MOSH

All notes / 7 min read

The website launch checklist.

Everything worth checking before a new website goes live, grouped so you can work through it in an afternoon.

Published · By MOSH

A long concrete corridor with a thin line of fluoro-yellow light along the floor, leading to a bright opening.

Content

  • Every page has a clear purpose and one obvious next step.
  • Spelling, phone numbers, email addresses and prices are checked by someone who didn’t write them.
  • No placeholder text or images are left (search the site for “lorem” and “TBC”).
  • Contact details are consistent everywhere they appear.
  • Legal pages are in place: a privacy notice, cookies and terms where relevant.

Search foundations

  • Each page has a unique, descriptive title (about 50–60 characters) and meta description (about 120–160).
  • One h1 per page, with headings in a logical order.
  • An XML sitemap exists, and robots.txt points to it and doesn’t block anything important.
  • Canonical URLs are set, and old URLs redirect permanently (301) to their new homes.
  • Structured data describes your organisation and key pages, and passes Google’s Rich Results Test.
  • Share images and Open Graph tags are set, so links look good on LinkedIn and in messages.

Speed

  • Images are compressed (WebP or AVIF), correctly sized and lazy-loaded below the fold.
  • Fonts are limited to what you use, and load without hiding text.
  • Third-party scripts are kept to a minimum; each one costs speed and privacy.
  • Pages pass Core Web Vitals in PageSpeed Insights on mobile, not just desktop.

Security

  • HTTPS everywhere, with HTTP redirecting to HTTPS and HSTS enabled.
  • Security headers are set, including a Content Security Policy.
  • Admin accounts use strong, unique passwords and multi-factor authentication.
  • Forms are protected from spam (for example with Cloudflare Turnstile) and validate input on the server.
  • A security.txt file tells researchers how to report problems.

Accessibility checks

  • Everything works with a keyboard alone, with a visible focus outline.
  • Text has enough contrast, and doesn’t rely on colour alone to carry meaning.
  • Images have useful alt text (or empty alt text if purely decorative).
  • Form fields have labels, and errors are clearly explained.
  • Pages respect “reduce motion” settings, and work when zoomed to 200%.

Forms, email and analytics

  • Every form is tested end to end, and messages arrive where they should.
  • Emails sent by the website (such as form notifications) are tested, and arrive reliably rather than in spam.
  • Analytics, if you use them, are privacy-friendly and covered by your cookie notice.

After launch

  • Submit your sitemap to Google Search Console and Bing Webmaster Tools.
  • Check for broken links and 404 errors in the first week.
  • Set up uptime monitoring and make sure backups can actually be restored.
  • Ask the people you work with to link to you: it’s the quickest way for search engines to find a new site.

Want someone to run through this for you? We do pre-launch reviews as part of our website and technical advice work.

More notes

Keep reading.

Want a hand with this?

Tell us what you’re working on. You’ll get a proper reply, usually with a few questions.

Keyboard