Website Launch Checklist 2026: What to Check Before, During and After You Go Live
Before a website goes live, check that it can be found and trusted: HTTPS on one domain version, no leftover noindex, a working robots.txt and XML sitemap, unique titles and descriptions, link previews, fast mobile pages, tested forms and emails, legal pages, and AI crawler access. On launch day, announce in two or three places that fit your audience, with copy written for each. In the first 30 days, set up Google Search Console and Bing Webmaster Tools, submit your sitemap, list in relevant directories and watch which pages get indexed.
- The most common launch killer is a staging noindex tag or a robots.txt Disallow that ships to production. Check those first.
- Pick one domain version (www or bare domain, always HTTPS) and permanently redirect everything else to it.
- Test the unglamorous parts yourself: the contact form, the signup email, the 404 page and the link preview on X and LinkedIn.
- Blocking GPTBot keeps you out of OpenAI's training data, not out of ChatGPT search. OAI-SearchBot controls that.
- Launch day is distribution, not a deploy: a few well-chosen places, copy written for each, and you in the comments all day.
- Google says crawling can take a few days to a few weeks, so plan directories, communities and backlinks for that gap.
#How to use this checklist
This checklist is for founders launching a product, SaaS or small business site, not for an agency QA team. It has three phases: before you go live, launch day, and the first 30 days.
Every item has a reason and a quick way to check it. Items in bold are the ones that silently stop a site from being found at all. If you only have an hour, do those.
#Phase 1: Before you go live
Deploy to production a few days before you tell anyone. Most of these checks only work on the real domain.
#Domain, HTTPS and redirects
| Item | Why it matters | How to check |
|---|---|---|
| HTTPS everywhere | Google prefers the HTTPS version of a page as canonical, and Stripe's website checklist asks that your site, especially the payment form, uses HTTPS. | Load http://yourdomain.com and confirm it lands on https://, for both www and the bare domain. |
| One canonical host | If www and the bare domain both serve pages, every URL exists twice and your signals split. | Try all four variants (http, https, with and without www). Three should permanently redirect to the fourth. |
| Redirects for old URLs | Google recommends server-side permanent redirects (301 or 308) and says they don't lose PageRank. | Spot-check URLs from the old sitemap. curl -I shows the status code. |
| A real 404 page | A "not found" page served with status 200 is a soft 404 to Google. | Visit a made-up URL. It should link to your main pages and return 404 in the network tab. |
| Favicon | Google shows it next to your result. It must be square and crawlable, and Google recommends larger than 48x48px. | Check the file in your homepage's rel="icon" tag loads and isn't blocked by robots.txt. |
#Titles, descriptions and link previews
| Item | Why it matters | How to check |
|---|---|---|
Unique <title> per page | Titles are the main source of your blue link. Google asks for distinct, descriptive, concise titles, not vague ones like "Home". | View source on your top pages. Each title should say what the page is, plus your brand. |
| Meta descriptions | Google sometimes uses them as the snippet, and identical descriptions on every page don't help. | Look for blanks or copies across your top five pages. |
| Open Graph tags | Most platforms build link previews from them. Without og:title, og:type, og:image and og:url, launch-day shares show a bare URL. | Paste your URL into a private message to yourself on two platforms. |
| X card tag | X needs twitter:card to pick a card type and falls back to Open Graph for the rest. | Paste the link into a draft post on X and check the preview. |
| An H1 that says what you do | People, search engines and AI assistants read your homepage heading first. "Welcome" wastes it. | Read it to someone who's never heard of you. Can they say what you sell? |
The minimum head for a homepage (use absolute URLs):
<title>Example: invoice reminders for freelancers</title>
<meta name="description" content="Example sends polite, automatic reminders when a client pays late, so you stop chasing invoices by hand.">
<link rel="canonical" href="https://example.com/">
<meta property="og:title" content="Example: invoice reminders for freelancers">
<meta property="og:type" content="website">
<meta property="og:url" content="https://example.com/">
<meta property="og:image" content="https://example.com/og.png">
<meta name="twitter:card" content="summary_large_image">#Crawling and indexing
| Item | Why it matters | How to check |
|---|---|---|
| No leftover noindex | Staging sites are often noindexed, and that setting is easy to ship to production by accident. | Search your page source for noindex and your response headers for X-Robots-Tag. |
| robots.txt allows crawling | A Disallow: / from staging blocks everything. And robots.txt doesn't hide pages: Google says a blocked URL can still be indexed if others link to it. | Open /robots.txt and confirm it blocks only what you mean to block. |
| XML sitemap | Helps Google find pages on a new site with few links. Google ignores priority and changefreq, and uses lastmod only if it's accurate. | Open /sitemap.xml. It should list only live, canonical URLs on your final domain. |
| Canonical tags | Tell Google which URL is the main one when content is reachable at several. | Each page's canonical should point to itself on the final HTTPS host, never to staging. |
| Internal links | Google finds pages mainly through links from pages it already crawled. | Click from your homepage to every page you want ranked. |
A sensible starting robots.txt for a product site:
User-agent: *
Disallow: /app/
Disallow: /api/
Sitemap: https://example.com/sitemap.xml#Structured data
Structured data (Google recommends JSON-LD) tells search engines what a page is. Correct markup makes you eligible for rich results; it doesn't guarantee them. Two types cover most launches:
WebSiteon the homepage, withnameandurl. Google calls it the most important signal for specifying the site name shown in results.Organizationon the homepage or about page, with name, URL and logo. Google says it helps disambiguate your organization, including which logo to show.
<script type="application/ld+json">
{"@context": "https://schema.org", "@type": "WebSite", "name": "Example", "url": "https://example.com/"}
</script>Add SoftwareApplication, Product or Article only on pages that really are those things, and validate with Google's Rich Results Test.
#Speed, Core Web Vitals and mobile
| Item | Why it matters | How to check |
|---|---|---|
| Core Web Vitals | Google's "good" thresholds: Largest Contentful Paint within 2.5 seconds, Interaction to Next Paint 200 milliseconds or less, Cumulative Layout Shift 0.1 or less. On new sites the usual culprit is an oversized hero image or a heavy script bundle. | Run PageSpeed Insights on mobile and fix the element it flags as the LCP element first. |
| Mobile parity | Google indexes and ranks the mobile version of your content. What's missing on mobile doesn't exist for search. | Open every key page on a real phone. Menus, forms and pricing should all work. |
#Analytics, forms and email
| Item | Why it matters | How to check |
|---|---|---|
| Analytics on production | Launch traffic you can't measure is a launch you can't learn from. Google Analytics is free. | Open the site in a private window and watch your visit appear in the realtime view. |
| Forms tested end to end | The contact form that emails an inbox nobody reads is a classic. | Submit every form on your phone with a real address and confirm it arrives. |
| Emails reach the inbox | Gmail requires every sender to set up SPF or DKIM, and bulk senders to set up SPF, DKIM and DMARC. Unauthenticated signup emails land in spam. | Sign up with a Gmail address and see where the welcome email lands. |
| Tagged launch links | Without UTM tags, launch traffic shows up as "direct" and you can't tell which post worked. | Add utm_source, utm_medium and utm_campaign, click one, and find it in analytics. |
#Legal and trust pages
| Item | Why it matters | How to check |
|---|---|---|
| Privacy policy | If you collect anything personal (emails, analytics identifiers, payments), say what, why and for how long. | Compare it with what the site actually collects, including embedded tools. |
| Cookie consent where required | In the UK, the ICO says non-essential cookies need consent before they're stored, including ones that are merely "helpful or convenient". Rules differ by country. | Load the site in a private window and see which cookies are set before you click anything. |
| Refund, cancellation, contact (if you sell) | Stripe's website checklist asks for clear fulfilment policies, such as refunds and cancellations, and real contact details. | From your pricing page, can a customer find how to cancel and reach a human in two clicks? |
This is a checklist, not legal advice. If you handle sensitive data, get your policies reviewed properly.
#AI crawler access and llms.txt
| Item | Why it matters | How to check |
|---|---|---|
| OAI-SearchBot allowed | OpenAI says sites that opt out of OAI-SearchBot won't be shown in ChatGPT search answers. GPTBot is the separate training crawler. | Read robots.txt for rules naming these bots, and for a blanket User-agent: * block. |
| Claude-SearchBot and PerplexityBot allowed | They crawl for search results in Claude and Perplexity, separately from training crawlers like ClaudeBot. | Check robots.txt, then your CDN: Cloudflare's managed robots.txt setting adds Disallow rules for known AI crawlers. |
| Google-Extended understood | Google says it doesn't affect inclusion or ranking in Google Search, and AI Overviews need no special files or markup. | Block it only if you don't want Gemini training on your content. |
| llms.txt (optional) | A proposed Markdown summary at /llms.txt that points AI agents to your key pages. Chrome's Lighthouse checks it, and marks the audit not applicable if the file is missing. | If you publish one, keep it short, accurate and linked to real pages. |
To stay in ChatGPT search while opting out of OpenAI's training:
User-agent: OAI-SearchBot
Allow: /
User-agent: GPTBot
Disallow: /The full breakdown of every AI crawler is in can AI crawlers read your website.
#Check most of Phase 1 in one pass
A free Verdy audit reads your homepage, crawls about a dozen of your pages, and checks titles, meta descriptions, headings, canonical tags, the sitemap, robots.txt, structured data, Open Graph and X cards, speed through PageSpeed Insights, AI crawler access and llms.txt, with a severity for every finding. It won't test your forms, email deliverability, legal pages or analytics, and it doesn't crawl thousands of pages, so those stay on your list. The quick tools need no signup.
#Phase 2: Launch day
Launch day is the day you tell people, not the day you deploy.
#What to prepare the week before
| Item | Why it matters | How to check |
|---|---|---|
| A one-line pitch and a short description | Every platform asks for both. Product Hunt's description allows 260 characters. | Show the line to someone outside your field. Can they repeat what it does? |
| Logo and screenshots | Product Hunt recommends a 240x240 thumbnail and 1270x760 gallery images, with at least two in the gallery. | Keep one folder: square logo, three to five screenshots, a short demo video. |
| A launch post on your own site | Every other post can link to it, and it can rank and be cited later. | Publish it before launch and check its link preview. |
| A way to try it without friction | Show HN asks that people can try your thing, ideally without signups, and calls signup pages off topic. | Open the product in a private window and count the steps to the first useful moment. |
| Answers to the obvious questions | Pricing, privacy and "how is this different from X" come up everywhere. | Draft them in a doc. Adapt each time; don't paste. |
#Where to announce
| Place | Best for | The rule to know |
|---|---|---|
| Product Hunt | Most software, AI and consumer products | Posts go live at 12:01 AM Pacific. Not every post is featured on the homepage; the rest stay in the All feed. |
| Show HN | Things people can try right now, especially technical ones | Blog posts, signup pages and newsletters are off topic, and asking friends to upvote is "not ok on HN". |
| Indie Hackers | Bootstrapped founders | A story with numbers and lessons travels further than a bare link. |
| Relevant subreddits | Products with a clear niche | Each has its own rules, and Reddit's spam policy asks people who mostly post links to their own business to watch the frequency. |
| Your own network | Everyone | Personal messages beat a broadcast. Say what you want: feedback, a share or an intro. |
| Launch boards and directories | Everyone, spread over weeks | See the Product Hunt alternatives and startup and SaaS directories guides. |
Don't do all of these on the same day. Pick one or two anchor launches and spread the rest over the following weeks, with copy written for each audience. Verdy's launch console ranks about 150 curated places by fit for your product and drafts the copy for each.
#On the day
- Answer every comment quickly for the first few hours on each platform.
- Watch your error logs and signup flow, not just the vote count. A broken signup costs more than a low rank.
- Write down every piece of feedback. Often the most useful output of a launch is a list of fixes.
- Don't ask for upvotes. Product Hunt's help center says "Please don't" and warns it can drop you in the ranks or off the homepage.
#Phase 3: The first 30 days
| Item | Why it matters | How to check |
|---|---|---|
| Google Search Console | Your first-party view of indexing, queries and clicks. A Domain property covers all subdomains and both protocols, verified by DNS. | Add and verify the property, then open the Page indexing report after a few days. |
| Sitemap submitted, key pages inspected | The sitemap tells Google about all your URLs. URL Inspection requests a crawl of single pages, with a quota; repeating a request doesn't speed it up. | Sitemaps report shows Success. Inspect the homepage and two or three key pages, once. |
| Bing Webmaster Tools and IndexNow | Bing can import verified sites and sitemaps from Search Console. IndexNow pings Bing, Naver, Seznam.cz, Yandex and Yep about changes; Google isn't listed. | Use the import option, confirm the sitemap appears, and switch on IndexNow if your host supports it. |
| Directory listings | Relevant directories send qualified visitors and early links, but queues vary. AlternativeTo says new apps usually wait at least a few months, or $5 buys priority review (as of September 2026). | Keep a sheet: where, when, and whether the listing went live with a working link. |
| First backlinks | Links from real sites help Google discover and trust you. | Work through how to get your first 10 backlinks. |
| Indexing monitored | Google says crawling can take a few days to a few weeks, and requesting a crawl doesn't guarantee inclusion. | Search site:yourdomain.com weekly and look for crawled-but-not-indexed pages in Search Console. |
| AI answers checked | Buyers ask ChatGPT and others for recommendations, and you want to know whether they find you. | Ask the questions your buyers would ask, or run the AI visibility verdict. |
| Real queries read | After a few weeks, Search Console shows the searches you appear for: your content roadmap. | Performance report: sort by impressions, look for queries with few clicks. |
If your pages still aren't in Google after a few weeks, work through why a new website isn't showing up on Google. For turning launch week into steady traffic, see how to get your first 100 website visitors.
#Common launch mistakes
- Shipping staging settings: a noindex tag,
Disallow: /, or staging URLs in canonicals and the sitemap. - Blocking the wrong AI bot. Blocking GPTBot is a training choice. Blocking OAI-SearchBot takes you out of ChatGPT search answers.
- A blank link preview because
og:imageis missing or relative. - Launching everywhere on one day with the same copy. You can't reply properly in five places at once, and a Hacker News post reads wrong on Product Hunt.
- Measuring votes instead of signups. Votes fade in a day; signups and conversations stay.
- Expecting Google traffic in week one. Google's starter guide says some changes take effect in hours and others take several months.
#FAQ
#What should I check before launching a website?
Check that search engines can crawl and index it (no noindex, a sensible robots.txt, an XML sitemap, correct canonicals) on HTTPS and one domain version. Give every page a unique title, make sure link previews work, test every form and email on a phone, and confirm analytics records your visit.
#How long does it take Google to index a new website?
Google says crawling can take anywhere from a few days to a few weeks, and that requesting a crawl doesn't guarantee inclusion. Submitting a sitemap and inspecting your homepage in Search Console helps Google discover the site, and links from other sites help it find you faster.
#Should I block AI crawlers on my new website?
Only block what you mean to. Training crawlers (GPTBot, ClaudeBot, Google-Extended) are separate from search crawlers (OAI-SearchBot, Claude-SearchBot, PerplexityBot). Blocking GPTBot doesn't remove you from ChatGPT search and Google-Extended doesn't affect Google Search, so you can opt out of training and still appear in AI answers.
#Do I need an llms.txt file?
No. It's an optional proposal, and Google says AI Overviews and AI Mode need no special files. It can help AI agents find your key pages, and Chrome's Lighthouse checks it when present, so if you publish one, keep it short and accurate.
#What legal pages does a new website need?
At minimum, a privacy policy if you collect any personal data, including analytics and email signups. If you sell, add terms, clear refund and cancellation policies and contact details, which Stripe's website checklist also asks for. Cookie consent rules depend on where your visitors are, so check the ones that apply to you.
#Should I launch on Product Hunt on day one?
Only if the product is usable without friction and you can spend the whole day in the comments. It's often better to launch quietly, fix what early users find, and go to Product Hunt a few weeks later with a sharper page. Product Hunt says you can resubmit after six months, but a rushed first launch is still a wasted shot.
#Final recommendation
Do the bold items first: HTTPS on one host, no noindex, a clean robots.txt, Open Graph tags, analytics, tested forms, OAI-SearchBot allowed, and Search Console with a sitemap. Those decide whether anyone can find you at all. Everything else improves how well you show up once they can.
Then treat launch as a month, not a day: one or two anchor launches, directories and communities spread over the following weeks, a few earned backlinks, and a weekly look at what Google has indexed.
Want most of the pre-launch technical checks done in one pass? Run a free Verdy audit on your homepage.
Run a free auditPrices, plans and platform rules change. Anything current in this guide was checked on September 28, 2026; confirm on the vendor's own site before you buy.