Know exactly what could
block your launch.
A practical, source-backed checklist for websites and web apps. Find the risky gaps, verify the fix, and ship with confidence.
- 36 production checks
- No account needed
- Progress saved locally
Browse your launch plan
Six focused passes take you from “it works locally” to ready for real traffic.
Launch essentials
The production basics that prevent broken launches.
- Domains
- HTTPS
- Core journey
Search & discovery
Make important pages understandable and discoverable.
- Metadata
- Indexing
- Sitemaps
Performance
Keep the first visit fast and the interface responsive.
- Core Web Vitals
- Media
- Caching
Accessibility
Make every critical path operable and understandable.
- Keyboard
- Forms
- Zoom
Security & privacy
Reduce common exposure before real traffic arrives.
- Headers
- Sessions
- Privacy
Monitoring & recovery
Know when production fails and how to recover safely.
- Analytics
- Alerts
- Recovery
One checklist. Every high-risk detail.
Begin with the essentials, or open all 36 checks for a complete production review.
Deployment checklist
0of 15 essential checks complete
Progress is saved on this device.
Launch essentials
The production basics that prevent broken launches.
0 of 0 complete
Set one canonical production URLChoose the single HTTPS URL that represents the live site.Launch blocker
How to verify
- Open the production domain and confirm it loads the intended release.
- Check that alternate hostnames and URL variants resolve to the preferred URL.
Confirm HTTP redirects to HTTPSProtect visitors and keep one secure version of every URL.Launch blocker
How to verify
- Visit the HTTP version of the domain in a private browser window.
- Confirm it reaches the matching HTTPS page in a single permanent redirect.
Verify production environment variablesMake sure required configuration exists outside local development.Launch blocker
How to verify
- Compare the production variable names with the application configuration contract.
- Restart or redeploy and confirm the app starts without missing-variable errors.
Test the primary user journey end to endComplete the action that gives the site its reason to exist.Launch blocker
How to verify
- Start from a new private session on the production domain.
- Complete the primary flow and confirm the expected success state and side effects.
Confirm DNS and the custom domainVerify the public domain points at the intended production service.Launch blocker
How to verify
- Resolve the apex and any required subdomains from outside your local network.
- Confirm old deployment targets are no longer receiving production traffic.
Remove debug output and placeholder contentKeep test data, verbose logs, and unfinished copy out of production.
How to verify
- Search the production build for TODO copy, sample records, and development-only banners.
- Review the browser console and server logs for unexpected debug output.
Add a useful 404 pageHelp people and crawlers recover when a URL does not exist.
How to verify
- Visit a random URL that cannot exist on the production domain.
- Confirm the response is a real 404 and the page offers a useful next step.
Search & discovery
Make important pages understandable and discoverable.
0 of 0 complete
Write unique titles and descriptionsGive every important page a clear search result and browser label.
How to verify
- Inspect the title and meta description on each indexable page template.
- Confirm they describe the page specifically instead of repeating site-wide copy.
Review robots and indexing directivesRemove accidental noindex rules and keep private routes out of search.Launch blocker
How to verify
- Inspect robots.txt and the robots meta tag on the production response.
- Confirm public pages are indexable and private or duplicate routes are intentionally excluded.
Generate and publish a sitemapList the canonical URLs you want search engines to discover.
How to verify
- Open the production sitemap and confirm it returns valid XML.
- Check that it contains absolute canonical URLs and excludes private or broken pages.
Verify canonical tags page by pagePrevent duplicate URL variants from competing in search.
How to verify
- Inspect the canonical link in the initial HTML of each indexable template.
- Confirm it is absolute, valid, and points to the preferred version of that page.
Check social sharing previewsControl how key pages appear when people share them.
How to verify
- Confirm the title, description, URL, and image metadata use absolute production values.
- Paste a key URL into the preview debugger for the platforms you support.
Validate relevant structured dataDescribe eligible content without marking up information users cannot see.
How to verify
- Run representative production pages through a structured-data validator.
- Fix syntax errors and confirm every marked-up value is visible on the page.
Performance
Keep the first visit fast and the interface responsive.
0 of 0 complete
Measure Core Web Vitals on productionTest loading, responsiveness, and visual stability on the real origin.
How to verify
- Run representative pages through PageSpeed Insights or Chrome DevTools.
- Record LCP, INP, and CLS; investigate any metric outside the good range.
Size and encode images for their displayAvoid shipping oversized pixels or causing layout shifts.
How to verify
- Confirm responsive images provide appropriate source sizes and modern formats.
- Set intrinsic width and height so the browser reserves space before each image loads.
Review the JavaScript shipped on first loadKeep nonessential scripts out of the critical interaction path.
How to verify
- Inspect the production network and coverage panels for unused or duplicated code.
- Defer third-party and route-specific scripts until they are actually needed.
Set a deliberate cache policyCache fingerprinted assets aggressively without serving stale HTML forever.
How to verify
- Inspect Cache-Control on HTML, static assets, API responses, and media.
- Confirm immutable fingerprinted files use long caching and update-sensitive responses do not.
Enable response compressionReduce transfer size for text assets such as HTML, CSS, JavaScript, and JSON.
How to verify
- Inspect production responses for Brotli or gzip content encoding.
- Confirm already-compressed media is not recompressed unnecessarily.
Prevent fonts from blocking or shifting contentMake text immediately readable and keep layout stable during font loading.
How to verify
- Load only the font files and weights used by the production interface.
- Use an appropriate font-display strategy and inspect for visible text reflow.
Accessibility
Make every critical path operable and understandable.
0 of 0 complete
Complete every critical flow with a keyboardEnsure controls work without a pointer and focus follows a useful order.Launch blocker
How to verify
- Use only Tab, Shift+Tab, Enter, Space, Escape, and arrow keys where expected.
- Confirm every action is reachable, operable, and encountered in a logical order.
Keep keyboard focus clearly visibleShow where interaction will happen without hiding focus behind sticky UI.
How to verify
- Tab through the complete page at desktop and mobile widths.
- Confirm the focus indicator is high contrast, unobscured, and never clipped.
Label forms and explain errorsGive every input a persistent name and every error a useful recovery path.Launch blocker
How to verify
- Confirm every field has a programmatic label and relevant instructions.
- Trigger each validation state and verify the message identifies the problem and next action.
Write useful alternatives for meaningful imagesDescribe information and leave purely decorative images silent.
How to verify
- Review every image, icon-only control, chart, and embedded visual.
- Provide equivalent text for meaning; use empty alt text for decoration.
Check text and interface contrastKeep content readable and controls distinguishable in every state.
How to verify
- Measure body text, muted text, focus indicators, controls, and status colors.
- Check default, hover, focus, active, disabled, error, and success states.
Test zoom, reflow, and target sizeKeep content usable when text grows or the viewport narrows.
How to verify
- Zoom to 200% and test at a 320 CSS-pixel viewport without losing core actions.
- Confirm standalone controls have adequate target size and do not overlap.
Security & privacy
Reduce common exposure before real traffic arrives.
0 of 0 complete
Remove insecure and mixed-content requestsLoad every production resource over HTTPS.Launch blocker
How to verify
- Inspect the browser security and network panels on representative pages.
- Replace or remove every HTTP script, image, font, frame, and API request.
Keep secrets out of client code and logsAssume every browser-delivered value and public build artifact can be read.Launch blocker
How to verify
- Search built assets, source maps, logs, and version history for credentials and private keys.
- Move privileged operations server-side and rotate anything that may have been exposed.
Set relevant browser security headersAdd defense in depth for content loading, framing, and transport.
How to verify
- Inspect production headers for CSP, HSTS, frame restrictions, and content-type protection.
- Start restrictive policies in report-only mode when rollout could break legitimate behavior.
Protect authentication and session cookiesLimit when sensitive cookies are sent and whether scripts can read them.Launch blocker
How to verify
- Inspect session cookies for Secure, HttpOnly, and an intentional SameSite value.
- Confirm domain, path, and expiration are no broader or longer than necessary.
Audit production dependenciesRemove known vulnerable packages and software you no longer need.
How to verify
- Run the ecosystem audit tool against the production lockfile and container image.
- Resolve high-impact findings or document a time-bound mitigation and owner.
Protect state-changing requestsValidate authorization and prevent forged cross-site actions.
How to verify
- Confirm every write operation checks authorization on the server.
- Use framework CSRF protections or appropriate tokens and SameSite cookie controls.
Monitoring & recovery
Know when production fails and how to recover safely.
0 of 0 complete
Capture production errors with release contextMake failures visible without exposing sensitive data.
How to verify
- Trigger a controlled test error and confirm it reaches the production error system.
- Verify reports include the release identifier and exclude tokens, credentials, and personal data.
Monitor the public service from outside itDetect availability failures before users have to report them.
How to verify
- Create an external check for the public URL and one meaningful dependency or health endpoint.
- Send a test alert and confirm it reaches a person who can act on it.
Review logs for actionability and sensitive dataRecord useful operational events without storing secrets or unnecessary personal data.
How to verify
- Trace one successful and one failed request through production logs.
- Confirm logs support diagnosis while masking sessions, tokens, passwords, and private payloads.
Test backup restorationA backup is only useful when you can restore it within the required time.
How to verify
- Restore a recent backup into an isolated environment using the documented process.
- Verify integrity, access controls, encryption, and the time required to recover.
Write and rehearse the rollback pathKnow who can stop a bad release and how to return to a known-good version.Launch blocker
How to verify
- Identify the last known-good release and the exact command or control that restores it.
- Assign an owner and test the rollback in a safe environment before launch.
No checks match
Clear the search or filters to return to the checklist.
Specific enough to verify. Short enough to use.
Every check names an observable outcome, a short verification path, and a primary source. No vague advice and no account wall between you and a safer launch.
36production checks
15launch essentials
0accounts required