very scientifically, use the scientific method, only one variable at once, have a control group, test your hypothesis and see if itโ€™s real.

Yeah. Sounds like youโ€™ve done the test already. Whatโ€™s your opinion on multiple H1 tags?

I donโ€™t think multiple H1s really make a difference at all. Itโ€™s not like a worse practice or a best practice, itโ€™s just code, itโ€™s like adding a dev tag or something, it doesnโ€™t really do anything. Itโ€™s more whatโ€™s rendered on the page is that important content as itโ€™s rendered or is it unimportant because if it looks unimportant to the user, it looks unimportant to Google.

Yeah. Iโ€™d say thatโ€™s absolutely true. HTML5 also allows for multiple H1 tags, with their side classes. Thereโ€™s a lot of misconception. I would still say have an H1 tag for sure, I wouldnโ€™t worry too much about multiple H1s these days. Thereโ€™s a lot of things that we do as SEOs that we do just because kind of, it might help, it might not, but we still do them, right?

This is a bug for me, because Iโ€™m very outcome focused and most SEOs are activity focused. If itโ€™s supposedly a best practice, they just got to do it, itโ€™s on the checklist. If the box is unchecked, theyโ€™re not done with their SEO project and I think thatโ€™s a mistake, I donโ€™t think thatโ€™s practical, I donโ€™t think thatโ€™s in the clientโ€™s best interest. If youโ€™re outcome focused, you have a goal, you want to attain that goal, that outcome, and you go after the highest value activities first. If those first three activities get you to your outcome, youโ€™re done, you come up with a new, bigger, more audacious goal to go after and a new set of activities for that. You donโ€™t go through the entire list of every single potential optimization, people are so busy working through meta descriptions for their entire sites and they have a massive website. Theyโ€™re not even thinking that you know what, meta descriptions are not an optimization ranking signal, theyโ€™re not a Google ranking signal and so theyโ€™re not going to improve their rankings for these meta description changes. Thatโ€™s my pragmatic approach.

Yeah. Iโ€™m completely with you. We do a lot of things that are time wasters. Meta description is a good one, usually thatโ€™s in everyoneโ€™s technical SEO audit, Iโ€™ll rewrite you meta descriptions, blah, blah, blah. I always say something like prioritize. Maybe your top 10 pages, maybe your top 50 pages can have those rewritten, but Iโ€™m still going to prioritize a lot of other stuff before I ever even recommend that.

And youโ€™re also a master at using scripts and tools to automate and scale across those 50 million pages so you donโ€™t have to a lot of manual labor. What would be an example of something that youโ€™ve written that is semi automated or fully automated, maybe youโ€™re dealing with redirects or something?

Thereโ€™s a lot of different things. Sometimes the stuff isnโ€™t necessarily great, itโ€™s just more for fun to do. I would say the one idea for redirects is a good example of that. I used machine learning and algorithm calledย [00:55:09]ย to match previous content with the closest relevant content on the website, basically enough with an order list of page one, page two, page three and how relevant they are. Usually the answerโ€™s in the top three but for business reasons it may not be the actual closest match. We have a lot of times of 20, 30 pages that are about the same thing unfortunately, so we do a lot of content consolidation because of that. The system is cool but if Iโ€™m really being practical about it, I would say do a site search with your keyword on the end and find which one of those pages you want to go to. One is going to take you a few hours to run, one is going to take you three seconds. What are you going to do?

Sometimes the stuff isnโ€™t necessarily great, itโ€™s just more for fun to do.

Boy, is that a cool thing to have a machine learning algorithm figure out what the closest, most relevant page is to another page. Letโ€™s say youโ€™re going to remove that one page from the site and youโ€™re trying to figure out where you want to redirect that to on a redirect map and you figured it out through machine learning, thatโ€™s pretty darn cool. Youโ€™re a ninja.

Yeah. One system that was actually useful for that, we had a previous system for detecting duplicate content and it used w-shingling which is [engramsย [00:56:27]ย which are like one, two, three, four, five keyword combinations and they were tokenized and we could compare the content to see how close it was to each other. But we did one with aย [00:56:40]ย also, that looked like sentence level, paragraph level and then the entire document level to do this comparison. We got about 5% better accuracy. Itโ€™s an incremental win but it was a win, I would say.

Thatโ€™s pretty cool. If your eyes are starting to glaze over as a listener because weโ€™re geeking out a bit too much, weโ€™re going to wrap up now so you can start to breathe again. Clearly Patrick, you know your stuff, youโ€™ve been doing SEO for a while and doing some really sophisticated SEO practices. Are you working solely for IBM or do you take on side gigs or can somebody work with you whoโ€™s listening to all your ninja advice?

I usually am pretty picky about side projects, my time is fairly limited, but if you have a really interesting problem, really difficult cutting edge legacy crap or just something that you canโ€™t quite figure out, sure.

Alright, awesome. How would somebody reach out to you? Should they go to your website? Where do you want to direct them?

Yeah. I have a website, stoxseo.com, which is being rewritten, donโ€™t judge me. Itโ€™s from 2010 right now, hand coded. Iโ€™m on Twitter @patrickstox.

Awesome! Thank you, Patrick. This was a lot of fun. I love geeking out and youโ€™re one of the geekiest and very, very skilled SEO. It was a real pleasure. Listeners, now take some action. If this is something thatโ€™s over your head but you know from this episode that itโ€™s important stuff, HTTP/2, HTTPS, doing some of the page speed optimization stuff we talked about, etc., ask your developers, ask your systems administrators to start making some changes to your website. Weโ€™ll catch you on the next episode of Marketing Speak, this is your host Stephan Spencer signing off.

Important Links:

Your Checklist of Actions to Take

โ˜‘ย Migrate my HTTP site to HTTPS or HTTP/2 to make it faster and more secure.

โ˜‘ย Research and be more aware of technical SEO terms. This will help me assign necessary tasks to my developer during site creation.

โ˜‘ย Hire a web developer who has at least has a beginner SEO background and is capable of doing some primary optimization on my website.

โ˜‘ย Never build a website without integrating SEO. Itโ€™s like building a house and forgetting to install the wires for electricity, then bring down the walls again to assemble them.

โ˜‘ย Look for ways to shortcut my SEO processes without jeopardizing the quality of the results.

โ˜‘ย Use hreflang tags on my site if it has multiple languages. This lets Google know which language I am using on specific pages.

โ˜‘ย Secure my site with HTTPS to avoid content injection and to prevent companies from posting ads without my consent.

โ˜‘ย Set up Google Analytics, sign up for Google Developer Tools, and change my site to HTTPS. This will help me be more informed on my website activity.

โ˜‘ย Make everything on my site load faster by migrating to HTTP/2.

โ˜‘ย Reach my target audience and improve my online visibility with the help of Ryte.

About Patrick Stox

Patrick Stox is a Technical SEO for IBM. He writes for many search blogs and speaks at many of the conferences. He’s an organizer of the Raleigh SEO Meetup (the most successful in the US) and was founder of the Technical SEO Slack group.