A website launch is not complete when the site looks finished. Use this recurring checklist to verify domain and DNS settings, secure hosting, backups, analytics, technical SEO, forms, mobile usability, and Core Web Vitals before launch and at regular intervals afterward.
Overview
A reliable launch process has two parts: a controlled pre-launch review and a repeatable post-launch monitoring routine. The first confirms that visitors can reach the correct site securely. The second helps you notice gradual problems, such as an expired certificate, a broken form, a slow template change, or a DNS record that no longer matches your email or hosting setup.
This website launch checklist is suitable for a small business site, a WordPress installation, or a site built with a website builder. The exact controls vary by platform, but the sequence remains useful:
- Confirm the domain, hosting environment, and DNS records.
- Test security, access controls, backups, and recovery procedures.
- Review search visibility, analytics, forms, and important user journeys.
- Measure performance on representative pages and devices.
- Record the baseline and schedule recurring checks.
Keeping a simple log is valuable. Record the date, page or service tested, result, and corrective action. This turns a one-time launch task into an operational habit.
What to track
Domain, DNS, and hosting
Start with the public address visitors are expected to use. Decide whether the canonical version uses the root domain, such as example.com, or a www hostname, then redirect the alternate version consistently. Confirm that the domain registration is active and that the authoritative nameservers point to the intended DNS provider.
Review the essential records rather than changing records speculatively. An A or AAAA record may direct a hostname to an IP address, while a CNAME commonly points one hostname to another. Check that the records for the website, subdomains, verification services, and email are still required and accurate. If your site and email use separate providers, take extra care not to replace mail-related records while connecting the website. The email DNS setup guide explains how MX, SPF, DKIM, and DMARC fit into a business domain configuration.
Check the hosting environment for the resources and access your site needs. For managed hosting, verify who handles platform updates, backups, and support. For a self-managed cloud server, document operating system updates, firewall rules, administrative accounts, and the process for restoring service.
HTTPS, accounts, and recovery
Open the main pages using HTTPS and confirm that HTTP requests redirect to the preferred secure URL. Look for mixed content, such as images, scripts, or stylesheets still loading over an insecure address. Test internal links, canonical tags, and any hard-coded assets after the redirect is enabled.
Review administrator accounts and remove unused users. Use distinct credentials for each person, limit privileges to what each role requires, and enable multi-factor authentication where the platform supports it. Store recovery details in an appropriate password manager or documented operational system rather than in a shared text file.
Backups should be more than a setting in a control panel. Confirm what is included, how long copies are retained, where they are stored, and whether a restoration has been tested. A small test restoration can reveal missing uploads, database errors, or permissions problems before an incident occurs.
SEO, analytics, and user journeys
Check that the preferred pages can be crawled and indexed as intended. Review the robots.txt file, XML sitemap, page titles, meta descriptions, heading structure, canonical URLs, and status codes. Remove temporary noindex directives and staging references before launch. If a previous site exists, map important old URLs to relevant new destinations instead of leaving valuable links to dead ends.
Install analytics and consent-related controls according to your chosen setup and applicable requirements. Test that meaningful events are recorded, including contact submissions, purchases, downloads, or appointment requests. Do not assume tracking works because the script appears in the page source; use a test visit and confirm the expected event or conversion is received.
Walk through the journeys that matter to the business. Submit every major form, check validation messages, verify notification delivery, test search, and confirm that confirmation pages do not expose private information. Use a real phone and a narrow viewport as well as a desktop browser. Pay attention to keyboard navigation, readable text, visible focus states, and buttons that are easy to use on touch screens.
Performance and Core Web Vitals
Measure the home page and a representative content page, not just the page that has received the most optimization. Include pages with large images, embedded media, forms, product listings, or third-party scripts. Compare mobile and desktop results using the same test approach so that changes are easier to interpret.
Track the main user-facing signals associated with loading, visual stability, and responsiveness. A useful website speed optimization checklist includes:
- Compressing and correctly sizing images before upload.
- Using modern image formats when the platform supports them.
- Removing unused plugins, scripts, fonts, and tracking tags.
- Reducing redirects and avoiding chains between URL versions.
- Checking server response time and caching configuration.
- Preventing banners, images, and embeds from shifting the layout as they load.
- Testing interactive elements after scripts finish loading.
For a deeper technical workflow, use the online developer tools guide and keep test inputs free of passwords, private tokens, and customer data.
Cadence and checkpoints
Use a cadence that matches the site’s risk and change rate. A brochure site with infrequent edits can use a monthly or quarterly review. A site with frequent releases, user accounts, or transactions may need checks after every deployment as well as a scheduled review.
Before launch
- Confirm the production domain and DNS records.
- Verify HTTPS, redirects, certificate behavior, and mixed-content results.
- Test forms, email notifications, payments, logins, and key integrations.
- Remove staging content, test accounts, debug settings, and temporary access.
- Record a performance baseline for important pages.
- Confirm backups and document the restoration process.
Within the first week
- Review analytics, search visibility, crawl errors, and server logs where available.
- Test the site from more than one network and device.
- Check that redirects from important old URLs work as expected.
- Review real form submissions and customer-facing confirmation messages.
Monthly or quarterly
- Check domain renewal details, DNS changes, certificates, backups, and administrator access.
- Update the CMS, themes, plugins, dependencies, and integrations through a controlled process.
- Repeat performance tests on the same representative URLs.
- Review broken links, indexing signals, conversions, and unusual traffic patterns.
- Test at least one backup restoration or rehearse the recovery procedure.
How to interpret changes
A changed result is a prompt to investigate, not automatically proof of a serious failure. First compare the new result with the same URL, device type, test location, and measurement method. One inconsistent speed test may reflect network conditions; a repeated decline after a release deserves closer attention.
Use timing to narrow the cause. If performance worsened immediately after a design change, inspect new images, fonts, scripts, and layout components. If only one route fails, compare its template and integrations with a healthy page. If all pages slow down, review hosting resource usage, caching, DNS resolution, and recent platform changes.
Separate availability from performance. A page that loads eventually may still create a poor experience, while a fast page with a broken form is a business failure. Prioritize issues that block access, expose data, prevent conversions, or affect many important pages. Then address recurring speed and usability problems using the smallest change that can be measured.
Keep a change log for deployments, DNS edits, plugin updates, tracking changes, and hosting migrations. Correlating a result with a recorded change is usually more useful than collecting increasingly complex measurements without context.
When to revisit
Revisit this checklist monthly or quarterly, and immediately after a domain transfer, hosting migration, redesign, CMS update, major plugin change, DNS edit, or security incident. Also repeat the relevant checks when a user reports a broken form, a search visibility drop, unexpected redirects, slow pages, or an email delivery problem.
Before each review, select the same small set of critical URLs and user journeys. Update the baseline when the site intentionally changes, but preserve the old result so you can distinguish an expected change from regression. If ownership changes, refresh the contact list, access inventory, recovery instructions, and renewal records.
For the next review, create a short action list:
- Choose three to five important pages and record their current performance.
- Test the primary domain, HTTPS redirect, DNS resolution, and one key subdomain.
- Submit a form and verify the complete notification and confirmation path.
- Check backups, administrator accounts, updates, and recovery documentation.
- Review indexing controls, analytics events, broken links, and recent search changes.
- Assign an owner and due date to every unresolved issue.
A launch checklist becomes most useful when it is treated as a living operating document. Keep it with the site’s deployment and recovery notes, review it on a predictable schedule, and adjust the checks whenever the website, hosting environment, or business-critical journeys change.