Scenario · The bigger jobs
A prospect wants a free audit
A sales conversation where showing beats telling.
A sales audit for a prospect who hasn't granted any access has to earn trust with nothing but what's publicly visible — no logins, no analytics — which means every finding in it has to survive being checked by the prospect's own provider. This runs entirely from outside the site, and the deliberate discipline is cutting the result down to a small handful of the most credible, most consequential findings rather than a long list that reads as automated and gets dismissed wholesale.
What to ask for
See it work
A real run of Hosting & DNS:
example.com
hosting: Cloudflare (origin hidden)
platform: —
CDN/edge: Cloudflare
nameserver: Cloudflare
IP: <ip> CLOUDFLARENET - Cloudflare, Inc., US
email:
SSL: SSL Corporation
registrar: RESERVED-Internet Assigned Numbers Authority
registered: <date>
last change:<date>
account: active — SEO (Active)
expects: seo, analytics, content
CS: Jordan Casey
specialist: Priya Nandan
tech SEO: Sam Okafor
writer: Morgan Reyes
editor: Alex Chen
content dev:Jamie Park
HOSTING PLAYBOOK
wiki disabled (--no-wiki)
wrote ./out/hosting-and-dns.json
report: ./out/hosting-and-dns-hosting-and-dns.htmlThe captured report, exactly as a run hands it to a client —open the full report ↗
A sales artefact, which changes the rules: it goes to someone who has not agreed to anything, so it must be accurate, readable, and free of anything that reads as a scare tactic. Findings that cannot be substantiated cost the meeting.
- Confirm this is a real prospect and the audit is wanted. Unsolicited audits of businesses that never asked are cold outreach with extra steps, and for a medical practice they land badly.
- Run the site-level audit. One pass discovers the URLs, detects the stack, and fans out across QA, redirects, images and — where detected — WordPress and Divi. This is the bulk of the substance and it needs no access to anything.
- Read the infrastructure. Hosting, DNS, SSL and registrar, plus whether the domain or certificate is near expiry. An expiring certificate is the single most credible finding available from outside, because it is verifiable in ten seconds and has an obvious consequence.
- Check AI search visibility. Whether the engines name them for their own procedures and city, and who takes the share of voice instead. This is currently the finding prospects have least visibility of and react to most.
- Optionally cross-check with the remote engine, which also serves as a second source for anything you intend to put in front of them.
- [manual] Cut it down hard. Three findings, not thirty. The most credible, the most consequential, and one that is quick to fix — the third one demonstrates competence more than the other two demonstrate need. A forty-item list reads as automated and is easy to dismiss wholesale.
- Assemble the document and say what it did not cover. The roll-up builds the branded deliverable; add the note that this was done without access, and that the things it could not see are usually where the larger problems are. That sentence is honest and it is also the reason for a follow-up conversation.
Three findings, all verifiable
Every finding in a prospect document will be shown to their current provider, who is motivated to discredit it. One overstated item discredits the whole audit. That is why step 6 is a reduction step and why nothing unverifiable from outside belongs in it.
What this does not cover
Anything requiring access. This runs entirely from outside — no analytics, no Search Console, no logins — so it cannot report traffic, conversions or rankings, only what is observable on the public site. That limit is worth stating in the document, because a prospect who thinks it covered their analytics will wonder why it missed the obvious.