Is your website ready for launch day? A 20-minute pre-launch check
A 20-minute website launch checklist: indexing, link previews, signup and checkout, speed under load and HTTPS, in the order a failure would hurt.
LLaunchScaler·Published ·8 min read
A website is ready for launch day when search engines are allowed to index it, every shared link shows a proper preview, signup and checkout work end to end, pages stay fast when traffic arrives, and it serves HTTPS with its security headers set. Check those five things in that order, because the first failures are the quietest and the slowest to undo.
The checks below fit in about 20 minutes on a small site. Each one names the exact file, header or tool to look at and what a pass looks like. For the full sequence of launch week, the SaaS launch checklist covers the weeks before and after this check.
What should a website launch checklist cover?
A launch checklist covers what visitors and machines hit first: the directives that let search engines index the site, the tags that build link previews, the forms that turn a visit into a signup or a sale, the caching that keeps pages fast under a spike, and the headers that keep the site secure. Everything else can wait a week.
The order matters. A stray noindex costs nothing on the day and a lot later, because nobody notices until the site is missing from Google. A broken preview costs you every share. A broken checkout costs you the buyers who arrive. Slow pages and missing headers hurt less on day one, but they are cheap to fix now.
Minutes
Area
What you check
A pass looks like
0 to 5
Indexing
robots.txt, meta robots, X-Robots-Tag, sitemap
No Disallow or noindex on public pages; sitemap submitted
Questions, answered
What people ask about this
01
What should a website launch checklist include?
Five areas: search engines can index the site, every shared URL shows a title and image preview, signup and checkout work end to end, pages stay fast under load, and the site serves HTTPS with security headers. Check them in that order, because an indexing mistake is the hardest to notice and the slowest to recover from.
og:title, og:type, og:image, og:url on each shared URL
The preview tool shows your title and image
8 to 14
Signup and checkout
The full flow in a fresh private window
An account is created and a test payment succeeds
14 to 17
Speed under load
Cache headers on pages and assets
Static assets are cached; hot pages are served from the CDN
17 to 20
HTTPS and headers
Redirect, HSTS, CSP, nosniff
HTTP redirects to HTTPS; the headers are present
Can search engines index your site?
Search engines can index a page when robots.txt does not block it, the page carries no noindex in its meta tag or HTTP header, and it returns a 200. The usual launch-day failure is a staging setting that shipped: a Disallow: / in robots.txt or a site-wide noindex left on from before launch.
Run these in order:
Open https://yourdomain.com/robots.txt. A line reading Disallow: / under User-agent: * blocks the whole site. Remove it, or narrow it to paths like /api/ that should stay out.
View the source of your homepage and two key pages and search for name="robots". If you find content="noindex", remove it from the template that produced it.
Check the header version, which view-source cannot show: curl -sI https://yourdomain.com/ | grep -i x-robots-tag. Any output containing noindex means the server or a framework setting is adding it.
Confirm https://yourdomain.com/sitemap.xml loads and lists your real, canonical URLs. A single sitemap file is limited to 50,000 URLs or 50MB uncompressed.
Add Sitemap: https://yourdomain.com/sitemap.xml to robots.txt and submit the same URL in Search Console's Sitemaps report. Google says a sitemap is a hint, not a guarantee, but the report shows when Googlebot fetched it and any processing errors.
In Search Console, open URL Inspection on the homepage, click Test live URL, and confirm the result allows both crawling and indexing.
One trap catches careful people. To keep a page out of Google, the page must not be blocked in robots.txt, because Google's documentation says a crawler that cannot fetch the page never sees the noindex, and the URL can still appear in results when other pages link to it. Use noindex for pages you want hidden, and leave them crawlable.
Does every shared URL show a link preview?
A shared URL shows a preview when its page carries Open Graph tags that the platform can fetch. The Open Graph protocol names four required properties: og:title, og:type, og:image and og:url. On launch day your links go into Product Hunt comments, Slack, LinkedIn and X, so every URL you plan to share needs them.
Put them in the <head> of each page:
<meta property="og:title" content="Your product: what it does in one line" />
<meta property="og:type" content="website" />
<meta property="og:url" content="https://yourdomain.com/" />
<meta property="og:image" content="https://yourdomain.com/og/home.png" />
<meta property="og:description" content="One sentence a person would click." />
Size the image for the strictest platform. LinkedIn's help page asks for at least 1200 by 627 pixels, a 1.91:1 ratio and at most 5 MB, and says an image under 401 pixels wide displays as a small thumbnail. It also notes that when the image meets the requirements but still does not appear, your site may be blocking LinkedIn from fetching it.
Test the exact URLs you will share, including the pricing page and any launch-post URL, in LinkedIn's Post Inspector. Fix the tags before the first share, not after. If a preview shows the wrong image or none at all, the guide to OG images not showing walks through each cause, from relative image URLs to a firewall blocking the fetcher.
Do signup and checkout work end to end?
Signup and checkout work when a stranger can complete them in a fresh browser, on a phone, without help. Test the whole path, not the first screen, because the break usually sits two steps in: a confirmation email that never arrives, a form whose submit button does nothing, or a payment step that errors after the card is entered.
Walk it like a new visitor:
Open a private window, so no session, cookie or saved password helps you.
Click the main call to action on the homepage. It should navigate or open something. A button with no link and no handler looks finished and does nothing, and the dead CTA button test shows how to find every one.
Sign up with an email address you have never used on the site. Confirm the verification email arrives, the link in it works, and it lands you signed in.
Complete onboarding to the first screen that shows the product working.
Buy in test mode. In a Stripe sandbox, the card 4242 4242 4242 4242 with any future expiry date and any three-digit CVC completes a payment that moves no money. Check that the account unlocks what was bought.
Repeat steps 2 to 4 on a phone. If the layout overflows sideways or the text is tiny, check the page's <meta name="viewport"> tag; the viewport meta tag guide covers the correct value.
After the test run, switch to live keys and make one real purchase with your own card. Test mode proves the code; one live purchase proves the keys, the webhook and the receipt email.
Will the site stay fast when launch traffic arrives?
A site stays fast under a spike when most requests are answered by a CDN cache instead of your server. Static assets with hashed file names can be cached for a year, and public pages that are the same for every visitor can be cached at the edge for a short time. Pages rendered per request are the ones that slow down.
What to look for, using the directives MDN documents for Cache-Control:
Hashed assets (JavaScript, CSS, fonts, images with a content hash in the name) should send Cache-Control: public, max-age=31536000, immutable. immutable tells the browser the file will not change while it is fresh.
Public pages that are the same for everyone can send s-maxage, which applies to shared caches such as a CDN and overrides max-age there. Cache-Control: s-maxage=60 lets the edge serve a page for a minute before asking your server again.
Pages with a signed-in user or a cart should send private or no-store, so a CDN never serves one person's page to another.
Then check the numbers visitors feel. Google's Core Web Vitals thresholds for a good experience are a Largest Contentful Paint within 2.5 seconds, an Interaction to Next Paint under 200 milliseconds and a Cumulative Layout Shift under 0.1. Run PageSpeed Insights on the homepage and the pricing page. A new site usually has no field data yet, so the lab result is what you get before launch.
Is HTTPS set up with the right security headers?
HTTPS is set up when every http:// URL redirects to its https:// version on the same host, the certificate is valid for every hostname you use, and the response carries a Strict-Transport-Security header. A few more headers close the common gaps: Content-Security-Policy, X-Content-Type-Options: nosniff and a frame-ancestors rule against clickjacking.
The first command should show a 301 or 308 with a location: header pointing at the https URL. The second should list the headers. A typical HSTS value is Strict-Transport-Security: max-age=31536000; includeSubDomains. MDN notes that submitting to the preload list requires a max-age of at least 31536000 (one year) plus includeSubDomains, so only add preload once every subdomain serves HTTPS.
Treat CSP carefully on launch week. A strict policy added in a hurry can block your own scripts and break checkout, so start with Content-Security-Policy-Report-Only, watch the reports, then enforce it.
What goes wrong most often on launch day?
The expensive failures are the invisible ones: a noindex that stops Google, a preview that shows a blank card, a confirmation email that lands in spam. Visible bugs get reported by the first visitors within minutes. Nobody reports that your site is missing from search.
Plan around that. Fix the invisible problems before the launch, and keep an hour free on launch day for the visible ones. The list of product launch mistakes covers the timing and messaging errors that sit outside this technical check.
Run most of this check in one pass
LaunchScaler's free scan runs 156 checks across 6 of its 7 categories (search, AI visibility, security, compliance, speed and visual, and whether the site works), with no account. You give it a URL and nothing else. It covers most of this list: robots.txt rules that block a page, noindex in the meta tag or the X-Robots-Tag header, a missing sitemap or one that lists non-canonical URLs, a dead call to action, a form with no way to submit, a signup flow or checkout that breaks before completion, Core Web Vitals, text compression and static-asset caching, HSTS, CSP, the HTTP to HTTPS redirect and a non-standard viewport tag. It does not test link previews, so run the Post Inspector step yourself. Run the free scan the day before you launch, fix what it flags, and run it again on the morning of launch.
02
How do I check that my site is not blocking Google before launch?
Open yourdomain.com/robots.txt and look for a Disallow rule covering pages you want found, then check each key page for a noindex in the meta robots tag or the X-Robots-Tag header. In Search Console, URL Inspection's Test live URL reports whether crawling and indexing are allowed.
03
How do I test checkout before launch without paying?
Run the flow in your payment provider's test environment. In a Stripe sandbox, card 4242 4242 4242 4242 with any future expiry date and any three-digit CVC completes a payment that moves no money.
04
What image size do link previews need?
LinkedIn asks for at least 1200 by 627 pixels at a 1.91:1 ratio and at most 5 MB, and says images under 401 pixels wide show as a thumbnail. An image that size, set in og:image as an absolute https URL, works across the main platforms.
05
Should I submit a sitemap before launch?
Yes. Submit it in Search Console's Sitemaps report and add a Sitemap: line to robots.txt. Google calls a sitemap a hint rather than a guarantee, but the report shows when Googlebot fetched it and any errors it hit.
A listing that gets clicks has a one-liner for the job, a description of problem, method and audience, highlights with numbers, and a price stated plainly.
Launch traffic drops because every launch board resets daily. What keeps a product found after that: indexed pages elsewhere, reviews and your own content.
AI tool directories ranked by cost, review and link terms, each checked on its own site, and which ones curate submissions versus accept almost anything.