Web

Website Launch Checklist: How to Build and Go Live From Scratch

Talha Aslan 18 min read 1 views

What is a website launch checklist and which steps does it cover?

A website launch checklist is an ordered list of tasks that takes a site from idea to live: goals and sitemap, domain, hosting, build, design and content, SSL, speed testing, SEO basics, analytics, privacy notices, business email, backups and launch day checks. Following it in order prevents gaps you cannot fix after go live.

We built this guide as a working checklist rather than an essay. Each step explains what to do, which decision affects the next one, and which tasks you should hand over to your hosting provider or a specialist. We also link to our deeper guides at every stage. That way this page works as a roadmap, while the detail lives in the dedicated article.

In short, the goal is simple. On launch day your site should be ready for visitors, for search engines and for your own measurement tools. Some gaps, especially missing tracking or broken redirects, cannot be fixed retroactively. Therefore we recommend working through the list in sequence.

Also, do not treat a website launch as a one-off project. After go live you still update content, apply security patches and review reports. That said, a solid start makes every later task easier. For example, a domain account set up correctly on day one, or a verified Search Console property, keeps saving you time years later.

How do you define goals and a page plan before building a website?

The first step on any website launch checklist is not technical. Start by writing the site's job in one sentence: collect quote requests, book appointments, sell products or build trust. That sentence shapes the number of pages, the platform you choose and the conversion you will track. For instance, an appointment-driven clinic site and a catalog site for a manufacturer need very different page plans.

  1. Write down the primary goal and one secondary goal.
  2. List your audience and the five questions they ask most often.
  3. Map every question to a page or a section.
  4. Decide on the main menu pages: home, services, about, contact and, if relevant, a blog.
  5. Give each page one call to action, and decide whether the form, the phone number or a chat button comes first.

Link the goal to a measurable action, such as monthly quote requests, bookings or sales. Our guide on how to set website conversion goals covers this in depth. On the other hand, jumping into design before the page plan is final causes the most expensive rework. In our web design projects, this is the delay we run into most often.

What should you check when choosing and registering a domain?

Your domain is the permanent address of your brand online, and changing it later costs you in SEO. So choose a name that is short, easy to say and hard to misspell. For the extension, think about your market. A .com is the usual choice for international reach, while a country code such as .co.uk signals a local focus. We cover the selection criteria in our guide on how to choose a domain name for your business.

  • Register the domain in the company's name and under a company account, not a designer's personal account.
  • Turn on two-factor authentication at the registrar.
  • Enable auto renewal and make sure the contact email is an inbox someone actually reads.
  • Keep the transfer lock on and remove it only during a planned transfer.

After registration, run a WHOIS lookup to confirm the details look right. We also suggest securing your brand's social media handles on the same day. As a result, your domain and your profiles stay consistent from the start.

How do you choose the right type of hosting?

Hosting is the server service where your files and database run. For a small business site, shared hosting is often enough. When traffic, plugin count or custom code grows, a VPS or managed cloud plan becomes relevant. However, do not decide on price alone. Server location, backup policy, support quality and up-to-date software versions such as PHP matter at least as much.

We compare plan types, criteria and common mistakes in our guide on how to choose web hosting. Here we only summarize what matters for the checklist:

  1. Ask in writing whether the provider takes automatic backups and how a restore works.
  2. Check whether free SSL with automatic renewal comes with the plan.
  3. Open the control panel and billing account in the company's name.
  4. Decide who manages the server: a managed service or your own team.

An honest note: if operating system updates, firewalls and security patches are not your field, do not buy an unmanaged VPS. Leaving that work to the provider through managed hosting saves time and lowers risk. Also, decide on hosting together with the domain. Switching providers halfway through the project means redoing DNS settings and email records.

CMS or custom build: which setup should you choose?

The right setup depends on how often the site changes and which custom features it needs. A content management system, or CMS, lets your team add pages and posts without technical skills. A custom build, on the other hand, carries only the features you need, so it can be lighter and easier to control. The trade-off is that every change requires a developer.

We weigh both options in our article on WordPress vs a custom website. Whichever path you take, run these checks during setup:

  • Install the site in a staging area first and keep it hidden from search engines.
  • Avoid a predictable admin username, and use a strong password plus two-factor authentication.
  • Delete plugins and themes you do not use; deactivating them is not enough.
  • Finalize the permalink structure before launch, because changing it later means redirect work.

If you use WordPress, the Search engine visibility box under Settings, then Reading, lets you discourage indexing while you build. However, forgetting to untick it on launch day is a classic mistake on new sites. For that reason, we repeat the reminder near the end of this list.

In what order should design and content come together?

The right order runs from content to design. First draft each page's headline, key message and call to action. Then the designer builds a layout around that content. If you do it the other way round, picking a template and squeezing content into it, either the copy falls short or the design breaks. Keeping this order also cuts down revision rounds.

  1. Prepare a content draft per page: headline, subheadings, copy and an image list.
  2. Hand your brand assets, meaning logo, colors and fonts, to the designer in one file.
  3. Approve the mobile layout first, since a large share of visitors arrive on phones.
  4. Resize and compress images for the web, and write meaningful alt text for each one.
  5. Test every form: does the notification reach the right person, and does the thank you page load?

Discussing content and design at the same table sets the balance between copy and visuals early on. Moreover, writing content early makes SEO titles and descriptions easier. At that point you already know which page answers which search.

How do you verify SSL and HTTPS before launch?

An SSL certificate encrypts traffic between the visitor and the server, and the browser shows that the connection is secure. Today HTTPS is a baseline requirement, not an option. Above all, it matters for any site with a form. We explain certificate types and how they work in what is an SSL certificate.

Your pre-launch SSL checklist:

  • Confirm the certificate covers both the bare domain and the www version.
  • Check that every HTTP request redirects permanently to HTTPS.
  • Pick either www or non-www as the main address and redirect the other one to it.
  • Make sure there is no mixed content, meaning images or scripts loaded over HTTP on an HTTPS page.
  • Ask your provider to confirm that automatic renewal is active.

You can see the expiry date and chain quickly with our SSL checker. So you can handle the basic check yourself without technical skills. Installation and renewal run automatically in most hosting panels. If something goes wrong, handing it to your provider is the fastest fix.

Which tools should you use for mobile and speed testing?

Mobile usability and speed affect both user experience and search visibility. Google's developer site web.dev defines good Core Web Vitals thresholds as follows. Largest Contentful Paint should be 2.5 seconds or less. Interaction to Next Paint should be 200 milliseconds or less, and Cumulative Layout Shift 0.1 or less, measured at the 75th percentile of page loads. Source: web.dev Web Vitals.

  1. First, open the pages on a real phone and check that menus, forms and buttons work with a thumb.
  2. Next, run an automated check with our mobile friendly test.
  3. Then use Lighthouse, built into Chrome DevTools, to review performance, accessibility and SEO scores.
  4. Test your heaviest page separately, usually the home page or a product listing.

Keep one limit in mind. A lab test before launch does not replace real user data. That is because field data only builds up once the site is live and gets enough visits. Therefore your pre-launch goal is not a perfect score. Instead, aim to remove obvious bottlenecks such as huge uncompressed images, unnecessary scripts and uncached pages.

Which SEO basics belong on a website launch checklist?

SEO basics mean introducing your site to search engines correctly. Google Search Central's getting started guide also highlights creating a sitemap, using Search Console and keeping important pages crawlable for a new site. Here is what to finish before launch:

  • Write a unique title and meta description for every page, so no two pages share a title.
  • Use a single H1 per page and order subheadings in a logical hierarchy.
  • Create an XML sitemap; if your CMS does not, our XML sitemap generator can help.
  • Check that robots.txt does not block important pages.

A simple robots.txt file looks like this:

User-agent: *
Disallow: /admin/
Sitemap: https://www.example.com/sitemap.xml

The file sits in the root directory, so its address is always your domain plus /robots.txt. Also note that robots.txt does not remove a page from the index. It manages crawling. For a page you want out of the index, you use a noindex tag instead.

How do you connect Google Search Console?

Search Console is a free tool that shows your visibility in Google, index status and errors. Connect it on launch day, because data only builds up after you add the property. You can choose a Domain property or a URL prefix property. Google's help page on adding a property states that a Domain property covers all subdomains and protocols, and that it requires DNS record verification.

  1. Choose a Domain property in Search Console and copy the TXT record it gives you.
  2. Add that TXT record in your domain's DNS management panel.
  3. Confirm the record has propagated with a DNS lookup, then start verification.
  4. Submit your sitemap address under Sitemaps.
  5. Grant suitable access to team members under Users, and keep ownership on a company account.

We walk through the reports step by step in what is Google Search Console and how to use it. Put simply, Search Console is the screen you will open most often during the first week after launch.

When should you set up analytics and conversion tracking?

Finish your tracking setup before launch. If visits, campaigns and form submissions go unrecorded from the moment the site opens, that data never comes back. So treat measurement as part of pre-launch preparation, not as a launch day task. If you use Google Analytics 4, create the property on a company account and set the data retention period from the start.

  • Add the analytics tag to every page and see your own visit in the realtime report.
  • Define the main conversion as an event: form submission, phone click, chat click or purchase.
  • If you use a thank you page, keep it out of search results.
  • If you plan to run ads, test the ad platform's conversion tag on the same day.
  • Plan to filter internal traffic, meaning your own team's visits.

On the other hand, if you run a cookie banner, test separately that your tags respect each visitor's consent choice. A tag that fires without consent creates both a legal and a data quality problem. Run this test twice in a private window: once without consent and once with it.

What should privacy notices and cookie consent cover?

Any site that collects personal data needs a clear privacy notice, and even a simple contact form collects names, phone numbers and emails. If you serve visitors in the EU or the UK, GDPR applies to that data. In addition, the ePrivacy rules generally require consent before you set non-essential cookies. Other markets have their own privacy laws, so check the rules for each country you target.

  1. Publish a privacy notice and link it clearly next to every form.
  2. Write a cookie policy that separates strictly necessary cookies from analytics and marketing cookies.
  3. Install a consent tool that asks visitors before non-essential cookies load.
  4. Where you need explicit consent, use a separate checkbox that is not pre-ticked.
  5. If you plan email marketing, review the opt-in rules separately.

This section is general information, not legal advice. The right wording depends on how your business processes data, so we recommend having a lawyer review the final texts. We cover the technical side in detail in how to build a GDPR compliant website.

How do you set up business email and DNS records?

An email address on your own domain, such as info@example.com, builds trust and keeps your brand consistent. However, messages only reach the inbox when the DNS records are right. Google's email sender guidelines ask everyone sending to Gmail accounts to set up SPF or DKIM. Senders of more than 5,000 messages a day need SPF, DKIM and DMARC together.

  • Set MX records to the values your email provider gives you.
  • Keep SPF in a single TXT record, since multiple SPF records cause failures.
  • Generate the DKIM key in your provider's panel and add it to DNS.
  • Start DMARC in monitoring mode.

A sample DMARC record looks like this; adapt the values to your own domain:

_dmarc.example.com.  TXT  "v=DMARC1; p=none; rua=mailto:dmarc@example.com"

MX, SPF and DKIM values are provider specific, so use exactly what your hosting or email provider gives you. We compare the options in our business email guide. Also, sending your site's form notifications through SMTP lowers the risk of them landing in spam.

Why should your backup plan be ready before launch?

Because the first content change, the first plugin update or the first accidental deletion can come at any moment. Without a backup, you therefore have no way back. Moreover, the host's automatic backup alone is not enough. If the backup sits on the same server, a server-side problem can take both down together.

  1. Back up files and the database separately; together they form one whole.
  2. Keep at least one copy off the server, with a different service.
  3. Set backup frequency according to how often your content changes.
  4. Run one restore test before launch, because an untested backup is not a backup.

We explain methods and retention rules in our website backup strategy guide. So here we only stress one point: write down who restores the site and how. In a crisis, that note saves hours.

Which website launch checklist tasks should you not do yourself?

You can do every step yourself. Still, on some steps the cost of a mistake is higher than the cost of handing it over. To be honest, if you lack experience, the following tasks belong with your provider or a specialist:

  • Server OS updates, firewall and SSH access: leave them with the provider through managed hosting.
  • DNS migration and nameserver changes: one wrong record can stop email and the website at the same time.
  • Payment integration on ecommerce sites: a developer should follow the payment provider's technical documentation.
  • The wording of privacy notices: this needs a lawyer's review.

On the other hand, writing content, choosing images, connecting Search Console and reading analytics reports are tasks you can take on easily. In fact, doing them yourself helps you know your site better. If you want end-to-end support, our web design service covers these steps from planning to launch.

In short, a clear division of work removes most of the risk. Also put in writing who can access which account, where passwords live and how access is handed over when the project ends. That way your site never ends up without an owner, even if an agency, developer or employee changes.

Website launch checklist summary: who owns each step?

The table below sums up the previous sections at a glance. The owner column shows a common split of work, and yours may differ. For example, you can print this website launch checklist table and use it in project meetings.

StepWhenOwnerHow to verify
Goals and page planStartBusiness owner and agencyApproved page list
Domain registrationStartBusiness ownerWHOIS lookup
Hosting choiceBefore setupBusiness owner and developerWritten backup and SSL policy
CMS or custom buildAlongside designDeveloperStaging site
SSL and HTTPS redirectBefore launchHosting providerSSL check
Speed and mobile testBefore launchDeveloperLighthouse report
Analytics and conversionsBefore launchMarketing teamRealtime report
Privacy and cookiesBefore launchLawyer and developerConsent tool test
Email DNS recordsBefore launchProvider and developerTest email
Search Console and sitemapLaunch daySEO ownerVerified property

For detailed test scenarios, such as browser, form and link tests, see our pre-launch QA checklist. We do not repeat those tests here.

What goes on your launch day checklist?

In other words, launch day is not the day for new work. It is the day you switch on what you prepared and verify it. So push big changes to the days before. Launching early in the week and during business hours means your team and your provider are reachable if something breaks.

  1. Take a full backup right before launch.
  2. Point DNS to the new server, and keep both old and new servers running while the change propagates.
  3. Remove search engine blocks: check the CMS visibility setting, staging noindex tags and password protection.
  4. Retest the HTTPS redirect and the redirect to your preferred main address.
  5. Submit every form for real and confirm the notification arrives.
  6. Verify a realtime visit and a conversion event in analytics.
  7. Submit the sitemap in Search Console and inspect the home page URL.
  8. If an old site existed, confirm old URLs redirect permanently to the new ones.

If you are redesigning or migrating, redirect planning is a separate job. In that case, map every old URL to its new address in a sheet before launch.

What should you check in the first week after launch?

The first week is for catching what slipped through on launch day. That said, during this period you do not interpret long-term metrics. You only confirm the system works. We explain which metrics to watch and how often in website metrics to track after launch, so here we list only the technical checks.

  • Confirm in Search Console that the sitemap has been read without crawl errors.
  • Look for unexpected blocks in the page indexing report.
  • Check that form notifications arrive every day.
  • Spot check random pages for working certificates and redirects.
  • Confirm in the panel that the first automatic backup actually ran.
  • Make sure your test emails do not land in spam.

A new site takes time to earn a place in search results. Therefore watching technical health in week one is more useful than waiting for rankings. Logging these checks in a shared sheet also makes ownership clear. In practice, the real close of the project is the end of this first week, not launch day itself.

Sample timeline: how does the project run from scratch to launch?

The plan below is a sample timeline for a five to ten page business site. It is a starting plan based on field experience, not a guarantee. In practice, content readiness, approval speed and custom features change the timeline directly.

  1. First week: goals, audience and page plan, plus domain and hosting decisions.
  2. Second week: content drafts, brand assets and staging setup.
  3. Then, in week three: design, with the mobile layout first and desktop after it.
  4. After that, week four covers content entry, image optimization, forms and email DNS records.
  5. Next, week five brings SEO basics, tracking setup, privacy notices and testing.
  6. Finally, week six is launch day plus the first week checks.

In this sample timeline, content is the link that slips most often. When copy and images arrive late, the design and testing weeks get squeezed. That is why we suggest naming a content owner on day one. Keeping your website launch checklist in a shared document also shows everyone who is waiting on what.

Which decisions drive the budget and cost?

We do not quote prices in this guide, because cost does not depend on a single variable. Page count, the share of custom design, multiple languages, special features such as ecommerce or booking, who writes the content and the maintenance you expect all shape the total. Also, budget for yearly renewals such as the domain, hosting and email.

Answer these questions while planning your budget:

  • How many pages will the site have, and in how many languages?
  • Will you write the content yourself, or is copy and image production part of the service?
  • Who will handle maintenance, updates and backup monitoring after launch?

Our article on business website cost and pricing factors explains each cost driver and gives you a common language for comparing quotes. For example, one quote may include hosting, SSL and tracking setup while another covers design only. That gap does not show in the total at first glance. Consequently, you can use this website launch checklist as a quote comparison template: next to each row, note whether the quote covers that step.

Frequently Asked Questions

How long does it take to build and launch a website?
It depends on scope. Our sample timeline for a five to ten page business site runs about six weeks, but that is a starting plan based on field experience, not a guarantee. Content readiness, approval speed and custom features such as ecommerce or booking can stretch or shorten the schedule considerably.
Do I need coding skills to launch a website?
No, not for a basic site. With a ready-made CMS you can add content, connect Search Console and read analytics reports yourself. However, server security, DNS migration, payment integration and the wording of privacy notices are better left to your provider, a developer or a lawyer if you lack experience.
Should I buy my domain and hosting from the same company?
You do not have to, and keeping them separate is perfectly fine. One company makes management simpler, while separate accounts let you move hosting without touching the domain. Either way, open both accounts in the company's name, turn on two-factor authentication and keep auto renewal active.
When will a new website show up on Google?
There is no fixed timeframe, since Google crawls and indexes on its own schedule. To help, connect Search Console on launch day, submit your sitemap and request inspection for the home page. Also confirm that robots.txt or a leftover noindex tag is not blocking your important pages.
What is the most commonly forgotten launch step?
Leaving a search engine block in place is one of the most common mistakes. If the staging visibility setting, a noindex tag or password protection stays on, the site cannot enter search results. Postponing analytics setup is another frequent gap, because the first days of visit and conversion data never come back.
Does my website need a privacy policy?
Yes, in most cases, because any site that collects personal data needs one, and even a contact form does. In the EU and UK, GDPR applies, and non-essential cookies generally require consent. This answer is general information, not legal advice, so have a lawyer review your final texts.
  • website launch checklist
  • how to launch a website
  • new website setup
  • domain and hosting
  • SEO basics
  • Search Console
  • web design
Share:
Talha Aslan

Google Partner digital marketing expert. Hands-on with SEO, Google Ads, web design and e-commerce projects since 2012; every post here comes from that experience.

Next project

Let's talk about your project.

Your brief goes straight to Talha Aslan and team: strategy led by Talha, delivery by an experienced team. The first consultation is free; we listen and come back with a clear roadmap.