Website launch checklist: 15 checks before you publish
I have lost count of the times a client has written to me on a Sunday night, euphoric, telling me that "the website is live". And when I open it I find a form that does not send emails, a legal notice with another company"s name or a page that takes six seconds to load on mobile. Launching a website is not hitting a button: it is the moment when the most things can break at once, and almost always because of haste.
I am Elmar Mamedova, full stack developer in Málaga, and in this article I share the exact checklist I review before putting any project into production. It is 15 checks grouped into blocks: content, technical SEO, performance, legal and GDPR, analytics, security, forms and mobile. It is not theory: it is the list that lets me sleep soundly after a launch. I explain the reasoning behind each point so you can apply it too.
Why you need a checklist before publishing
Launch day is the worst time to improvise. You have spent weeks looking at the same design, you have reviewed the copy so many times that you no longer see the typos, and the pressure to "get it out now" makes you sign off on details that later cost money. A checklist turns an emotional task into a mechanical process: you tick off points and do not rely on your memory.
Launch errors are not cosmetic. A broken form is a lost sale you will never know existed. An incomplete legal notice is a potential fine. A slow website penalises your ranking from day one. And worst of all: many of these failures go unnoticed for weeks because nobody is looking at them. The checklist exists precisely to catch them before they reach your customers.
Golden rule
Do not launch on a Friday afternoon or a public holiday. If something breaks, you will want time and a clear head to fix it. I always reserve a launch for a weekday morning, with the rest of the day free to keep watch.
The complete checklist: the 15 points grouped into blocks
This is the list I apply in every project, ordered by thematic blocks. In the following sections I develop the reasoning behind the most critical ones, but I want you to have the whole thing on hand from now. Print it, copy it into your task manager or use it as a reference: the order matters less than not skipping any of them.
- 1Content — Copy review: read each page out loud looking for typos, unfinished sentences and filler text like "Lorem ipsum" that gets left behind.
- 2Content — Optimised images: check that no photo is oversized, that they all have alternative text and that there are no links to development images or watermarked stock images.
- 3Technical SEO — Metadata and Open Graph: each page must have its own title and meta description, and the Open Graph image must look good when shared on WhatsApp or social media.
- 4Technical SEO — Sitemap and robots.txt: generate the sitemap.xml, check that the robots.txt does not accidentally block the whole website and verify that both are accessible.
- 5Technical SEO — 301 redirects: if it is a redesign, map the old URLs to the new ones so you do not lose the ranking you have earned.
- 6Technical SEO — Indexing in Search Console: register the property, submit the sitemap and confirm that Google can crawl the key pages.
- 7Performance — Speed and Core Web Vitals: measure the real website, not the one on your laptop, and work above all on mobile loading on 4G.
- 8Mobile — Responsive: test on a physical phone, not just in the browser, checking menus, buttons and forms.
- 9Forms — Submission and notifications: fill in each form and confirm that the email arrives, that it does not land in spam and that the user sees a success message.
- 10Legal/GDPR — Legal notice and privacy policy: complete texts, with real data and adapted to the GDPR and the LSSI.
- 11Legal/GDPR — Cookie banner: it must block non-essential scripts until the user accepts, not just inform.
- 12Analytics — Measurement installed: verify that analytics records real visits and respects cookie consent.
- 13Security — HTTPS and backups: active SSL certificate, http-to-https redirect and a backup saved before publishing.
- 14Quality — Broken links, 404 page and favicon: no link should lead to an error, the 404 page should help visitors keep browsing and the favicon should appear in the tab.
- 15Accessibility — Contrast and navigation: sufficient colour contrast, labels on form fields and the ability to navigate with the keyboard.
Fifteen points may seem like a lot, but most are reviewed in minutes. What matters is that none of them depends on you "remembering" at the moment of launch. If you want to delegate this whole process, in my web development service every project goes through this same review before it is delivered.
Content and technical SEO block: copy, metadata and Open Graph
Start with the most human part: the copy. Read it out loud, page by page. It is astonishing how many typos and half-finished sentences survive ten silent reviews and fall at the first reading aloud. Also look for forgotten filler text, out-of-date prices and links that point to the development site instead of the final one.
Then comes the metadata. Each page needs its own title (the one that shows in the tab and on Google) and its meta description. If they all share the same one, you are telling Google you do not know what each page is about. And do not forget Open Graph: that image and text that appear when someone shares your link on WhatsApp or social media. Without it, your website is shared as a dull, untrustworthy link. If you want to go deeper into the ranking side, I cover it in depth in my local SEO guide and in the SEO service.
Sitemap, robots.txt and indexing
The sitemap.xml is the map you give Google of all your pages. The robots.txt tells it what it can and cannot crawl. The classic error when moving from development to production is leaving in place a robots.txt that blocks the whole website (perfect while you develop, catastrophic when you publish). Review both files, open them in the browser and confirm they exist and say what they should. Then register the website in Search Console, submit the sitemap and request indexing of the main pages. Without this step, you can take weeks to appear on Google.
A website that Google cannot crawl is a shop with the shutter down: no matter how beautiful it is inside, nobody is going to come in.
Performance and mobile block: speed, Core Web Vitals and responsive
Speed is no longer a luxury: it is a ranking factor and, above all, a conversion factor. Most of your visitors in Málaga will open your site from a phone, on mobile data and sometimes with poor coverage. If your website is slow to load, they leave before seeing anything. Always measure in real conditions, not on your laptop with fibre: use PageSpeed Insights to get a faithful picture of how it loads for a normal user.
The Core Web Vitals are the three metrics with which Google measures the real experience: how long the main content takes to appear, how long it takes to respond to your first interaction and how much the design "shifts" while it loads. Those three define whether a website feels fast or frustrating. You can see the detail of each metric in the official Web Vitals documentation, and I have written a complete guide on how to optimise them in Core Web Vitals and speed.
Responsive deserves its own check with a physical phone in hand, not just resizing the browser. There are things that only show up on the real device: a menu that does not open, a button too small for a finger, a form that runs off screen or text hidden behind the keyboard. Test it on at least one Android and one iPhone if you can.
Quick performance tip
80% of speed problems on small-business websites come from unoptimised images. Before hunting for complex culprits, compress the photos and serve modern formats: often it is the only optimisation you need.
Does your website not pass these checks?
I audit your website, tell you exactly what is failing and leave it ready for production. No jargon and with a clear plan.
See the web development serviceLegal and GDPR block: legal notice, cookies and privacy
This is the block that gets neglected most and the one that can prove most costly. In Spain, any professional website needs a legal notice and a privacy policy adapted to the GDPR and the LSSI. Copying another company"s will not do: it has to carry your real data, the purpose for which you process your users" information and the retention periods. Check that no data from the original template has been left behind.
The cookie banner is where most people get it wrong. The law does not ask you to "inform" about cookies, it asks you to block them until the user accepts. If your analytics or your advertising pixels start recording before consent, the banner is decorative and does not protect you. Check that, until you accept, the non-essential scripts do not load. And that there is an option to reject that is as clear as the one to accept.
- Legal notice with real identifying data and, if you sell online, terms of contract.
- Privacy policy that explains what data you collect, what for and for how long.
- Cookie banner that genuinely blocks non-essential scripts until consent.
- Consent checkboxes on each form, not ticked by default, with a link to the policy.
Analytics and security block: measurement, HTTPS and backups
If you do not measure, you are flying blind. Before launching, confirm that the analytics tool is installed and recording real visits. Do a test visit and check that it appears. But careful: the measurement has to respect cookie consent, so verify that it only activates when the user accepts. Analytics that skips the banner is a legal problem disguised as data.
On security, the non-negotiable minimum is HTTPS: active SSL certificate and automatic redirect from http to https, so nobody ends up on the insecure version. Browsers mark websites without a certificate as "not secure", and that scares off any customer. And before touching anything in production, make a complete backup: if something goes wrong during the launch, you will want to be able to roll back in a minute instead of rebuilding from scratch.
Quality and accessibility block: 404, links, favicon and contrast
The final details are what separate a professional website from one that "looks half done". Run a broken-link checker across the whole website: nothing is more frustrating than clicking and landing on an error. Customise the 404 page so that, when someone reaches an address that does not exist, they have a way back to your website instead of a dead end. And check the favicon, that little tab icon: its absence is small, but it shouts "unfinished".
Accessibility is not just about complying with regulations: it is about not leaving customers out. Check that the contrast between text and background is sufficient to be read in sunlight or with poor eyesight, that all form fields have their label and that you can navigate with the keyboard. They are quick checks that widen your audience and, along the way, Google likes them. You can see examples of websites cared for to this level in my projects.
Conclusion: launch with a clear head
Launching a website well is not about performing magic, but about not skipping steps. These 15 points cover the errors I have most often seen cost money, ranking and credibility to small businesses in Málaga. Most are reviewed in a morning, and the cost of not reviewing them is almost always far greater than that of doing so: a lost sale, a fine, a month without appearing on Google.
My advice: turn this checklist into your launch ritual. Tick off the points one by one, without trusting memory or haste. And if you prefer someone to take care of the whole process, from development to the last check before publishing, that is exactly what I do in every project.
Let"s talk about your next launch
Tell me about your project and I will help you take it into production without scares, with this same checklist applied from start to finish.
Book a callFrequently asked questions
It is 15 checks grouped into blocks: content, technical SEO, performance, mobile, forms, legal and GDPR, analytics, security, quality and accessibility. They cover the errors that prove most costly when publishing.
Let's bring this to your business
If you want to apply what you've read, tell me your case and I'll help you make it happen.
Related articles
Web Development in Málaga: the complete guide to building a website that sells in 2025
Everything you need to know to build a professional website in Málaga: technologies, pricing, performance, SEO and how to choose a developer. A practical guide for companies and freelancers.
Core Web Vitals and web speed: the practical guide for small businesses
What LCP, INP and CLS are, how to measure your website speed with PageSpeed Insights and which concrete changes improve conversion and SEO ranking.
The price of a website in Málaga: what it really costs
I explain, without beating around the bush, how much a website costs in Málaga: the factors that move the price, real ranges by type of website and what a good quote should include.