Skip to content

Website Launch Checklist: 40 Things to Check Before Go-Live

Website launch checklist with 40 checks for SEO, speed, accessibility, GDPR, forms and analytics, plus the 8 that cost the most to miss on launch day.

By

Freelance full-stack developer

Published
Reading time
9 min
In this post8

A website launch checklist should cover seven areas: SEO, performance, accessibility, forms and email, analytics, privacy and cookies, and hosting. Below are all 40 checks, and if you only have an hour, start with the eight in the first section. Launch-day mistakes are rarely hard to fix, but they get expensive when nobody notices them for weeks.

I build websites for businesses myself, so weigh my advice on hiring help with that in mind.

The short answer: 8 checks that cost the most to miss

Short on time? Prioritize what is hard to undo, or what nobody will notice:

  1. Every old URL 301-redirects to its closest new page.
  2. Staging noindex rules and password protection are gone.
  3. No analytics or marketing tags fire before consent.
  4. Every form has been tested with a real submission.
  5. Your domain has SPF and DKIM, so form emails actually arrive.
  6. Analytics records visits and conversions.
  7. HTTPS works everywhere, and the site resolves to one address.
  8. Backups run, and you have tested a restore.

If you're still deciding how to build the site, start with my guide to building it yourself, using no-code or hiring a developer.

SEO and content (10 checks)

These checks let search engines crawl and index the site from day one.

SEO and content

  • Titles and descriptions: every page has a unique title (about 60 characters max) and meta description.
  • Headings: exactly one H1 per page, with H2s and H3s in a logical order.
  • URLs and redirects: new URLs are short and final, and every old URL has a 301 (permanent) redirect to the best match.
  • Staging is cleaned up: noindex tags, passwords and staging domains are gone, and robots.txt doesn't block key pages, CSS or JavaScript.
  • Sitemap: an XML sitemap exists and is submitted in Google Search Console and Bing Webmaster Tools.
  • One preferred domain: canonical tags point to a single version of each page, with or without www.
  • Language versions: the lang attribute is set, and multilingual pages link their translations with hreflang.
  • Social previews and favicon: shared links look right on LinkedIn, in Slack and in browser tabs.
  • No leftovers: no lorem ipsum, stock placeholders, empty pages or broken links.
  • A useful 404 page: it helps visitors find their way instead of showing a bare error.

Without redirects, Google and other sites keep pointing at dead pages. See the full process in my guide to migrating a website without losing SEO.

Performance and accessibility (11 checks)

Test speed on a phone. Google's Core Web Vitals measure loading (LCP), responsiveness (INP) and layout shifts (CLS). According to web.dev's Core Web Vitals overview, "good" means 2.5 seconds, 200 milliseconds and 0.1, reached by at least 75% of page visits.

Performance

  • Images: resized to their display size, compressed as WebP or AVIF, and lazy-loaded below the fold.
  • Core Web Vitals: checked on mobile in PageSpeed Insights and green on your key pages.
  • Fonts: a small number of weights, loaded so text doesn't jump when the web font arrives.
  • Third-party scripts: chat widgets, embeds and pixels have each earned their place.
  • Caching and compression: enabled on the server or via a CDN (servers close to your visitors).

Accessibility means people with impaired vision, hearing or motor skills can use the site. For some businesses it is also a legal requirement: the European Accessibility Act has applied since June 2025 to services such as online shops, while service businesses with fewer than 10 employees and under €2 million in turnover are exempt. My overview of EAA requirements for websites explains who it covers.

Accessibility

  • Alt text: meaningful images have descriptive alt text, decorative ones an empty alt attribute.
  • Keyboard: the whole site works with Tab and Enter, and focus is always visible.
  • Contrast: body text has at least 4.5:1 contrast against its background (WCAG level AA).
  • Form fields: every field has a visible label, and error messages say what to fix.
  • Zoom and reflow: the site works at 200% zoom and on a narrow screen without sideways scrolling.
  • Captions: videos with speech have captions or a transcript.

Forms, email and analytics (8 checks)

A form that looks fine but never delivers is one of the most expensive bugs on this list, because nobody reports it. Prospects think you ignored them, and you think nobody wrote.

Forms and email

  • Real test: every form has been submitted on the live site, and the message reached the right inbox.
  • Confirmation: visitors see a clear thank-you message and know when to expect a reply.
  • Spam protection: a honeypot field, rate limiting or an invisible CAPTCHA is in place.
  • SPF and DKIM: your domain is authenticated so site emails don't land in spam. Add DMARC too.
  • Only what you need: the form asks only for information you will actually use.

Google's email sender guidelines require SPF or DKIM from every sender to Gmail, so skipping both puts your form notifications at risk.

Analytics

  • Tracking works: your analytics tool is installed, and you've seen your own test visit come in.
  • Conversions: form submissions and clicks on your phone number and email address are recorded.
  • Baseline: traffic and leads from the old site are noted, so you can compare.

Privacy, cookies and company details (5 checks)

Under EU rules, cookies for analytics, advertising or market research need consent, while strictly necessary ones (login, shopping cart) don't. The EU's Your Europe guide to online privacy adds that withdrawing consent must be as easy as giving it. These rules generally apply to EU visitors wherever your company is based, and the UK has its own rules. I'm a developer, not a lawyer, so treat this as a technical check.

Privacy, cookies and company details

  • Nothing loads before consent: analytics, ad pixels, YouTube embeds and Google Maps wait until the visitor says yes.
  • A real choice: the banner has a Reject button as visible as Accept, and visitors can change their mind from any page.
  • Privacy policy: states what you collect, why, for how long and which providers process it.
  • Data processing agreements: signed with your host, email provider, form tool and analytics provider.
  • Company details: legal name, address, email, company registration and VAT numbers are easy to find, usually in the footer. The EU's e-Commerce Directive requires this of most businesses.

Hosting and launch day (6 checks)

Hosting and launch day

  • HTTPS and one address: the certificate covers every page, and http, www and non-www all redirect to one version.
  • Backups: automatic, stored off the server, and a restore has been tested.
  • Uptime monitoring: you get an alert when the site goes down, before your customers notice.
  • Updated and locked down: CMS, plugins and packages are current, admins use two-factor login, and test users are deleted.
  • Real devices: tested on iPhone and Android, and in Safari, Chrome and Firefox.
  • A launch plan: the DNS switch happens on a weekday morning, with someone ready to fix issues for the first days.

A day before the switch, lower the TTL on your DNS records (how long other servers cache the old address) to a few minutes, so the change spreads fast and is easy to roll back. Avoid Friday afternoons, when a bug often stays unfixed until Monday.

On WordPress, plugin updates are ongoing work, not a launch task. My WordPress vs custom website comparison covers what that means.

Next steps: do it yourself or get help

Much of this list needs no code: titles, alt text, the privacy policy and form tests just take time. On Wix, Squarespace or Webflow, the platform also covers hosting, HTTPS, the sitemap and caching. My comparison of Wix, Squarespace, Webflow and hiring a developer shows where each one stops.

A developer earns their fee on the items that need access to code, servers and DNS: redirects during a migration, mobile performance, a consent banner that actually blocks scripts, and email authentication. Still unsure whether to build it yourself? Work through the 10 questions on DIY website vs hiring a developer.

If you want help, see how I work on custom websites for businesses, or send me the items you're unsure about.

Frequently asked questions

How far ahead of launch should I run this checklist?

At least a week before launch. Checking a small business site of 5-15 pages typically takes half a day to a full day. The fixes take longer: missing redirects, heavy images or a consent tool that needs replacing. A week lets you fix them without moving the date.

Do I need a cookie banner if my analytics is cookieless?

Not necessarily. Tools such as Plausible, Fathom and Simple Analytics can run without cookies, and then they generally don't need consent under EU cookie rules. Video embeds, maps and chat widgets can still set cookies, though. GDPR still applies, so list the tool in your privacy policy, and ask a lawyer if you're unsure.

What should I watch in the first weeks after launch?

Watch the page indexing report in Google Search Console for new 404 errors and redirect them as they appear. Compare form submissions and traffic with your baseline every week. Real-user Core Web Vitals data takes weeks to build up, so judge speed after about a month, not on launch-day lab scores.

Should a developer's quote include these checks?

Ask before you sign. A good quote says which of these items are included, because redirects, consent setup, analytics, email authentication and backups are often treated as extras. If the quote doesn't mention them, assume they're missing and ask for a price.