Testing · Checklist

The pre-launch website QA checklist: 42 checks before you go live

Breakop Guides · 12 min read

Most launch-day problems aren't exotic. A contact form that sends but never arrives. A checkout that breaks when a promo field is empty. A page that looks fine on the designer's laptop and falls apart on a five-year-old Android phone. None of these are hard to find — they're just easy to skip when everyone is rushing to go live.

This checklist is the pass we'd run on any website before customers see it. It's split into seven areas. You don't need special tools for most of it: a laptop, two phones, and an afternoon.

Before you start

  • Test on the real thing. Staging is fine for most checks, but run the forms, payments and emails once more on the live domain — DNS, email settings and payment keys are exactly what differs between environments.
  • Write down what you find with the page, the steps, what you expected and what happened, plus a screenshot. "The form is broken" can't be fixed; "Contact form on /pricing: submit with a +20 phone number → error 'invalid phone'" can.
  • Decide what blocks launch. Anything that loses money or leads blocks launch. Cosmetic issues usually don't.

1. Forms and key journeys (8 checks)

Forms are where your leads and customers enter. They deserve the most attention.

  1. Submit every form with valid data and confirm the result arrives where it should — inbox, CRM, spreadsheet. Check the spam folder too.
  2. Submit each form empty. Every required field should say what's missing, next to the field, in plain words.
  3. Try realistic "unusual" input: an international phone number, a name with an apostrophe or Arabic letters, a long company name, an email with a plus sign.
  4. Double-click the submit button. You should get one submission, not two.
  5. Check the confirmation: the person should see that it worked and know what happens next.
  6. Run sign-up, sign-in, password reset and log-out end to end, including the emails they send.
  7. Open every link in every automatic email. Links that point to staging are a classic launch-day bug.
  8. Walk the three journeys that make you money (for example: find a product → add to cart → pay) from start to finish without shortcuts.

2. Checkout and payments (6 checks)

  1. Pay with a real card for a small amount on the live site, then refund it. Test mode doesn't prove your live keys work.
  2. Try a declined card (your payment provider publishes test numbers) and make sure the message is clear and the cart survives.
  3. Apply a valid discount code, an expired one, and leave the field empty.
  4. Check totals: tax, shipping and discounts should add up the same on the cart, the checkout, the confirmation page and the receipt email.
  5. Change quantity to 0, to a very large number, and remove the last item. Nothing should go negative or crash.
  6. Confirm the order reaches whoever fulfils it — dashboard, email, warehouse sheet.

3. Mobile and browsers (6 checks)

  1. Open every template on one iPhone and one mid-range Android — not only the newest flagship.
  2. Nothing should scroll sideways. A page wider than the screen is the most common mobile bug.
  3. Tap every button and link with a thumb. Targets that are too small or too close cause wrong taps.
  4. Fill in a form on the phone: the right keyboard should appear (numbers for phone, @ for email) and the field shouldn't hide under the keyboard.
  5. Check Chrome, Safari and at least one of Edge or Firefox on desktop.
  6. If you support Arabic or another right-to-left language, check that layout, icons and numbers flip correctly — and that mixed Arabic/English text reads in the right order.

4. Speed (5 checks)

  1. Run your home page and your most important landing page through a speed test such as Google PageSpeed Insights, on mobile.
  2. Look for oversized images — a 4 MB hero photo is still the most common reason a page is slow. Serve compressed, correctly sized images.
  3. Load the site on a phone on mobile data, not office Wi-Fi, and see how long you wait before you can read or tap anything.
  4. Check that text compression and browser caching are on (your host or CDN usually has a switch).
  5. If you expect a campaign spike, test that the site holds up under that traffic before the ads go live — not during.

5. Content and SEO basics (6 checks)

  1. Every page has its own title and meta description — not the same one copied everywhere.
  2. Remove "lorem ipsum", placeholder prices, test products and "coming soon" pages that go nowhere.
  3. Run a broken-link check across the site. 404s from your own menu are avoidable.
  4. Make sure the live site is not blocked from search engines — a "noindex" left over from staging is a quiet disaster.
  5. Share a page link in WhatsApp or LinkedIn and check the preview: title, description and image.
  6. Check contact details, prices, addresses and legal pages (privacy, terms) are the current ones.

6. Security basics (6 checks)

This isn't a penetration test, but these catch the configuration mistakes attackers look for first.

  1. Every page loads over HTTPS and the http:// version redirects to it.
  2. Security headers are set — at least Content-Security-Policy, Strict-Transport-Security and X-Frame-Options (or frame-ancestors). Free header scanners will show what's missing.
  3. No admin panels, backups, .env or .git files are reachable from the public web.
  4. Sign-in has a limit on repeated wrong passwords, and password reset links expire.
  5. One user can't see another user's data by changing an ID in the address bar.
  6. Default passwords on the CMS, hosting and plugins have been changed, and unused plugins removed.

7. Accessibility (5 checks)

  1. You can reach and use every link, button and form field with the Tab key alone — including checkout.
  2. Images that carry meaning have a text alternative.
  3. Text has enough contrast against its background, especially grey text on white and text on photos.
  4. Form fields have visible labels, not just placeholder text that disappears when you type.
  5. Zoom the browser to 200%: content should still fit and work.

After launch: the first week

Launch isn't the end of testing. In the first week, re-run the money journeys daily, watch your error logs and form submissions, and ask two or three real customers to tell you anything that felt odd. The bugs you find in week one are cheaper than the ones customers find in month three.

Doing it yourself vs. getting help

A careful person can run this checklist in an afternoon on a small site. It gets harder when you have many templates, a mobile app next to the site, several languages, or releases every week — that's when an automated regression suite and a second pair of trained eyes pay for themselves.

Want this run for you?

Breakop can scan your site with AI and put vetted QA testers on the journeys that matter — with every issue logged with steps and evidence, and re-tested after the fix.