In short: Three separate controls stop a Squarespace page being found, and they reach different distances: a per-page hide, a site-wide crawler block, and a password.
Only the last actually prevents access. The other two are requests, and a request that is honoured still leaves the page reachable by anybody with the address.
The one to audit on any site you inherit is the site-wide block, because it explains complete absence and nothing else on the dashboard hints that it is on.
The Three, And What Each Reaches
Hide from search results is a per-page toggle in the page's SEO settings. The page stays live and reachable at its address; what changes is that it asks not to be indexed.
Block search engine crawlers is the site-wide version, in the crawlers settings. It applies to everything at once and is the switch behind most cases of a site being entirely absent for no visible reason.
A password is the only one of the three that is not a request. A protected page cannot be read by a crawler because it cannot be read by anybody without the password.
The distinction that decides which to use: the first two are conventions that well-behaved systems honour, and the third is access control. If the requirement is "this should not show up in results", either of the first two is right. If the requirement is "nobody who should not see this may see it", only the password qualifies, and anything else is a comfortable misunderstanding.
Unlinked Is Not Hidden
Squarespace keeps a section for pages that are not in the navigation, and it is easy to read that as a private area. It is not one.
An unlinked page is a public URL that happens not to appear in a menu. It can be in the sitemap, it can be found, and it will be retrieved like any other page if something points at it. Teams put pricing experiments, old campaign pages and draft policies there on the assumption that not linking is the same as not publishing.
The useful version of that assumption is the opposite one: if a page exists at a URL, plan for it to be read.
What Hiding Costs You With Retrieval
Everything in the platform modules comes back to the same mechanism. A retrieval system has to learn a URL exists before it can fetch it, and the sitemap is the main way that happens on any site with more pages than a person would link by hand.
So it is worth checking what your sitemap lists after changing any of these, rather than assuming. On some platforms an indexing switch also removes the page from the sitemap and on others it does not, and the difference decides whether you have asked not to be listed or removed the way you are found. The Three Ways to Disappear on Shopify is the same question with different names on the controls.
The Audit, Which Takes Ten Minutes
- Open the crawlers setting and confirm the site-wide block is off unless somebody meant it.
- Fetch robots.txt and read what is actually served, rather than trusting the screen.
- Fetch the sitemap and check that your twenty most important pages are in it.
- List every unlinked page and decide, for each, whether it should be a public URL at all.
- For anything that genuinely must not be read, use a password rather than a hide toggle.
Write down what you found even where nothing was wrong. An audit that only records problems cannot answer "was this checked" in three months, which is the point The Technical Passes makes about negative findings.
Nothing here removes what has already been collected. Hiding a page stops it being fetched again; it does not reach into a model that was trained while the page was open, and it does not un-say anything an assistant has already learned to say about you.
Key Takeaways
- Hiding a page, blocking crawlers site-wide and setting a password reach different distances, and only the password prevents access.
- The site-wide crawler block is the one to audit on an inherited site, because it explains total absence and shows nowhere else.
- An unlinked page is a public URL that is not in a menu. Plan for anything with a URL to be read.
- Check the sitemap after changing any of these. Whether an indexing switch also removes the page from it differs by platform, and the sitemap is how a retrieval system learns the URL exists.
- Record what you checked even when it was fine, or the audit cannot answer the question later.
Check yourself
Before you move on
Not scored, not recorded, and not part of the certificate. Both answers are settled by a sentence in this lesson, and the reasoning appears whichever option you pick.
- 01
Which of these actually prevents a page being read, rather than asking for it not to be indexed?
- 02
A team keeps a pricing experiment on an unlinked page. What have they assumed wrongly?