Skip to main content
Technical SEO
4 min readPublished on April 18, 2026Updated on September 09, 2026

XML Sitemaps in 2026: What Actually Belongs In One

Simon Heistermann

Simon Heistermann

Owner

This article was written with AI assistance and editorially reviewed.

Most sitemap problems are not caused by missing sitemaps - they are caused by overloaded ones. Dumping every URL that ever existed into a sitemap does not feed Google more content, it feeds it more noise. And noise costs crawl budget that is then missing from the pages that actually matter.

In short

A sitemap should contain only canonical, indexable pages with a 200 status. A maximum of 50,000 URLs and 50 MB per file, a sitemap index above that. changefreq and priority barely matter any more, but a correct lastmod date does.

What belongs in a sitemap, and what damages it

A sitemap is not a list of every URL that ever existed - it is a list of the pages you actually want to show up in search. It should contain only canonical pages with a 200 status that are not excluded from indexing with noindex and are not blocked by robots.txt. Everything else does more harm than good:

  • Redirected URLs (301 or 302) do not belong in the sitemap - only their final destination does
  • 404 pages or deleted content cost crawl budget without delivering anything in return
  • Pages marked noindex send a contradictory signal: the sitemap says "crawl this", the meta tag says "do not index it"
  • Duplicates from parameter URLs (filters, sorting, tracking parameters) do not belong in - only the canonical version does
  • Staging URLs, test pages and internal tools have no place in a public sitemap

Each of these categories dilutes the one signal a sitemap is supposed to send: here are the pages that matter. A lean sitemap with 200 relevant URLs is worth more than one with 2,000 URLs, half of which are dead links or duplicates.

Size and URL limits: when you need a sitemap index

A single sitemap file may contain at most 50,000 URLs and at most 50 MB of uncompressed file size. For most SME sites with a few dozen to a few hundred pages, this limit is irrelevant. It becomes relevant for large blogs, extensive product catalogues, or sites with many location pages. If either limit is exceeded, split the content across multiple sitemap files - one for blog posts, one for location pages, for example - and tie them together with a sitemap index that itself only references the individual files, not any URLs directly.

What a sitemap entry should technically contain

The specification allows for four fields, but they carry very different weight today:

FieldRequiredActual relevance in 2026
<loc>YesThe full canonical URL including https://, nothing works without it
<lastmod>Optional, but recommendedA relevant signal, provided it reflects the real last content change
<changefreq>OptionalLargely ignored by Google, not a reliable control lever
<priority>OptionalAlso largely ignored, no dependable effect on crawling

The practical takeaway: invest care in a correct lastmod, not in fine-tuning priority values. A lastmod that resets to the current date on every deploy, regardless of whether the content actually changed, gets recognised as unreliable by crawlers fairly quickly and is then simply ignored - and that loss of trust applies to the whole sitemap, not just the affected URL.

Submitting your sitemap and linking it from robots.txt

The standard path is /sitemap.xml at the domain root. Actively submit the URL through Google Search Console under Sitemaps and through Bing Webmaster Tools, rather than assuming crawlers will find it on their own. On top of that, add a reference in robots.txt so crawlers that never touch Search Console can still find their way to it:

Sitemap: https://your-domain.com/sitemap.xml

For a broader look at configuring robots.txt for classic and AI crawlers, see robots.txt in 2026.

Concrete steps for the next 90 days

  • Days 1-30: audit the current sitemap against the checklist above, remove redirected, deleted and noindex pages
  • Days 31-60: verify lastmod values for accuracy, set up automatic generation in modern frameworks that only updates on real content changes
  • Days 61-90: confirm the sitemap is registered in Search Console and robots.txt, re-check indexing status after four to six weeks

Conclusion

A sitemap is not a complete list - it is a curated one. Including only canonical, indexable pages, keeping lastmod values accurate, and respecting the size limits gives crawlers, classic and AI alike, a clean signal that actually works. How this pairs with deliberate internal linking is covered in Internal linking in 2026. For dynamic applications with client-side rendering, additional considerations apply, which we cover in JavaScript SEO for SPAs.

Want to know whether your sitemap is set up cleanly?

Get in touch
Technical SEO

WordPress or Custom Build? Run the Five-Year Numbers

WordPress powers a large share of the web, and for good reasons. What it actually costs to run, where it wins outright, and when a custom build makes sense.

September 09, 20265 min read
Technical SEO

Websites for IT Service Providers: Your Own Site Is the Work Sample

An IT provider with a slow, insecure website refutes its own pitch. What an IT manager checks in the first few minutes, and what follows from it.

September 09, 20266 min read
Technical SEO

Website Maintenance in 2026: What It Costs and What Must Be In It

What website maintenance actually covers, what the market charges for it, and how to spot an empty maintenance contract before you sign it.

September 09, 20267 min read
Technical SEO

Website Hosting for Businesses: What Actually Matters in 2026

Shared hosting, managed hosting or a platform: what the difference means for load time and resilience - and who actually owns the domain at the end.

September 09, 20267 min read
Technical SEO

SEO Costs 2026: What Visibility Really Costs

What SEO realistically costs small and mid-sized businesses: one-off optimisation versus ongoing management, and what should be included in the price.

September 09, 20266 min read
Technical SEO

A GDPR Check for Your Website: The Gaps That Are Almost Always There

Fonts from someone else's server, maps without consent, analytics before agreement: the typical gaps on SME websites, as a list you can actually check.

September 09, 20266 min read

Frequently asked questions

Simon Heistermann

Simon Heistermann

Owner

Heistermann Solutions is the web studio run by Simon Heistermann. We build custom websites for small and medium-sized businesses that want to achieve more online.

Every article grows out of day-to-day project work and is reviewed editorially before publication.

Get it for free

Enter your email address. You'll immediately receive a confirmation link - after clicking it the checklist is available right away.

Let's talk about your project

Free introductory call