Checklist · Maintenance and Security

Website Redesign Migration Checklist

Use this checklist when replacing or substantially restructuring an existing website. It is designed to protect content, URLs, enquiries, data, email and the ability to recover. Adapt it to the platform and business…

Use this checklist when replacing or substantially restructuring an existing website. It is designed to protect content, URLs, enquiries, data, email and the ability to recover. Adapt it to the platform and business risk.

Before development

  • ☐ Record the redesign objective and acceptance criteria.
  • ☐ Crawl or inventory all current URLs, files and redirects.
  • ☐ Export relevant analytics and Search Console data.
  • ☐ Identify pages with enquiries, sales, impressions or external links.
  • ☐ Confirm ownership of domain, DNS, hosting, CMS and critical services.
  • ☐ List forms, integrations, scheduled tasks, feeds and APIs.
  • ☐ Record current email DNS and transactional email configuration.
  • ☐ Take and verify an independent full backup.

Content and URL decisions

  • ☐ Assign every current URL a keep, improve, merge, redirect or remove decision.
  • ☐ Retain useful URLs where there is no good reason to change them.
  • ☐ Map changed URLs directly to the most relevant new destination.
  • ☐ Avoid redirecting unrelated removed pages to the home page.
  • ☐ Preserve valuable headings, evidence and user intent when rewriting.
  • ☐ Update internal links to final URLs rather than relying on redirects.
  • ☐ Identify downloadable files and image URLs that need preservation or redirects.
  • ☐ Prepare a new XML sitemap containing canonical, indexable URLs.

Staging safeguards

  • ☐ Protect staging from public access where practical.
  • ☐ Prevent accidental indexing without copying temporary noindex settings into production.
  • ☐ Use realistic content and representative data.
  • ☐ Keep production credentials and personal data out of staging unless properly controlled.
  • ☐ Record any environment-specific settings that must change at launch.

Functional testing

  • ☐ Test contact, quotation and application forms.
  • ☐ Confirm recipient addresses, reply handling and spam controls.
  • ☐ Test booking, payment, refund and cancellation routes where applicable.
  • ☐ Test customer accounts, password reset and permissions.
  • ☐ Check search, filters, pagination and downloadable files.
  • ☐ Verify transactional emails and message templates.
  • ☐ Test privacy choices and consent withdrawal.
  • ☐ Confirm analytics events without collecting more data than intended.

Content, SEO and technical checks

  • ☐ Each indexable page has one clear H1 and an editable title.
  • ☐ Canonical URLs point to the intended production pages.
  • ☐ Robots directives and robots.txt do not block important content.
  • ☐ Structured data reflects visible, truthful content.
  • ☐ Breadcrumbs and internal links use final destinations.
  • ☐ Redirects return the intended permanent status and avoid chains.
  • ☐ Custom 404 pages return HTTP 404.
  • ☐ The XML sitemap and Search Console property are ready.

Mobile, accessibility and browser checks

  • ☐ Test core tasks on real Android and iOS devices where available.
  • ☐ Check widths from 320 to 430 CSS pixels.
  • ☐ Ensure page-level horizontal scrolling is absent.
  • ☐ Test keyboard navigation, focus and skip links.
  • ☐ Check labels, instructions and form error messages.
  • ☐ Test major desktop and mobile browser engines.
  • ☐ Check zoom, text resizing and reduced-motion behaviour.

Performance and security

  • ☐ Optimise responsive images and reserve dimensions.
  • ☐ Review third-party scripts and remove unnecessary ones.
  • ☐ Confirm HTTPS and no mixed-content errors.
  • ☐ Apply supported software versions and least-privilege access.
  • ☐ Enable multi-factor authentication for critical accounts where available.
  • ☐ Confirm backups, monitoring and recovery contacts.

Launch preparation

  • ☐ Agree a content or transaction freeze if required.
  • ☐ Take a final production backup.
  • ☐ Export late orders, users or submissions that need synchronising.
  • ☐ Confirm the redirect file and deployment package.
  • ☐ Lower DNS TTL in advance only if the migration plan requires it.
  • ☐ Record who can approve launch and rollback.
  • ☐ Prepare a maintenance or customer communication if downtime is possible.

Immediately after launch

  • ☐ Test the home page and representative deep URLs from an external connection.
  • ☐ Run core forms, bookings and payments.
  • ☐ Verify HTTPS, canonical, robots and index settings.
  • ☐ Test old high-value URLs and redirect samples.
  • ☐ Check server logs and application errors.
  • ☐ Submit or verify the new sitemap in Search Console.
  • ☐ Check real-time or diagnostic analytics without treating it as the sole proof.
  • ☐ Confirm business email and transactional delivery.

First month

  • ☐ Monitor 404s, redirect chains and indexing.
  • ☐ Compare important landing pages and conversions with the baseline.
  • ☐ Review customer and staff reports.
  • ☐ Keep the old backup and rollback material for the agreed period.
  • ☐ Document fixes and unresolved limitations.

Official technical reference

Google Search Central: site moves with URL changes

The checklist is complete only when evidence of the tests is recorded, not when boxes are ticked from memory.

Keep the decision under your control

Retain the relevant accounts, source material, supplier terms and recovery information. Recheck changing prices, interfaces and rules before acting.