Solutions4sf Salesforce, built and repaired

Pardot audit · the checklist, not the sales call

Audit it yourself first.
Twenty seven checks, one afternoon.

A Pardot audit is six groups of checks: configuration, the Salesforce sync, scoring and grading, deliverability, database health, and the reporting that proves any of it. All twenty seven are below, each with what to look at and what a bad answer looks like. Run them yourself; you only need somebody else for what they find.

Vendor figures on this page were read from Salesforce and Google documentation on 18 and 24 September 2026, and each is dated where it appears.

How to use it

Score each check one to five, then fix nothing yet.

Go through the twenty seven in order and give each a number: one means broken, five means you could show it to somebody. Anything at three or below goes on a list. Only then decide what to do, because the order matters more than the count: a sync that drops prospects makes every other check meaningless, and a scoring model nobody trusts makes the reporting an argument rather than a fact.

The checks assume administrator access to Account Engagement and read access in Salesforce. None of them changes anything, so a self audit cannot break a setup that is working.

Group 01 · 5 checks

Configuration and foundation

Five checks. None of them is hard, and all five drift.

01

The edition you pay for, against the features you use

Read the order form, then list what your team touched in the last quarter. On the European price list read on 24 September 2026, Account Engagement is €1,250 a month for Growth+, €2,750 for Plus+, €4,400 for Advanced+ and €15,000 for Premium+, per org, billed annually. A tier bought for one feature nobody uses is the most expensive line in marketing.

02

Business units keep assets, users and prospects apart

If you run more than one unit, open each and confirm the user list, the asset folders and the prospect visibility are genuinely separate. Shared assets across units are how a German prospect receives the American nurture, and it is found by the recipient, not by a report.

03

Who is an administrator, and who has not logged in for ninety days

List every user with the administrator role and ask what each one needs it for. Then list anybody who has not logged in for ninety days. Both lists are usually longer than expected, and both are configuration drift waiting to happen.

04

Names follow a written convention

Open the email, list, form and automation rule libraries and sort by name. A convention exists when a stranger can tell what an asset does without opening it. Copies named final, new or v2 mean the convention is a habit rather than a rule.

05

Folders match how the team actually works

Two hundred assets in one folder is not a naming problem, it is a reuse problem: nobody finds what exists, so they build it again. Check whether the hierarchy matches campaigns, regions or product lines, and whether anybody outside the person who built it can navigate it.

Group 02 · 5 checks

The Salesforce sync

Five checks, and this is the group that loses leads in silence.

06

The connector is verified and on the current version

Account Engagement Settings, then Connectors. The connector should be verified and running the version Salesforce documents as current for your org. A broken connector does not shout; the first symptom is usually a quiet week in the pipeline.

07

Every mapped field has a direction and a source of truth

Go field by field and write down which side wins. A field that syncs both ways with no agreed owner produces overwrites that take an afternoon each to trace, and they look like somebody editing records at random.

08

The sync error queue is empty, and somebody owns it

The queue is the single cheapest check on this list. Every row in it is a prospect that is not in Salesforce, or is there with the wrong values. The twelve error types and what each one means are written up separately.

09

Connected Campaigns is on and used consistently

Without it, campaign influence reporting has nothing to attribute revenue to. Check that it is enabled, that campaigns are connected rather than duplicated on both sides, and that new campaigns are created in one place by habit.

10

Completion actions and assignment rules agree with each other

Follow one qualified prospect from form submission to the rep who owns it. If the completion action assigns one way and the Salesforce assignment rule another, the lead lands somewhere nobody watches. This is the check people skip because it takes ten minutes.

Group 03 · 4 checks

Scoring and grading

Four checks. Sales stops trusting the numbers here, not in the CRM.

11

Scoring rewards intent rather than volume

Pull the scoring rules and compare the weight of a pricing page visit against a blog read. If ten blog reads reach the qualified threshold, the model qualifies readers rather than buyers, and the sales team learns to ignore it within a quarter.

12

The grading profile matches the customers you want now

Grading is fit: industry, size, role. Open the profile and ask whether it describes the accounts you closed this year or the ones you hoped for two years ago. Fit that has aged is the second reason reps stop calling marketing qualified leads.

13

Score decay exists for prospects who went quiet

Without decay, somebody who was interested eighteen months ago still looks hot. Check for the automation that decrements the score after thirty, sixty or ninety days of silence, and check that it actually runs.

14

The qualified threshold is set from closed deals, not from a round number

Take the last six to twelve months of won deals and read the score and grade each one had when sales accepted it. That is your threshold. A hundred is a round number, not a finding.

Group 04 · 5 checks

Deliverability

Five checks, and three of them are now conditions of delivery, not advice.

15

SPF is published for every sending domain

Domain Management in Account Engagement shows the record your account needs and whether it is found. Do not copy a record from a blog: read the one your own account asks for, publish it, and confirm the status turns green.

16

DKIM signing is active, not merely configured

Every sending domain should show as verified, not pending. Signing proves the mail is yours; without it a receiving server has only your word for it, and Gmail and Outlook do not take your word.

17

DMARC is published, with a mailbox reading the reports

Google documents this as a requirement rather than advice. Senders of more than 5,000 messages a day to Gmail accounts must have SPF, DKIM and DMARC. The From domain has to align with one of them, one-click unsubscribe has to work, and spam complaints have to stay below 0.30 percent in Postmaster Tools. Read on 24 September 2026. Start at p=none with reporting on, read the reports for a month, then move to quarantine.

18

Links point at your own tracker domain

The default tracker domain puts a Salesforce hostname in every link you send. A custom tracker domain on your own name costs one DNS record and removes a reason for filters to treat your mail as somebody else's marketing.

19

Bounce, complaint and unsubscribe rates are read per list, not in aggregate

An aggregate rate hides the one list doing the damage. Pull the last six months by send and look for the spikes, then look at what those sends had in common: an imported list, an old segment, a reactivation campaign.

Group 05 · 4 checks

Database health

Four checks. This is where the data an agent would read is decided.

20

Mailable prospects against the total you pay for

Divide one by the other. A database where most prospects cannot be mailed is a database you are storing rather than using, and the cause is upstream: how the list was collected, and what happened to consent when it was.

21

Dynamic lists still describe something real

Open every dynamic list and read its criteria. Lists that filter on retired fields or on campaigns from two years ago keep recalculating daily and keep feeding programs that nobody reviewed. Retire them or fix the criteria; do not leave them running.

22

Visitor filtering is on

Without it, scanners and bots appear in your tracking as engaged visitors, and an engagement spike from a security scanner looks exactly like a buying signal until somebody checks.

23

Forms are protected, and the last thirty days prove it

Check that honeypot or reCAPTCHA protection is active, then read the last thirty days of submissions. Gibberish names and free mailboxes on a form meant for companies mean the protection is decorative, and every one of those rows is scoring, syncing and mailing.

Group 06 · 4 checks

Reporting and what it proves

Four checks. Without these the other twenty three cannot be sold internally.

24

One campaign influence model is chosen, and everybody reads it the same way

First touch, last touch, even distribution or a custom model: any of them can be defended, and mixing them cannot. Confirm which one is configured and whether marketing and sales describe it the same way in the same meeting.

25

A marketing influenced pipeline report exists and is actually opened

If nobody can produce that report in under a minute, it does not exist in practice. Build it, save it where both teams look, and put it on a recurring agenda rather than in a folder.

26

Engagement History is on the layouts sales use

The components that show opens, clicks and form submissions belong on the Lead, Contact and Opportunity pages. A rep who has to open another tab to see what a prospect did will not do it before the call.

27

You know which analytics you are entitled to

On the European price list read on 24 September 2026, B2B Marketing Analytics comes with five licences on Growth+, Plus+ and Advanced+, while B2B Marketing Analytics Plus is an add-on for Growth and Plus. Check what your order form includes before building dashboards somewhere else, and check whether the licences you own are assigned to anybody.

After the list

The audit tells you what is broken. It does not rebuild it.

Those are deliberately two different pieces of work. Diagnosis is cheap and you can do it yourself with this page. Rebuilding a scoring model against closed deals, repairing a sync that has been dropping rows for months, or re-sequencing programs that nobody has opened since last year is implementation, and it is priced in hours.

What the repairs cost here is published rather than quoted. A sync audit and repair with monitoring that reports to a person is from €2,000. A scoring and grading rebuild, back tested against your own closed deals, is €2,250. The read only data check on the Salesforce side is €500, delivered within three working days. Anything wider is hours at €50, and the arithmetic is on the pricing page.

Where each group is written out in full

Four of the twenty seven have their own page.

01

The sync error queue

Twelve error types, the message each one shows and what to do about it, including the batch behaviour that makes one bad row look like hundreds. Read the twelve sync errors.

02

Forms that accept a submission and lose the lead

Five ways a form handler reports success while nothing reaches Salesforce, and the audit that finds all five. Read the form handler failures.

03

Scoring and grading, rebuilt

What a model back tested against closed deals actually contains, and why the threshold is a finding rather than a round number. See the scoring rebuild.

04

Account based marketing inside Pardot

Six architectural patterns that break it, each with the check you can run today. Read the six ABM patterns.

Asked often enough to answer here

Questions

Q

What is a Pardot audit?

A structured read of the configuration against what it is supposed to produce: the connector and field mappings, scoring and grading, deliverability, list and database health, and the reporting that proves any of it. The twenty seven checks on this page are the whole of it. An audit diagnoses; it does not rebuild.

Q

Can I audit Pardot myself?

Yes, and this page is written so that you can. The checks need administrator access and a quiet afternoon, not a consultant. Somebody outside the setup finds more, because assumptions baked in at implementation are invisible to the people who baked them, but that is an argument for a second pair of eyes rather than for an engagement.

Q

How long does a Pardot audit take?

An afternoon on a single business unit with a few hundred prospects. A day, sometimes two, on a multi unit account with custom integrations, because the sync and reporting groups grow with every connected system. The scoring group takes longest, since it needs closed deals to check the threshold against.

Q

How much does a Pardot audit cost?

This checklist costs nothing and neither does running it yourself. If the list comes back with work on it, the published repair prices apply. A sync repair with monitoring is from €2,000. A scoring and grading rebuild against your closed deals is €2,250. The read only data check on the Salesforce side is €500. Anything wider is quoted in hours at €50 from what the checks find.

Q

Which of the checks fail most often?

In the setups I have worked on, the same few come back. Rows sit in the sync error queue with nobody assigned to them. Scoring counts activity rather than intent. DMARC is published but the reports are never read. Dynamic lists still run on criteria from a campaign that ended. And campaign influence is switched on without anybody agreeing what the model means.

Serhii Skrypnyk · Senior Salesforce Administrator and developer · 7 Salesforce certifications · on the platform since 2018. Reviewed 24 September 2026.