Enter your site. Get your runbook.
The 36-point ready check
Enter your site and the scan answers every one. Nothing to tick by hand.
The basics
-
HTTPS on
HTTPS keeps information private as it travels between your visitors and your site. It also helps prevent browser security warnings. Your hosting provider can usually turn it on and keep its security certificate renewed.
Checked automatically.
-
http:// redirects to https://
People may open an old link or type your address without https://. Your site should send them straight to the secure version, so they do not have to fix the address themselves.
Checked automatically.
-
www and non-www end at one address
Both example.com and www.example.com should take people to the same version of your site. That way, either address works and search engines have one main address to use.
Checked automatically.
-
No http:// images, scripts or styles on https pages
A secure page should load its pictures and other files over secure connections too. Otherwise, browsers may block those files and parts of the page can stop working. Update any file addresses that still start with http://.
Checked automatically.
-
Domain registration not about to expire
You pay to keep your website address for a set period. If that runs out, your website and email can stop working. We check the published expiry date; check your domain account to make sure renewal is arranged.
Checked automatically.
-
Favicon
This is the small icon beside your page title in a browser tab. It also appears in bookmarks, helping people spot your site among others. Use a simple version of your logo that is clear at a small size.
Checked automatically.
-
Viewport tag for phones
This page setting tells phones to fit your site to their screen. Without it, the page can look like a tiny desktop website. We check for the setting; still open the site on a phone to see how it looks.
Checked automatically.
-
Visitors can zoom in on phones
Some people need to enlarge a page to read it comfortably. Your phone layout should allow them to zoom in. We check that the page settings do not restrict zoom; also try it on a phone yourself.
Checked automatically.
-
Buttons and links have room for phone taps
Small, crowded buttons and links are easy to tap by mistake on a phone. Google checks their size and spacing on the homepage. Give controls enough room, then try the main actions on a real phone too.
Checked automatically.
-
Pictures are not stretched or squeezed
Pictures should keep their natural proportions instead of looking stretched or squeezed. Google compares displayed images with their original shape. If one is distorted, adjust how it is sized or crop it to fit.
Checked automatically.
-
No browser errors when the homepage opens
A page can show errors inside the browser even when it looks normal. These may point to a missing file or a feature that is not working. Google records errors while opening the homepage; review the report and try the affected features yourself.
Checked automatically.
-
No immediate location or notification requests
Asking for someone's location or permission to send notifications as soon as the page opens can feel intrusive. Wait until they choose a feature that needs it, and explain why. Google checks whether the homepage asks for either permission during loading.
Checked automatically.
-
Homepage opens without a long redirect chain
A redirect sends the browser from one address to another before the page opens. A few may be necessary, but a long chain adds waiting. We count the steps from your HTTPS address; use the final address in your own links.
Checked automatically.
-
Text encoding is declared
This setting tells browsers how to read the characters in your page. If it is missing or wrong, letters and symbols can appear garbled. We check that a setting exists; look through the page to make sure the text displays correctly.
Checked automatically.
-
Homepage HTML is reasonably small
This checks the size of the homepage's underlying page file, without its pictures or separate files. A very large page file takes more work to download and open. Remove unnecessary repeated content or large blocks of stored data if it is getting too big.
Checked automatically.
-
No automatic page refresh or timed redirect
Some pages are set to reload or send people elsewhere after a timer runs out. That can interrupt reading or erase what someone is typing. We check for that page setting; let visitors control refreshes and send old addresses directly to their replacement.
Checked automatically.
-
Real 404 page
When an address does not exist, your site should tell the browser it is a missing page. That signal is called 404, and it helps search engines avoid listing broken pages. We test the signal; check that the page also gives visitors a useful way back.
Checked automatically.
-
Privacy page linked from the homepage
A privacy page explains what information you collect about visitors and what you do with it. Make it easy to find from your homepage. We look for that link, but do not read the policy or check whether it meets your obligations.
Checked automatically.
-
Contact page or email linked from the homepage
Give visitors a clear way to ask questions or report a problem. We look for a contact page or email link on your homepage. Try sending a message yourself to make sure it reaches you.
Checked automatically.
-
Analytics installed
Analytics tells you how many people visit your site and which pages they use. It is optional, but can help you see what is useful and what gets overlooked. We look for a known analytics tool; open its reports to check that visits are actually being counted.
Checked automatically.
-
Terms page linked from the homepage
A terms page explains the rules for using your site, such as how accounts or purchases work. The wording should match what your service actually offers. We look for a link from the homepage, but do not review the rules themselves.
Checked automatically.
-
Home screen icon (apple-touch-icon)
This is the icon people see when they save your website to an iPhone or iPad home screen. Add a clear, square version of your logo so the shortcut is easy to recognize.
Checked automatically.
-
No broken links on the homepage (check the rest with the W3C Link Checker)
A broken link sends someone to a missing or failing page. We try up to ten links from your homepage to other pages on your site. Use the linked checker to look through more of your site.
Checked automatically.
-
Works on mobile (try it on your phone)
Open your site on a real phone and try reading, opening menus and using its main feature. Look for cut-off text, awkward scrolling or buttons that are hard to reach. A page can pass automatic checks and still be frustrating to use.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Try the main tasks in different browsers
Try your site's main tasks in more than one browser, including a phone browser. Menus, forms and payments can work in one browser and fail in another. Test with normal settings and without being signed in as the site owner.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Test every form end to end (contact, sign-up, checkout)
Try each contact, sign-up and checkout form as a visitor would. Enter correct details, then try missing or incorrect details. Make sure the form explains problems clearly and that successful submissions reach the right place.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Domain set to auto-renew
Automatic renewal helps you keep your website address without remembering to pay each time. Turn it on in the account where you bought the address. Check the payment method and email address too, so a failed payment does not go unnoticed.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Domain transfer lock on
A transfer lock helps prevent your website address from being moved to another provider without your permission. We look for its published status. If it is unavailable, check the lock setting in the account where you bought the address.
Checked automatically.
Search and sharing
-
Search engines allowed (no noindex)
Your page can contain an instruction asking search engines to leave it out of results. That is useful for a test site, but easy to forget at launch. We check the homepage for this instruction; private pages should still have their own access controls.
Checked automatically.
-
robots.txt lets Google in
The robots.txt file tells search engines which parts of your site they may read. A rule left over from testing can accidentally block Google from the whole site. We check for that block; this file does not keep private information safe.
Checked automatically.
-
sitemap.xml
A sitemap is a list of your pages for search engines. It helps them discover pages they might otherwise miss. Keep the list up to date, but remember that Google still chooses which pages to include in search results.
Checked automatically.
-
Title and meta description
The page title names the page in browser tabs and search results. The description gives a short summary that search engines may show underneath. Write both so someone can understand what the page offers before opening it.
Checked automatically.
-
Canonical link
The same page may be available at several addresses. A canonical link tells search engines which address you want them to use. We check that the homepage points to the right version, rather than an old or unrelated address.
Checked automatically.
-
Page language set (<html lang>)
This setting tells browsers which language your page uses. It also helps software that reads pages aloud pronounce the words correctly. Set it to the language your visitors actually read on the page.
Checked automatically.
-
One main heading (<h1>)
The main heading is the page's headline. It tells visitors what they have opened and helps people using reading tools find their way around. We look for one main heading; extra headings are something to review, not proof that Google will penalize the page.
Checked automatically.
-
Share image (og:image) and Open Graph tags (Open Graph guide)
When someone shares your link in a chat or social app, these settings supply its preview title, description and picture. A clear preview helps people understand the link before opening it. We check the settings and image; the linked guide explains how to set them up.
Checked automatically.
-
Buttons have readable names
Every button needs a name that explains what it does, such as Search or Send message. This includes buttons shown only as icons, because reading tools need a name to announce. Google checks the homepage for missing button names.
Checked automatically.
-
Form fields have labels
Each form field should clearly say what to enter, such as Name or Email address. The label should remain useful while someone types and work with tools that read the page aloud. Google checks the homepage for missing or unconnected labels.
Checked automatically.
-
Links have readable names
People need to know what a link opens before they follow it. A link made from an icon or picture still needs a name that reading tools can announce. Google checks the homepage for links missing those names.
Checked automatically.
-
Search engines can follow the page links
A link should contain a real page address that search engines can follow. Something that only runs code when clicked may work for a visitor but hide the destination from search engines. Google checks homepage links for this problem.
Checked automatically.
-
Embedded maps and videos have names
An embedded map, video or other page needs a name that describes what it contains. This helps people using tools that read pages aloud decide whether to enter it. Google checks for missing names, but cannot judge whether each name is helpful.
Checked automatically.
-
Videos include captions
Captions let people follow a video's speech and important sounds without hearing the audio. Google checks for caption files on videos it can inspect. It cannot check every video player or the accuracy of the captions, so play the videos and review them yourself.
Checked automatically.
-
Text has enough contrast against its background
Text should stand out clearly from the color behind it. Pale text on a pale background can be hard to read, even when it looks stylish. Google checks the combinations it can measure; review text over pictures yourself too.
Checked automatically.
-
Headings follow a logical order
Headings divide a page into sections and smaller subsections. A clear order helps people skim the page or navigate with tools that read it aloud. Google checks for skipped heading levels that could make that structure confusing.
Checked automatically.
-
Images reserve space while loading
The page should leave room for pictures before they finish loading. Otherwise, text and buttons can jump when a picture appears. Google looks for images missing size information that helps reserve that space.
Checked automatically.
-
Page has a main content landmark
Your page can mark which part contains its main content. Tools that read pages aloud use this marker to help people jump past repeated menus. Google checks whether the homepage has that main-content marker.
Checked automatically.
-
Alt text on images
Image descriptions let people understand important pictures when they cannot see them. Software can read these descriptions aloud. We check whether each image has a place for that text; you still need to make sure useful images are described and purely decorative ones are left empty.
Checked automatically.
-
X card tag (twitter:card)
This setting tells X how to display a preview when someone shares your link. Use it with a suitable title and picture so the post is easy to recognize. X may take a while to replace an older preview.
Checked automatically.
-
Structured data (JSON-LD), check it with the Rich Results Test
These extra page details tell search engines what they are looking at, such as a product, recipe or business. They can help search engines display useful information alongside a result. We check whether the details can be read; use the linked test to check that they describe your page correctly.
Checked automatically.
-
Homepage text readable without JavaScript
Some search and link-preview tools cannot run the code that builds an interactive page. Sending the main text with the page helps those tools read it. We count that initial text; this does not test whether every feature works with page scripts turned off.
Checked automatically.
-
Google shows your site when people search its address
We search Google for your website address and look through the first ten results. This shows whether someone searching the address can find you. A new site may take time to appear, and results can differ by location and over time.
Checked automatically.
-
Google does not flag it as dangerous (Safe Browsing)
Google may warn visitors when it believes a site is deceptive or contains harmful files. We check its published warning status. A clean result means no warning was reported, not that every part of the site has been checked for security problems.
Checked automatically.
-
Google Search Console verification found
Search Console is Google's tool for seeing how your site appears in search and finding problems. We look for a public sign that you have connected it to your site. Some setup methods leave no sign we can see, so check your account if this is missing.
Checked automatically.
-
Speed on phones (PageSpeed Insights performance score)
Google opens your homepage as if it were on a phone and scores how quickly it loads. A higher score is better. Open the report to see what is slowing things down; the result can change between tests.
Checked automatically.
-
Accessibility (PageSpeed Insights score)
This score covers some common problems that make a site harder for people with disabilities to use. Examples include text that is hard to read and buttons without names. A good score helps, but it cannot replace trying the site with a keyboard and tools that read pages aloud.
Checked automatically.
-
SEO basics (PageSpeed Insights score)
This score checks basic settings that help search engines read your page. Fixing problems can make the page easier to discover. The score does not tell you how high it will rank or whether people will find the content useful.
Checked automatically.
-
Best practices (PageSpeed Insights score)
Google checks for common page problems, including browser errors and unsafe connections. A lower score means there are issues to review in its report. This is a quick check, not a full review of your site's quality or security.
Checked automatically.
-
Google shows your site when people search its name
We search Google for the name in your website address, without endings such as .com. This shows whether people searching that name can find you in the first ten results. Common names and new sites may be harder to find.
Checked automatically.
-
Submit your sitemap in Search Console
Give Google your list of pages through Search Console's Sitemaps section. This helps Google find them and lets you see problems reading the list. Check back for errors; submitting it does not put every page into search immediately.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Request indexing for the homepage (URL Inspection)
Google's URL Inspection tool shows what it knows about a page. Use it to check your homepage and ask Google to revisit it after a fix. The request does not guarantee when the page will appear in search.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Add site to Bing Webmaster Tools (import from Search Console)
Bing Webmaster Tools shows how Bing finds your pages and reports problems. Add your site there if you want to monitor its appearance in Bing search. You can also try importing an existing Google Search Console setup.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Fast for real visitors (Core Web Vitals from Chrome users)
This uses information from real Chrome visitors over the past 28 days. It checks how quickly content appears, how soon the page responds and whether things move unexpectedly. Small or new sites may not have enough visitors for a result yet.
Checked automatically.
-
Google Business Profile (only if local business)
A Google Business Profile helps customers find an eligible business in Google Maps and local searches. It is useful for businesses that serve customers in person. Check Google's eligibility rules before creating one; many websites do not need it.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
Speed and security
-
Server starts answering in under 0.8 seconds
This measures how long your server waits before it starts sending the page, after the connection is ready. A long wait delays everything the visitor sees. It is one test from our server, so other visitors may experience a different wait.
Checked automatically.
-
Main content appears quickly on phones
This measures how long the largest visible picture or block of text takes to appear in Google's phone test. It is a useful sign of how long visitors wait for the main content. Aim for 2.5 seconds or less; real visitors may get different results.
Checked automatically.
-
Page stays steady while loading
This measures how much the page unexpectedly moves while it loads in Google's test. A shifting button can make someone tap the wrong thing. Lower is better; a score of 0.1 or less is the usual target.
Checked automatically.
-
Scripts do not keep the page unresponsive
A page can look loaded while its code is still too busy to respond. This measures those blocked moments during Google's test. Aim for 200 milliseconds or less, and use the report to find code that keeps the page busy.
Checked automatically.
-
Compression on (gzip or Brotli)
Your server can shrink page files before sending them, and the browser restores them automatically. The page looks the same but uses less data and can load faster. We check whether this is enabled for the homepage.
Checked automatically.
-
HSTS header (Strict-Transport-Security)
This setting tells browsers to keep using a secure connection on later visits. It helps stop people ending up on an insecure version of your site. Enable it once HTTPS works reliably, and check with your host before applying it to all subdomains.
Checked automatically.
-
Security headers (nosniff, CSP, frame protection, referrer policy)
These settings tell browsers how to handle your page more safely. They can limit which code runs and whether another site can place your page inside its own. We check for the settings, but they still need to be set up correctly for your site.
Checked automatically.
-
security.txt with a contact for security reports
This small public file tells people where to report a security problem with your site. It helps a useful report reach you quickly. Add a working contact address and keep it current.
Checked automatically.
-
CAA record naming your certificate issuer
This setting names the companies allowed to issue security certificates for your website address. It gives you more control over who can create one. Use the company your host actually relies on, or your next certificate renewal could fail.
Checked automatically.
-
HTTP/2 or HTTP/3
These are newer ways for browsers and servers to send website files. They can help a page load more efficiently, especially when it has many files. We check what your server supports or advertises; ask your host about enabling them if needed.
Checked automatically.
-
Server hides its software versions
Some servers announce the exact software versions they use with every page. Removing unnecessary details gives outsiders less information about your setup. It does not fix security holes, so keeping the software updated still matters more.
Checked automatically.
-
IPv6 DNS record published
IPv6 is a newer internet addressing system that gives visitors another way to reach your site. We check whether your domain lists an IPv6 address. We do not test that connection, so make sure it works before publishing the address.
Checked automatically.
-
SPF record (v=spf1 -all if the domain sends no email)
SPF tells other email services which servers are allowed to send mail using your domain. It helps them spot messages pretending to come from you. Use the settings from your email provider, or state that the domain sends no mail if that is true.
Checked automatically.
-
DMARC record (learn DMARC)
DMARC tells email services how to handle messages that claim to come from your domain but fail identity checks. This helps protect your name from fake email. Follow your email provider's setup advice so genuine messages are not blocked.
Checked automatically.
-
Mail works on your domain (MX records)
These settings tell other email services where to deliver messages addressed to your domain. We check that the delivery settings exist. Send a real test message too, because that is the only way to confirm your mailbox receives it.
Checked automatically.
Claim your name
-
One handle, the same everywhere if possible
Using the same account name across services makes your official profiles easier to find. Choose a recognizable name and link your accounts from your website. You only need profiles on services you plan to use.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
X
An X account gives you a place to post updates and answer questions. It is useful if the people you want to reach already use X. Add your website to the profile and keep the account name recognizable.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Reddit
Reddit has communities where people discuss shared interests and ask questions. An account can help you join those conversations and get useful feedback. Read each community's rules before sharing your own site.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
LinkedIn page
A LinkedIn page can help people understand the business behind your site. It may be useful if your customers use LinkedIn for work. Add a clear description and a link to your website.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
YouTube
A YouTube channel gives you a place for demonstrations and how-to videos. It is worth considering when showing your site in use is more helpful than describing it. You do not need a channel just to launch.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
GitHub
GitHub gives developers a place to share code, track problems and follow updates. A profile or project page can be useful if your audience is technical. Only publish code and files you intend everyone to see.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Bluesky
Bluesky is a place to share updates and talk with people interested in your site. Use a recognizable profile name and link to your website. It is optional, so focus on it only if your audience is there.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Instagram
Instagram can be useful when photos or short videos help explain your work. Use a recognizable account name and put your website in the profile. Create an account if you plan to keep it useful and current.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Facebook page
A Facebook page can help people who already look for businesses there find you. Add your website and accurate contact details. If you invite people to message the page, make sure someone checks those messages.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
TikTok
TikTok can help you show a product or explain an idea through short videos. Consider it if that suits your audience and the time you have to make videos. It is not needed for every website.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Threads
Threads gives you another place to share updates and join conversations. Make the profile clearly match your website so people know it is yours. Use it if it reaches people you want to talk to.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
Launch and submit
-
Product Hunt
Product Hunt is a place where people discover and discuss products. A listing can introduce your site to that audience. Prepare a short explanation and clear pictures, and check the submission rules and any costs before choosing a launch option.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Show HN on Hacker News
Show HN is a section of Hacker News where people share something they have built that others can try. Explain what it does and be ready to answer questions. Read the posting guidelines before submitting.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Relevant subreddits like r/SideProject (read each sub's rules)
A relevant Reddit community can help you reach people who care about the problem your site solves. Explain why the site is useful to that group. Check its rules first, since some communities do not allow promotion.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Indie Hackers
Indie Hackers is a community for people building businesses. You can discuss what you are making, share lessons and ask for feedback. Give people something useful to discuss rather than posting only a link.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
BetaList
BetaList is a place to introduce an early product to potential users. Consider it if you are looking for people to try your site. Check its submission rules, audience and any costs before applying.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Uneed
Uneed is a directory where people discover products and tools. A listing may help if its visitors are likely to use your site. Check the listing options and any fees before submitting.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Launching Next
Launching Next is a directory for startups. It is one possible place to introduce your project. Check whether the audience fits your site and whether your chosen submission option costs money.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Smol Launch
Smol Launch is a place to introduce a small project. Consider it as an extra way for people to discover your site. Check that submissions are open and review the listing terms before applying.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
DevHunt (dev tools only)
DevHunt is aimed at people looking for developer tools. It may be a good fit if your site helps people build software. Make it easy to understand and try the tool before sharing it.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Peerlist Launchpad
Peerlist Launchpad is a place for builders to share their projects. It can give people another route to discover yours. Check the launch rules and timing, and prepare a clear explanation of what the site does.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Tiny Startups
Tiny Startups is another place to introduce a small business or project. A listing is only useful if it reaches people likely to care about your site. Review the submission terms and any price before choosing it.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
TinyLaunch
TinyLaunch is a directory for introducing products. Treat a listing as an optional way to find users, rather than a launch requirement. Check the current terms and any fees before submitting.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
AlternativeTo
AlternativeTo helps people find software that can replace something they already use. A listing may fit if your product is an alternative to a known tool. Be clear about the features, price and differences.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
SaaSHub
SaaSHub helps people discover and compare software. A listing may help visitors understand where your product fits. Keep the description and pricing accurate, and check whether the listing option has a fee.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Crunchbase
Crunchbase provides profiles of companies. It can give people another way to look up your business. Many small websites do not need a profile; create one only if it is useful and you have accurate company details to share.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
After launch
-
Check Search Console indexing after a week
Check Search Console after launch to see which pages have appeared in Google. If a page is missing, read the reason before changing anything. Some pages should stay out of results, such as duplicates or pages you deliberately excluded.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Check analytics
Open your site as a visitor, then look for the visit in your analytics reports. Try important actions too, such as submitting a form. This confirms that the tool is recording useful information, rather than simply being installed.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Set up uptime monitoring (UptimeRobot or Uptime Kuma)
An uptime monitor regularly checks whether your website opens and tells you when it stops responding. This helps you find an outage before a visitor reports it. Send alerts somewhere you will notice and test that they arrive.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Set up backups
A backup is a separate copy of the files and information you need to rebuild your site. It can save your work after a mistake or server failure. Make backups regularly and keep a copy away from the server running the site.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Use the whole site with a keyboard
Try using the site without a mouse. Use Tab to move, Enter or Space to activate controls, and Escape to close popups. Make sure you can see where you are and can reach and leave every menu, form and popup.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Restore a backup and check that it works
A saved backup is only useful if it can bring your site back. Try restoring one somewhere separate from the live site. Open the restored pages and check the important information before relying on it in an emergency.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Test sign-up and password-reset emails, if used
If your site sends sign-up confirmations or password-reset emails, try them with a real account. Check that messages arrive, links work and expired links give a useful message. This does not apply if your site sends no such emails.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Check caching for public and private pages
Saving copies of public files can make repeat visits faster. But a shared saved copy must never show one visitor's private information to another. Test with different accounts and after signing out, and check that visitors receive updated files after a site change.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Respect reduced-motion preferences
Some people set their device to reduce animation because movement makes them uncomfortable. Your site should respect that choice. Turn the setting on and make sure the page is still understandable without unnecessary movement.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Get notified about application errors
Error monitoring tells you when part of your site fails, even if nobody reports it. Set up alerts and try a safe test error to see that they reach you. Keep passwords and other private information out of the reports.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Test site search, including no results, if used
If your site has a search box, try common words, a typo and a search with no matches. Useful results should be easy to find, and an empty result should suggest what to try next. Skip this if your site has no search feature.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Test leaving an account or subscription, if used
If people can create accounts or subscriptions, make sure they can find how to leave. Try signing out, cancelling a test subscription and following the account-deletion process where offered. Check that confirmations clearly explain what happens to access, payments and saved information.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.
-
Protect administrator accounts with two-step sign-in
Protect the accounts that control your website, email and domain with unique passwords and a second sign-in step. That makes a stolen password less useful to someone else. Save recovery codes somewhere secure in case you lose your phone.
If this box is blank, check it yourself. Tick it when you have done it, or if your site does not need it.