Recovery audit, September 2026 · recovery plan

E-ITA.org Recovery Plan

The implementation half of the audit: 14 steps in 5 phases, each with an acceptance check, plus the measurement contract that judges them. The evidence behind every referenced finding ships as the companion document: E-ITA.org Methodology and Findings.

Sitee-ita.org
Data window2025-05-02 to 2026-09-16
Report date2026-09-24
Collapse date2026-08-21

05 Context and How to Read This Plan

This document is the implementation half of the audit. It holds the 14 steps in 5 phases and the measurement framework that judges them. The evidence behind every referenced finding (the loss segmentation, the change correlation, the quality assessment, the off-site review, and the extended analysis) ships as the companion document: E-ITA.org Methodology and Findings.

What happened, in 5 points

Why not roll back

A question this plan answers: should the site roll back to an earlier state? No. Archive checks across 2024 to 2026 and the release history show every earlier version carried the same template and claims layer that lost traffic, and older code reopens patched security advisories. Two limits qualify the archive half of that check: the release history starts 2026-03-28, so no earlier site state exists in it, and the archive holds no country-page captures after 2026-07-09 and almost no homepage coverage between 2026-05-15 and 2026-09-20, so it cannot show what Google re-scored in August 2026. The path forward is the phased rebuild below; rollback is cleanup, not recovery.

The plan at a glance

PhaseWindowWhat it delivers
0This weekMeasurement and safety: contradicting claims removed, order metric locked, redirect map deployed
1Days 1 to 30Trust layer: named authorship on every page, the reviews program, 2 brand-defense pages, AI-crawler policy
2Days 30 to 90Content rebuild: 64 country pages rewritten to the Differentiation Standard, honest 1-year SKUs, the guide pipeline, locale fixes
3Days 90 to 180Entity building: affiliate program, link reclamation, the editorial layer
4OngoingMeasurement cadence: weekly checks and monthly re-sweeps against the Part 7 gates

How to read this document


PART 6 Recovery Plan

This part is the implementation guide. It has 14 steps across 4 working phases, plus an ongoing measurement phase. Each step lists granular actions, the finding it answers, and an acceptance check.

Work the phases in order. Cheap, reversible fixes ship first. The redirect surgery ships last, after Google can re-crawl a site that states who runs it and by what authority it sells.

5phases, run in order
15steps, each with an acceptance check
0 of 6readiness gates green on 2026-09-17
~270clicks/day, the plateau path target, not the 2025 peak
Risk: Expect rankings to look worse between 2026-10-19 and 2026-12-06. That window carries the kill and fold deploys.
  • The killed 162 and the folded 155 still collect about 2.1 clicks/day of long-tail trickle; removing them zeroes that.
  • A fall toward 15 clicks/day inside the window is expected.
  • Below 15 clicks/day for 7 straight days is amber; 14 straight days is not expected. If it happens, stop and audit redirects, tracking, and new suppression.
The drop is the expected effect of removing the spam pattern, not a new failure. Pre-agree this reading before the work starts.
PhaseWindowGoalStepsExit criteria
Phase 0This weekMeasurement and safety3Claims fixed; order metric defined; the 177-row 301 map live
Phase 1Days 1 to 30Trust layer4Authorship live; review program live; 2 brand-defense pages live; crawler policy decided
Phase 2Days 30 to 90Content rebuild4 plus the citation standardCountry pages rewritten to the standard; SKUs honest; guide pipeline live; locales fixed
Phase 3Days 90 to 180Entity building3Affiliate program recruiting; reclaimable links reclaimed; editorial layer publishing
Phase 4OngoingMeasurement cadenceHeld in Part 7Weekly checks and monthly re-sweeps run directly; see Part 7
Source: phase windows and sequencing as defined above; recovery detection and dip window per the Part 7 KPI framework.

Phase 0: This week (measurement and safety)

Do these 3 steps first. Nothing here is reversible-risky, and everything downstream depends on it. While they run, freeze the page set: no new pages, new locales, or automated rewrites until the plan ships.

  1. Remove the contradicting claims. Edit the shared template once. Do not edit 362 pages by hand. Then work the list:
    • Delete the string "Accepted in 175+ countries including Japan". The line lives on 362 pages.
    • Publish 1 exclusion list naming Japan, South Korea, and mainland China. Word it the same on every page and in every locale. Match the FAQ and the terms pages.
    • Delete the "8 minutes" delivery claim, or publish proof for it. The line lives on 282 pages. Use 1 processing-time number per context.
    • Remove the recycled testimonial block. Keep a testimonial only where an order record substantiates it. 169 pages carry contradictory claims today.
    The homepage currently contradicts the FAQ on the same question (Part 3.3). An AI engine quotes the site against itself (Part 5.1).
    Spam policies: scam and fraud “Scam and fraud come in many forms, including but not limited to impersonating an official business or service through imposter sites, intentionally displaying false information about a business or service, or otherwise attracting users to a site on false pretenses.”
    SQRG 5.6, p.63 “If you find the information about the website or the content creator to be exaggerated or mildly misleading, the Low rating should be used.”
    SQRG 4.5, p.35 “Multiple or significant factual inaccuracies on an informational page which would cause users to lose trust in the webpage as a reliable source of information”

    Acceptance check: view source on /, /faq/, and /italy/ shows zero occurrences of "175+" and "8 min". 1 page carries the exclusion list. 1 page carries the AAA/AATA disclosure block.

    Finding cross-ref: Part 3.3; Part 5.1.

  2. Lock the measurement rules. Adopt order_complete as the single order metric in every report. Never quote raw key-event totals: generate_lead is 86.5% of post-collapse key events and masks the order trend (Part 5.5).
    • Annotate every deploy the same day, before push. Record date, scope, URLs touched, reason, and expected signal.
    • Treat GA4 figures from 2026-07-02 to 07-27 as void. Collection recorded zero traffic for those 26 days.
    • Identify what fires generate_lead and the "(not set)" visit block born 2026-07-28. That block holds 58.3% of post-collapse orders. Tag it or exclude it before reading any order curve.

    Acceptance check: every report quotes order_complete only. Every deploy carries a same-day annotation. The "(not set)" block is tagged or excluded.

    Finding cross-ref: Part 5.5; Part 7.

  3. Deploy the redirect map and fix the residue URLs. Ship the 357-row map in 2 stages: the 177 rows that return 301 to their mapped targets now, and the 180 rows that return 410 from week 3, after the identity layer is live.

    Why the kills return 410, not 301. A 301 to the homepage feels like the safe call, but Google reads a redirected dead page as a soft 404: the homepage is not what the searcher asked for, so the redirect gets flagged and the dead URL can linger in the index for months with a stale snippet attached. Users bounce the same way: they click expecting a specific page, land on the homepage with no explanation, and leave. A 410 is the clean signal: this page is gone for good, so remove it now. Google strips 410s from the index faster than 301s or 404s, crawl budget stays on pages that exist, and a custom 410 page can still tell the visitor the page is retired and point them at the nearest hub. That is why the 180 kill rows return 410.

    • Build the 6 redirect-target pages first: /africa/, /europe/, /americas/, /asia-pacific/, /middle-east/, and /guide/international-driving-permit-car-rental-companies/. They return 404 today. No 301 row may ship before its target returns 200.
    • Map each removed URL to its closest live equivalent. Never map a removed URL to the homepage.
    • Fix the residue: /argentina-2/ must reach /argentina/ in 1 hop, and /Italy/ and /Italy3/ must return 301 to /italy/.
    • Keep https on every hop. Return 410 on the 18 historic /translations/ slugs and kill their https-to-http downgrade chain.
    • Request re-crawl in Search Console for every touched URL batch after deploy.
    • Probe 25 evenly spaced map rows daily. Run the full 357-row sweep weekly. The full map is green by the Part 7 gate target of 2026-11-15.
    The page-by-page verdict sorts 454 audited URLs into keep 73, rewrite 64, fold 155, kill 162 (Part 3.5). The residue URLs are verified and itemized in Part 3.2.

    Acceptance check: a 25-URL sample of the map returns the expected status on every row. /argentina-2/ resolves in 1 hop. /Italy3/ returns 301 to /italy/.

    No row targets the homepage.

    Finding cross-ref: Part 3.5; Part 3.2.

Phase 1: Days 1 to 30 (trust layer)

The trust layer answers who runs the site and why anyone should believe it. It ships before the content rebuild so Google's re-crawl of the cut page set lands on answered questions.

  1. Build the authorship layer. No author or reviewer exists anywhere on the domain today. Work the list:
    • Assign a named author and a named reviewer to every editorial page, including the 73 keep pages.
    • Publish 1 bio page per person. State credentials relevant to driving documentation.
    • Acceptable credentials: travel law, automotive club work, rental operations, or documented travel in the country.
    • Add Article markup with author and reviewedBy fields. Emit datePublished and dateModified in ISO 8601 format.
    • Until a named person is approved, use the organization fallback: an "EITA editorial team" byline plus a named reviewer role.
    • Hold the gate: no rewrite ships without author and reviewer schema live.
    Authorship scores 4.67 of 10 across 445 live pages (Part 3.5).
    SQRG 4.5.1, p.36 “YMYL pages or websites that handle sensitive data with absolutely no information about the website or content creator should be rated Lowest.”
    Helpful content guidance “Is this content written or reviewed by an expert or enthusiast who demonstrably knows the topic well?”
    SQRG 3.3.4, p.25 “Educational degrees, peer validation, expert co-authors, and citations can be evidence of positive reputation information for professionals who publish their work.”
    Risk: never invent a profile. Fabricated author pages are a Lowest-rating trigger, not a shortcut.
    SQRG 4.5.3, pp.36-37 “A webpage or website with "fake" owner or content creator profiles. For example, AI generated content with made up "author" profiles (AI generated images or deceptive creator descriptions) in order to make it appear that the content is written by people.”

    Acceptance check: every shipped page shows a named author and reviewer with working bio links. The page markup parses with zero errors.

    Finding cross-ref: Part 3.5.

  2. Start the reviews program. Work the setup, then the reply engine:
    • Re-check the live Trustpilot profile in a browser. Record score, review count, one-star share, and reply rate. Quote no archived figure before this check.
    • Two archived figures conflict: 4.6 stars on 2026-09-05, against 4.2 and 1,328 in a stale February 2026 cache served to bots. The 2026-09-14 re-render read 4.5 stars and 1,555 reviews; a 2026-09-22 browser check read 4.6 stars and 1,563 reviews.
    • Enable Trustpilot Automated Feedback Service invitations on the fulfillment event, not the purchase event.
    • Invite every purchaser. Apply no sentiment filter anywhere in the flow.
    • Use 1 neutral template. Offer no incentive. Use no star-direction language.
    • Seed with the company's own test orders before go-live. Log every send in a dated compliance log.
    • Reply to 100% of new negative reviews within 48 hours. Sweep the one-star backlog weekly until cleared.
    • Structure every reply the same way: acknowledge, state the honest product scope, root-cause the specific claim, offer a concrete resolution path, move detail to support.
    • Pre-load the honest-scope paragraph into 3 templates: wrong expectation, delivery or document issue, police or rental refusal.
    Write 1 specific, professional reply to the review that quotes Italian police calling the permit "a fraud". UNVERIFIED The review sits in the 2026-09-05 engine capture but was not locatable live on 2026-09-14; the standing reply program covers it either way. Post the reply once, only if the review is visible. Never argue in the thread. Offer no incentive for any review. The leader replies to nearly all visible reviews; the site replies to about 5% of negatives (Part 4.3).
    SQRG 3.3.2, p.23 “Credible, convincing reports of fraud and financial wrongdoing is evidence of extremely negative reputation.”

    Compliance frame: generalized solicitations to all purchasers are the safe harbor, per the FTC rule on consumer reviews (16 CFR 465.2(d)(1)). Sentiment-conditioned incentives are prohibited under 16 CFR 465.4. Review gating is deceptive under 16 CFR 255.2(e) Example 11. Trustpilot's own rule matches: invitations must be neutral and unbiased, with no incentives offered (Trustpilot Guidelines for Businesses, June 2026).

    Directional month-3 (Phase 2) targets: reply rate at or near 90%; review count up 90 to 150; one-star share flat to down. Diluting the 11% one-star share below 7% is a 12-to-24-month trajectory, and the claims fixes are the load-bearing lever.

    Acceptance check: automated invitations are live. A weekly check shows 100% of new negative reviews answered within 48 hours. The police review carries a visible, professional reply.

    The compliance log shows every send and every reply.

    Finding cross-ref: Part 4.2.

  3. Publish the 2 brand-defense pages. Build both to this spec:
    • Publish /reviews: 1 canonical page. Carry dated, attributed, anonymized excerpts, both positive and negative, each with the company reply where one exists.
    • Add a visible "how we collect reviews" note to /reviews. Refresh the page monthly. Link out to the live Trustpilot profile as the full record.
    • Publish /is-e-ita-legit. Answer in the first paragraph. Sign it with the entity name, the address, and a visible last-updated date.
    • Answer 4 things directly on /is-e-ita-legit: what EITA LLC is, what the product is and is not, the AAA/AATA disclosure, and the refund policy.
    • Do not add self-serving review markup to either page. PROBABLE Google's 2026-07-24 review-snippet update makes fake or undisclosed-incentivized reviews a markup-level penalty surface (trade-press capture; not re-verified).
    • Also publish an About page and a real contact page. /about-us/ currently returns 404.
    • Put the physical address, entity details, and support channels on the contact page.
    • Add 1 line to both defense pages: "EITA LLC operates e-ita.org only." This separates the brand from lookalike sites.
    • Link both defense pages from the footer, sitewide.
    The 2019 and 2022 forum threads cannot be removed, so outrank them (Part 4.2). ChatGPT cites zero brand-owned sources on the legit question today (Part 5.1); first-party pages become the citable surface.
    SQRG 4.5.1, p.36 “Any site that handles personal, private or sensitive data must provide extensive contact information. This includes sites that ask users to create passwords, share personal information, or conduct financial transactions.”
    SQRG 5.5, p.63 “Pages that offer payment functionality or process other types of financial transactions should receive a Low rating if there is an unsatisfying amount of customer service information or contact information.”

    Acceptance check: both pages are live, indexed, and dated. Both reach page 1 for the brand-plus-legit query within 90 days (a Phase 2 target). The contact page shows the physical address and support channels.

    Finding cross-ref: Part 4.2; Part 5.1.

  4. Decide the AI-crawler policy, publish llms.txt, extend the schema. The WAF (web application firewall: the Cloudflare layer that filters requests) is the blocker today. Work the list:
    • Write the crawler decision down in 1 paragraph. Allow GPTBot, ClaudeBot, Bytespider, and OAI-SearchBot in the WAF.
    • In Cloudflare, open Security, then Bots. Turn off "Block AI bots", or add a WAF custom rule with the Skip action for verified bots.
    • Keep robots.txt permissive. robots.txt is not the blocker today; the WAF is.
    • Verify bots by IP address, not by user-agent string alone. Match hits against the published lists at openai.com/gptbot.json, claude.com/crawling/bots.json, and perplexity.com/perplexitybot.json.
    • PROBABLE ByteDance publishes no official IP list for Bytespider. Treat its identity as community-documented.
    • Probe all 5 user-agents weekly: GPTBot, ClaudeBot, Bytespider, PerplexityBot, and OAI-SearchBot. All 5 return 200 by 2026-10-11.
    • Publish /llms.txt as plain text. Link only surviving canonical URLs. PROBABLE llms.txt is a 2024 community proposal (llmstxt.org); no major engine has publicly committed to honoring it. Ship it anyway.
    • Add Organization and WebSite JSON-LD to the homepage, with the legal name.
    • Add BreadcrumbList markup to country pages as they rewrite.
    • Fix the markdown twins: strip the leaked doctype line, give the /faq/ twin exactly 1 level-1 heading, and unescape the frontmatter values.
    CONFIRMED on 2026-09-17: 3 crawlers blocked, llms.txt 404, FAQPage-only markup (Part 5.2). Note: structured data is not a ranking factor; Google's documentation does not list markup as one. The markup fixes how machines read the entity.

    Acceptance check: a probe with each of the 5 crawler user-agents returns 200. /llms.txt returns 200 as plain text. The homepage parses with Organization and WebSite nodes. / and /faq/ return markdown with no doctype leak, and the /faq/ twin carries exactly 1 level-1 heading.

    Finding cross-ref: Part 5.2.

Phase 2: Days 30 to 90 (content rebuild)

The content rebuild replaces the templated country farm with pages a rater can tell apart. 2 model pages are ready templates, /italy/ (English) and /es/estados-unidos/ (Spanish), alongside the Differentiation Standard. Clone the model pages; do not invent a new shape.

  1. Rewrite the country-template program. Every rewrite-verdict page must meet the Differentiation Standard. Start with the order-bearing pages. Per page, require all of the following:
    • At least 10 facts that appear on no other country page.
    • At least 5 primary sources, each with an accessed date.
    • 1 filled data table, such as issuing body and convention status.
    • 800 to 1,500 country-specific words; 2,500+ for priority markets.
    • Below 30% shared n-gram overlap with every sibling page.
    • A named author and reviewer.
    • One H1; no heading string repeats within a page, and country-specific headings do not repeat on a sibling page.
    • 3 visible dates: published, reviewed, and last verified.
    Then run the production workflow:
    • Clone the 2 model pages. Carry their 12-section anatomy in the same order on every page.
    • Build each page through 6 steps: research pass, draft, SME review, linguist pass for translated pages, quality gates, publish and annotate.
    • Run the research pass against the whitelist below. Record every URL, its status, and its accessed date in the page working file. Target 15 candidate facts per page.
    • Ship the 25 order-bearing pages first. All order share sits on English pages. Then rank the rest by click loss.
    • The first batch of 10: /italy/, /spain/, /us/, /united-kingdom/, /greece/, /kuwait/, /egypt/, /france/, /thailand/, /canada/. These carry the 2,500+ word target.
    • Hold 3 hard gates before publish. Overlap must read below 30% against every sibling. Every numeric claim carries a cited source. No contradiction survives against the FAQ, the homepage, and every locale.
    • Where automation contributed to a page, add a per-page disclosure block answering who was involved, how automation was used, and why. A site-wide sentence with no per-page indication fails the standard.
    • Complete all 64 rewrites by 2027-01-31 (the plan's third deadline gate); the plateau path in Part 7 needs them done by early December.
    184 of 195 English country pages have a sibling above 0.90 similarity today (Part 3.2).
    Spam policies: scaled content abuse “Scraping feeds, search results, or other content to generate many pages (including through automated transformations like synonymizing, translating, or other obfuscation techniques), where little value is provided to users”
    Spam policies: scaled content abuse “Scaled content abuse is when many pages are generated for the primary purpose of manipulating search rankings and not helping users. This abusive practice is typically focused on creating large amounts of unoriginal content that provides little to no value to users, no matter how it's created.”
    SQRG 4.6.5, p.42 “Pages and websites made up of content created at scale with no original content or added value for users, should be rated Lowest, no matter how they are created.”
    SQRG 3.2, p.21 “Accuracy: For informational pages, consider the extent to which the content is factually accurate. For pages on YMYL topics, consider the extent to which the content is accurate and consistent with well-established expert consensus.”
    SQRG 4.7, p.46 “The website terms of use states that "some articles" are generated by artificial intelligence and may have errors or be out of date; there is no indication to which pages this statement applies. The information in this article is not trustworthy and is Lowest E-E-A-T”

    Acceptance check: every page's claims carry their cited sources, with no open rows in the page working file. A diff against every sibling reads below 30% overlap. Author and reviewer markup is live on the page. Heading uniqueness is checked in the page and against sibling pages.

    The change log records the gate results per page.

    Finding cross-ref: Part 3.2; Part 3.5.

  2. Replace multi-year SKUs with renewal plans. Work the list:
    • Retire the 2-year and 3-year permit SKUs.
    • Sell a 1-year product as the flagship.
    • Offer a prepaid renewal plan at the same total price, so 3-year revenue holds.
    • State on the checkout page, in plain text: the product is a private translation booklet, not a government permit.
    • Carry the same statement in the FAQ, the terms pages, and every locale.
    • Where US buyers are addressed, quote the official 1-year rule. USA.gov states: "An IDP is valid for one year and cannot be renewed." (USA.gov, International Driving Permit, last updated 2026-04-14).

    The 1-year cap comes from the 1949 convention framework and issuer practice. The multi-year validity claim is the exact string AI engines quote as a warning sign (Part 5.1).

    Fixed-term renewals are the documented norm for travel documents. TSA PreCheck and Global Entry run fixed 5-year terms; ESTA runs a 2-year term with reapplication (TSA, CBP, and CBP ESTA published fee pages, checked 2026-09).

    PROBABLE No private IDP-vendor renewal SKU was verified. Treat the renewal-plan shape as the honest-reframe path, not a copied precedent.

    SQRG 5.6, p.63 “If you find the information about the website or the content creator to be exaggerated or mildly misleading, the Low rating should be used.”

    Acceptance check: no page sells a validity above 1 year as permit validity. The renewal plan keeps 3-year revenue. The checkout states what the product is and is not.

    Finding cross-ref: Part 5.1.

  3. Build the country-guide pipeline on original data. Work the list:
    • Build 1 "Do I need an IDP in X" guide per rewritten country page, in the existing guide collection.
    • Insert 3 first-party proof classes: anonymized orders per destination, reported rental-desk issues, and refund reasons.
    • Suppress any country count below 10. Round larger counts down to the nearest 50. Label every figure with its window, for example "Jun-Sep 2026".
    • Publish under the same authorship, sourcing, and citation rules as the country pages.
    • Mine support tickets monthly. Add the top 5 to 10 questions per country to the page FAQ. Answer each through the citation gate.
    • Log rental-desk reports in a country-keyed sheet: document type, printed or digital, company, country, date.
    • Update a country's "Rental desk reality" section after 2 consistent reports. Date the update.
    • Never invent a report or a count to fill a section.
    Anonymize every figure. Originality scores 2.18 of 10 across live pages today (Part 3.5). Original information is the first helpful-content question.
    Helpful content guidance “Does the content provide original information, reporting, research, or analysis?”
    Helpful content guidance “Does your content clearly demonstrate first-hand expertise and a depth of knowledge (for example, expertise that comes from having actually used a product or service, or visiting a place)?”

    Acceptance check: every pipeline page names its sources and dates. Every figure traces to the order system. The authorship block is live.

    Finding cross-ref: Part 3.5.

    Tooling: run this operation as a repeatable monthly cycle with the travel-content-skill package, not a one-off project. It is a six-step content pipeline for travel sites: research sweep, scored idea slate, drafting, editor pass, audit and fix pass, and localization on request. For this site it turns the country-guide pipeline into a standing monthly operation, and its gates match this plan: every page needs a named author, pages on legality, money, safety, or health need a named reviewer, the freshness window is an operator setting, and a page ships only when a reader cannot get it elsewhere.

  4. Fix the localization gaps. Patch the locale template once, then go locale by locale:
    • Localize every locale title tag, meta description, and H1. Ship es, fr, it, and ar first; these 4 survivor locales hold 124 pages on the verdict-sheet basis (120 live).
    • The 124-page template-level pass is scoped per locale. PROBABLE The scope is an estimate, not a measured value.
    • Add the missing H1 to the 37 live pages without one (per the 2026-09-13 crawl). Every locale FAQ carries exactly 1 H1.
    • Remove the doubled brand suffix on locale FAQ and legal pages.
    • Remove the source-level duplicate eligibility H2 string from the page template (it repeats in source on 313 of the 445 live pages; one copy sits inside a widget payload). The rendered pages do not show a duplicated H2 today (live check 2026-09-21).
    • Hold 1 register per page. Spanish currently mixes tu and usted.
    • Pick 1 product term per locale. Spanish holds one of IDL, PIC, or Permiso de Conducir Internacional.
    • Ban English title case in non-English headings.
    • Credit a named fluent reviewer on each locale page. Carry the same citation set as the English master.
    • Fix hreflang among surviving locales only. Emit an alternate only when the localized page exists, returns 200, and links back. Today the hreflang sets break two of the three conditions: 30 non-reciprocal edges and 33 targets at redirected URLs.
    • Localize the language-switcher chrome.
    • The verdict sheet retires 7 locale hubs: /de/, /el/, /hi/, /pt/, /ru/, /th/, /tr/. Apply this step to the 4 survivors: /es/, /fr/, /it/, /ar/.
    8 of 11 locale hubs carry English title tags today (Part 3.3).
    SQRG 3.2, p.21 “On the other hand, the automatic creation of thousands of pages by running existing freely available content through existing translation software without any oversight, manual curation, etc., would not be considered to have effort.”

    Acceptance check: a crawl of the 4 surviving locale hubs shows zero English title tags. Every locale FAQ has exactly 1 H1. Each locale page names its reviewer.

    Finding cross-ref: Part 3.3.

The citation standard: whitelist and blacklist

Every rebuilt page stands on citations. The IDP topic is YMYL (Your Money or Your Life: topics where wrong content can harm finances or safety), so the scrutiny standard is high.

SQRG 2.3, p.13 “For pages about clear YMYL topics, we have very high Page Quality rating standards because low quality pages on such topics could potentially negatively impact a person's health, financial stability, or safety, or the welfare or well-being of society.”

The rule of thumb: the official source wins. When sources conflict, the page states the conflict and defers to the more authoritative source.

SQRG 3.4, p.26 “The official government page for getting a passport is the unique, official, and authoritative source for passport renewal.”

(a) The whitelist: approved sources by claim type

Claim typeApproved sourcesExample claim it supports
Convention status (1949 Geneva, 1968 Vienna)UNECE, Texts and Status (unece.org)"Italy is party to the 1968 Vienna Convention."
Whether a country honors IDPs; the official countU.S. Department of State, 7 FAM 1430 (fam.state.gov); AAA IDP country list (aaa.com)"More than 150 countries honor IDPs."
Rules for US travelers in country Xtravel.state.gov country information pages; US embassy and consulate pages, for example U.S. Embassy in Japan (jp.usembassy.gov)"Americans cannot drive in Japan on a US license alone."
US issuers of record; the scam frameFTC alert (consumer.ftc.gov, 2024-06-24, issuer note updated 2025-07-16); USA.gov (usa.gov); AAA (aaa.com); AATA (aataidp.com)"Only AAA and AATA are authorized by the US Department of State."
United Kingdom rulesGOV.UK, Driving abroad (gov.uk)"Check whether you need an IDP before you travel."
France rulesservice-public.fr, Permis international (F11534)"The permis international is requested online."
Germany rulesGerman Federal Ministry for Digital and Transport (bmdv.de); local Straßenverkehrsamt pages"Apply at the licensing office where you live."
Italy rulesACI-hosted Codice della Strada art. 135 (aci.gov.it); Ministero dei Trasporti"The international permit is issued by the authority that issued the license."
Japan rulesJAF, Driving in Japan (english.jaf.or.jp); National Police Agency (npa.go.jp)IDP validity in Japan, per JAF and the National Police Agency.
Spain rulesDGT, Permiso internacional (dgt.es)"The international permit is a complementary permit."
Australia rulesState transport portals, for example Service NSW (service.nsw.gov.au); Australian Automobile Association (aaa.asn.au)"IDPs issue through the AAA network and state clubs."
Canada rulesCAA (caa.ca); provincial licensing pages"CAA is the authorized issuer for Canadian licenses."
Rental desk requirementsEuropcar IDP requirements (europcar.com); Avis location pages (avis.com); Hertz; Sixt"Rental desks list license and IDP requirements per country."
Federation positions on private IDLsFIA, Travel and Tourism (fia.com); AIT Touring Alliance (ait-touringalliance.com)"IDLs sold online are not legally recognised."
Statute changes and fee schedulesOfficial gazettes and journals, for example Bundesgesetzblatt (bundesgesetzblatt.de), BOE (boe.es), Gazzetta Ufficiale (gazzettaufficiale.it)"The fee schedule changed on [date]."
Travel demand contextUN Tourism Barometer (untourism.int); NTTO at trade.gov; IATA"Global international arrivals grew 4% in 2025."
Source: every URL checked live during the audit window 2026-09-14 to 2026-09-18, or verified against its cited sources. A page that returned 403 or blocked at research time may be cited only after a successful re-fetch. Fetch state on 2026-09-21: unece.org, travel.state.gov, aataidp.com, untourism.int, and bmdv.de blocked automated fetches (403 or timeout); each was retrieved during the audit window, and the issuer designations they support are corroborated at usa.gov and 7 FAM 1430. The ADVrider thread returns a JavaScript proof-of-work challenge to automated fetches on 2026-09-21; it was live-fetched by browser on 2026-09-14 (Part 4). Four more cited domains block scripted fetches while opening normally in a browser: trustpilot.com (browser-verified reads on 2026-09-05, 2026-09-14, and 2026-09-22), tripadvisor.com (SERP-verified), forbes.com, and unwto.org (which redirects to the blocked untourism.int).

(b) The blacklist: source types to never cite

Source typeWhy bannedExample domains to never cite
Rival IDP vendorsDirect conflict of interest. Their acceptance claims are marketing, not evidence. A citation endorses a competitor. Scope: never cite these domains on rebuilt pages. Reading a rival's affiliate terms as market research is not a citation.internationaldriversassociation.com; idaoffice.org; fastidp.com; internationaldrivingpermit.org
Lookalike and scam operatorsPolice-fraud reviews and ecosystem contamination. Citing one conflates the brand with a lookalike.e-itca.org
Wikipedia, Wikisource, and mirrorsCrowdsourced text is not legal authority. Transcriptions drift. Cite the treaty depositary instead.wikipedia.org; wikisource.org
Expat and travel blogsNo accountability. Recycled marketing claims, affiliate-incented content, and stale dates.twocantravel.com; mominitaly.com; schengentraveler.com
Forums and Q&A sitesAnecdote, not authority. Treat them as reputation evidence to monitor, never as citation sources.reddit.com; quora.com; tripadvisor.com forums
Scraped or stale aggregatorsUndated snapshots can be wrong and outrank the brand. No text provenance.eitareviews.com
Sites that sell coverageA "write for us" or "sponsored post" page means the source sells authority. What it publishes is inventory, not evidence.Any domain advertising paid posts
Source: category rules grounded in the source hierarchy and reputation findings. Conflict-of-interest rule: SQRG 3.4, p.27 “Important: The website or content creator may not be a trustworthy source if there is a clear conflict of interest.”

(c) Citation mechanics

Helpful content guidance “Does the content present information in a way that makes you want to trust it, such as clear sourcing, evidence of the expertise involved, background about the author or the site that publishes it, such as through links to an author page or a site's About page?”

External sources: the officialness, mirror, and machine-readability tests follow standard field practice. Cite statute text from official registers. Read pages as a crawler sees them: View Source, not a browser preview.

Acceptance check: every rebuilt page carries at least 3 primary outbound citations, at least 1 from a government or club authority and 1 from a rental-company source; every cited URL passes the View Source check; and every source line carries an accessed date in YYYY-MM-DD form.

Finding cross-ref: Part 3.5.

Phase 3: Days 90 to 180 (entity building)

Entity building grows who e-ita.org is off-site. It starts after the on-site trust layer is live, because every new mention then points back to a site that can hold it.

  1. Open the affiliate program. Work the list:
    • Stand up tracking before recruiting anyone. Run the program on an affiliate platform (the Impact, PartnerStack, or Tapfiliate class) with 30-day cookies, sub-ID parameters, coupon codes, and custom landing pages.
    • Write the program spec. Target the niche band of 30% to 50% commission per completed order, the published category precedent. Publish the band only after a unit-economics check confirms fulfillment can carry it.
    • Recruit rental agencies first; the buyer's moment of need is the rental counter. Then driving schools, then insurers and travel-insurance checkouts.
    • Vet every partner before approval: real business, real traffic, and no claims on the partner's site that violate the exclusion list or the 1-year framing.
    • Review partner quality monthly through the sub-ID ledger. A partner program without sub-IDs cannot be audited per placement.
    • Add an agent or reseller tier only after the claims pass is documented. A reseller repeating an unsafe claim is your claim under the FTC frame.
    • Ship a claims-approved product paragraph in the partner kit. Partners use it verbatim or write inside the same rules.
    • Put the disclosure clause in partner terms from day one: partners must disclose the paid connection (16 CFR 255.5(b)). Disclosure language ships in the kit.
    • Mark every affiliate link rel="sponsored".
    • Never let partners buy placements for ranking credit. A partner's paid link is your liability.
    • Never buy links for ranking. Paid placements that pass ranking credit violate the link spam policy even when disclosed.
    • Never buy marketplace or directory listings as links. Never run press-release link campaigns. Never place guest posts to borrow host authority.
    • Paid search closes to unauthorized providers in this category on 2026-10-05 (Google Ads); Microsoft Advertising has required preapproval since 2026-08-19 and its rule is already in force. Affiliates, Meta paid social, and organic remain open.
    Spam policies: link spam “Google does understand that buying and selling links is a normal part of the economy of the web for advertising and sponsorship purposes. It's not a violation of our policies to have such links as long as they are qualified with a rel="nofollow" or rel="sponsored" attribute value to the <a> tag.”

    External sources: the 30% to 50% commission band and the partner profile were read from a rival's published affiliate terms (idaoffice.org). That read is market research, not a page-citation source. Google Government documents and services ads policy, effective 2026-10-05, per trade press, 2026-09-16. Microsoft Advertising Government Services Policy, effective 2026-08-19 (PPC News Feed, 2026-08-26); Microsoft Advertising preapproval page. FTC endorsement rule, 16 CFR 255.5(b); subsection mappings not re-verified.

    Acceptance check: the spec is written. Tracking works before the first recruitment email. Partner terms carry the disclosure clause.

    A sample crawl shows rel="sponsored" on every partner link. The sub-ID ledger shows traffic per partner from week 1.

    Finding cross-ref: Part 4.3.

  2. Reclaim the reclaimable links. Work the list:
    • Pull the dead-URL inventory from the Search Console Links report plus 1 commercial index. Sort candidates by the authority of the dead page, not by link count.
    • Live-test every candidate with a header request. Never trust a tool's "lost link" status alone.
    • 301 every dead URL that still holds external links to the live page that now carries the linked content. Bulk redirects to the homepage discard the topical signal that made the link worth having.
    • Cover the 2 dead media URLs that hold page authority 35 and 33.
    • Cover the capitalized /Italy/ and /Italy3/ paths; 3 dofollow links from Italian travel blogs point at them.
    • Cover the dead guide URL that holds 473 links (wikiprocedure.com).
    • Cut the remitly.com chain to 1 hop, https only.
    • Ship single-hop 301s. Verify every chain ends in 200.
    • Request re-crawl of each fixed URL in Search Console the same day. Re-check the full map at 30 and 90 days.
    • Watch the education-domain referring pages quarterly. A link inside a retired course page can vanish at any CMS cleanup.
    • Run unlinked-mention reclamation on coverage that names the brand without a link. Warm requests convert at 15% to 40%. Convert only high-authority, topically relevant mentions; leave low-value mentions alone.
    • Where a redirect cannot fix the source page, run reclamation outreach to the linking site.
    • Decide the fate of the 4 alias domains 301ing in and the eitalicense.com clone. Review them against the expired domain abuse policy. Keep only what passes. Where an alias is kept, redirect page to page onto topically matched live pages; never whole-domain into the homepage.
    Part 4.1 maps the full list. The redirect items are recoverability 1.0: no outreach, and no one can say no. PROBABLE The 15% to 40% warm-reclamation band is vendor-reported; treat it as a planning band, not a promise.
    Spam policies: expired domain abuse “Expired domain abuse is where an expired domain name is purchased and repurposed primarily to manipulate search rankings by hosting content that provides little to no value to users.”

    External sources: the reclamation method and the sort-by-dead-page-authority rule follow the standard lost-equity recovery practice for migrated sites. The 15% to 40% warm-reclamation band is vendor-reported (Reporter Outreach, May 2026).

    Acceptance check: every listed URL returns 1 hop, 301, to a live equivalent and ends in 200. None targets the homepage. The 30-day and 90-day re-checks are logged.

    Finding cross-ref: Part 4.1.

  3. Start the editorial layer. Work the list:
    • Open a news-and-guides section under named authors, with the sourcing rules and citation standard above.
    • Lead with original data: permit statistics, destination rule changes, fee updates.
    • Ship 1 maintained dataset per quarter, built on official sources. First candidate: a digital nomad visa desk covering 50+ national programs with requirements, validity windows, and official links, refreshed on every rule change. Time the pitch before the summer demand spike.
    • Structure every asset for extraction: answer-first opening, strict heading hierarchy, 1 quotable stat statement per section, a methodology block, and tables. PROBABLE A 2026 preprint found structure-only changes lifted citation rates 17.3% across 6 engines (GEO-SFE, arXiv 2603.29979, single study, not yet replicated).
    • Add 1 change-log entry per substantive update on each page.
    • Never restamp a date without a substantive change.
    • Build 2 target lists before pitching. The link list: tier-1 editorial. The citation list: the roughly 20 outlets AI engines actually cite for this category, reverse-engineered from the monthly re-sweep receipts. The 2 lists barely overlap; do not reuse one for the other.
    • Seed the citation list with the travel-media slots engines already read: wise.com, remitly.com, and thelocal.it class sources.
    • Pitch original data only. 88% of journalists delete off-beat pitches (Muck Rack, 2026). Cap each campaign at about 100 personalized sends. The yield sweet spot is 51 to 100 sends; campaigns of 1,001+ sends earned 70% fewer links (BuzzStream, 31-million-email analysis).
    • Skip wire press releases. PROBABLE Press releases appear in about 1% of AI citations (Muck Rack data, vendor-commissioned).
    • Open a YouTube education channel on the category leader's template. Ship short explainers: what the document is, where it is valid, what it does not do. Post transcripts. Description links carry no ranking equity; the channel is a citation and brand-defense surface.
    • Keep the entity facts identical everywhere: name, address, and product description on the site, Trustpilot, YouTube, and partner pages.
    • Stay out of Reddit while the 2022 scam thread stands. Participation now reads as astroturfing. Reddit's own systems stop about 25,000 net new spammy posts and comments a day (Reddit, 2026-07-06). Seeded campaigns are the category's named failure pattern (Kotaku on the Trap Plan case, 2025-11-10; FTC 16 CFR Part 465).
    • After the claims fix is verified and the thread's premise is weakened, start the real-person answering program. Use 1 named account with 30+ days of genuine participation before any brand mention. Put a disclosure line in every brand-adjacent answer. Post mentions, not links.
    • Never draft AI comments at volume. Never purchase aged accounts. Never let colleagues upvote.
    • Measure monthly: the money-query prompt set, plus the Bing Webmaster Tools AI Performance report for citation counts. PROBABLE The Bing report launched 2026-02 and its per-property counts are unstable month to month; read quarters, not months.
    • Run a quarterly audit: every numeric claim cited, every date backed by a logged change.
    No blog or editorial section exists today (Part 3.4). Fresh citable pages feed both brand defense and AI-engine answers. PROBABLE More than 50 countries ran digital nomad visa programs in 2026; counts vary by definition (Forbes, 2026-03-15).
    Risk: never restamp a date without a substantive change. Freshness signals are significance-based, so cosmetic date edits add risk, not benefit.
    Google API leak: lastSignificantUpdate “Last significant update of the document. This is sourced from the quality_timebased.LastSignificantUpdate proto as computed by the LSUSelector from various signals.” Corroborating context only.

    External sources: Muck Rack, 2026 State of Journalism (88% delete off-beat pitches; syndicated release, the globenewswire.com original was unreachable on 2026-09-22). BuzzStream spray-and-pray analysis, 2025 (51 to 100 sends as the yield sweet spot; 1,001+ sends earned 70% fewer links). Reboot Online JRPass FOI case study (travel-category data-PR precedent, 100+ links, vendor-reported). GEO-SFE, arXiv 2603.29979. Reddit, 2026-07-06.

    Acceptance check: the section is live with named authors. Both target lists exist before the first pitch. A quarterly audit finds every numeric claim cited and every date backed by a logged change.

    Finding cross-ref: Part 3.4.

Phase 4: Ongoing (measurement cadence)

Recovery is declared by data, not by effort. Part 7 holds the pre-registered KPI framework: 6 readiness gates, weekly checks, and the decision rules for lifting and pivot reads. Read Part 7 before Phase 2 ships; the expected-dip window starts the moment the kills land.

Spam policies: recovery guidance “Making changes may help a site improve if our automated systems learn over a period of months that the site complies with our spam policies.” Verbatim on the live primary page (Google Search Central, “Spam updates”, fetched 2026-09-19). The timeline runs through months, not days.
Sequencing principle: every step above is ordered so Google's first re-crawl lands on a site that answers who, where, and by what authority. Do not re-order the phases to front-load content work.

PART 7 Measurement and Monitoring

This part is the KPI framework. Every threshold below was fixed on 2026-09-17, before any recovery data existed. Nothing on this page needs outside tooling. A Search Console login, a GA4 login, a Trustpilot business login, and 4 browser tabs cover the whole cadence.

0 of 6readiness gates green on 2026-09-17
30.9/dayclicks, era mean 2026-08-21 to 2026-09-13, 11.4% of the ~270 plateau path
33.60probe-set weighted position vs 9.40 pre-break
4 of 4AI engines negative on 2026-09-05

7.0 Terms

7.1 The 6 readiness gates

These gates measure deploy state, not traffic. Each is a yes-or-no probe. All 6 were red on 2026-09-17, the pre-remediation state.

GateWhat it probesPass conditionState on 2026-09-17
1. AI-crawler accessWAF response to AI crawlersGET / as GPTBot, ClaudeBot, Bytespider, PerplexityBot, OAI-SearchBot returns 200 for all 5RED GPTBot, ClaudeBot, Bytespider return 403; PerplexityBot and a browser return 200; OAI-SearchBot was not in the 2026-09-17 probe set
2. llms.txtMachine-readable site index/llms.txt returns 200, plain text, links only surviving canonical URLsRED 404
3. Homepage schemaEntity markupOrganization node with legal name plus WebSite node, all JSON-LD parsesRED FAQPage only; Organization and WebSite absent
4. Markdown twinsMarkdown content negotiation/ and /faq/ return markdown with no doctype leak; /faq/ twin has exactly 1 level-1 headingRED doctype leak on both; /faq/ twin has 0 level-1 headings
5. Redirect mapThe 357-row map liveEvery kill URL returns 410; every fold URL returns 301 to its mapped targetRED 5 of 5 sampled kills return 200; 2 of 5 sampled folds return 200
6. Shared-chrome claimsClaim strings on /, /faq/, /italy/"175+" and "8 min" absent from all 3 bodiesRED both strings live
Source: live probes of https://e-ita.org on 2026-09-17, 1 request per second, 10 URL sample on gate 5.

7.2 Weekly checks, 30 minutes

Run these every Monday. GSC data inside the last 72 hours is partial; read through the latest complete day only.

7.3 Monthly checks

7.4 Scorecard

MetricCurrent on 2026-09-17Target and dateHow to measure
All-site clicks/day, 7-day rolling30.9270 sustained 7 days inside 2026-12-14 to 2026-12-27 (rewrites complete by early December); final read 2027-03-31GSC, Performance, Date view; sum of last 7 complete days divided by 7
All-site impressions/day, 7-day rolling409 (527 post-collapse era)Recover together with position; below 406 sustained 7 days outside the dip window is amberGSC, Performance, Date view
Probe-set weighted position33.60 (9.40 pre-break)5 positions better than the trailing 28-day mean, held 14 days, means suppression is liftingCurrent value: GSC query export over the collapse window 2026-08-21 to 2026-09-13 (24 days), weighted by impressions over the 257 probe queries. Ongoing: last 28 days.
Indexed pages429 of 438 archived; 432 of 438 on a single live re-read 2026-09-21 (not archived)Falls toward the surviving page set by 2026-11-15; "Crawled - currently not indexed" returns to 0GSC, Index, Pages
order_complete, daily (GA4)30.4/day post-collapse eraNonzero every day; "(not set)" share of orders below 40%GA4, Events, order_complete, daily
Trustpilot4.6 stars (2026-09-22 read), 11% 1-starHold 4.6 or better; 100% of negative reviews answered within 48 hoursTrustpilot business account
AI-engine verdicts4 of 4 negative (2026-09-05)First neutral or positive verdict, with a first-party page citedMonthly re-sweep, 7.3
Readiness gates0 of 6 green6 of 6 green by 2026-11-15Gate probes, 7.1
Source: Google Search Console via SEO Gets, 2025-05-02 to 2026-09-16; GA4 via SEO Gets; Trustpilot 4.6 stars and 1,563 reviews per the 2026-09-22 browser read (4.5 stars on the 2026-09-14 and 2026-09-21 reads); 11% 1-star per the 2026-09-05 baseline; engine sweep 2026-09-05; live gate probes 2026-09-17.

7.5 Decision rules

These rules decide what the numbers mean. They are fixed in advance so no one re-reads them after the fact.

7.6 Failure states

Risk: never report a number you did not verify. Data older than 3 days is stale: show the last verified value with its date, and skip threshold calls on it. GSC data fresher than 72 hours is partial: record it, never decide on it. A check that cannot run reports "unknown", never "green". A gate that passed and later fails is a regression alarm, not a fluke.
Cadence summary: 30 minutes each Monday for the weekly checks. First Monday of each month for the re-sweep and gate re-probe. One decision review at each dated threshold in 7.4. If every check passes on schedule, the next Google spam or core update does the re-scoring; the framework only watches.

B Appendix: Verdict and Redirect Tables

The two execution sheets behind Part 3 live as their own pages, in full. Table B.1 classifies every URL in the 454-URL audit inventory. Table B.2 is the redirect and removal map for the URLs that do not survive.

B.1 Page-class verdict sheet: 454 URLs

One row per URL. Verdicts: keep 73, rewrite 64, fold 155, kill 162. Score columns use the E-E-A-T rubric (0 to 10) described in Part 3. Blank cells mean the metric does not apply; the exceptions are six rows with no scores (six URLs added to the inventory outside the 2026-09-13 crawl; live-verified 2026-09-21) and five country rows with no cosine. Delta% is undefined at zero pre-break clicks. Cosine and boilerplate exist only for pages with a sibling comparison.

Open the full verdict sheet (also ships as the EITA Verdict Sheet v0.6 workbook).

B.2 Consolidation and redirect map: 357 rows

The plan redirects 177 rows (301) to the closest matching page and removes 180 rows (410) at deploy time. Planned action is the deploy plan, not the current state; the live column shows what each URL returned on 2026-09-21. This map covers all 317 fold and kill URLs from Table B.1 plus 40 URLs that have no verdict row. The 40 are 14 rental-brand guide redirects, 8 legacy aliases, and 18 retired translations pages. The 5 regional hub targets and the car-rental guide target are new pages. Build them before the 301 rows ship; they return 404 on 2026-09-21.

Open the full redirect map (also ships as the EITA redirects v0.6 CSV).