Guide · updated 4 October 2026

Website testing checklist: what to check before a site goes live

The checks a website or web app needs before it goes live, and after every big change. Each one says what to do and what a pass looks like.

A website breaks in the gaps between the pages people designed. A form that sends twice. A link to a page that moved. A layout that scrolls sideways on a phone. A reset email that lands in spam. None of it shows up when you click through the site once on your own laptop.

This checklist is for sites and web apps opened in a browser. For apps installed on a phone, use the mobile app testing checklist. For a short pass on each update, use the release checklist.

Which browsers to test

Chrome, Safari, Firefox and Edge on a computer, and Safari on an iPhone. Edge is built on the same engine as Chrome, so it rarely differs, but it is cheap to check. Safari is the one that most often behaves differently, and it only runs on a Mac or an iPhone.

Safari on an iPhone is its own test. The on-screen keyboard covers the bottom of the page, the address bar shrinks as you scroll, and there is no mouse to hover with. Test it on a real phone if you can.

Some checks only need one browser: robots.txt, the sitemap, image sizes and contrast give the same answer everywhere. The checklist marks the others N/A for those.

Screen widths without a drawer of devices

Every browser's developer tools can resize the page to a set width. Check 375 px for a phone, 768 px for a tablet and 1440 px for a desktop. The one failure to look for at every width is sideways scrolling: if the page moves left and right under your thumb, something is wider than the screen.

Forms are where the bugs are

Test the empty submit, the wrong value and the double click, not just the correct entry. A pass means three things: the user sees what went wrong next to the field, what they typed is kept, and nothing is sent twice. For sign-in forms in detail, see the login test cases.

Sign-in and sessions

Most session bugs need two things at once to appear: two tabs, an expired session, or a sign-out followed by the back button. Test those combinations. A pass is simple to state: after signing out, no private page can be seen again without signing back in.

Accessibility you can check in ten minutes

Put the mouse away and complete the main journey with the keyboard. Then zoom the browser to 200% and do it again. Those two checks find most of the problems that stop people using a site. Add alt text on images and a contrast check on text, and you have covered the basics. A full audit goes further.

Security a non-technical tester can check

You do not need security tools for the basics. Check that the site always loads over HTTPS, that no token or password ever shows in the address bar, that a signed-out visitor cannot open a private page by pasting its URL, and that ten wrong passwords in a row are slowed down or blocked.

Payments and emails

If the site takes money, test it in the payment provider’s test mode with its test cards, never a real card. The checkout test cases cover declined cards, 3-D Secure, refunds and receipts in full.

For emails, “sent” is not a pass. Use a real inbox, check it arrived and was not filtered as spam, and click every link in it. A link that points to staging is a common find.

The checklist

Copy it and adapt the journeys to your site. It imports into qarunbook as a board with a column for each browser. Delete the payments or dark mode rows if your site has neither.

website-checks.md
# Website checks

## Forms and validation (FORM)

| ID | Journey | Preconditions | Steps | Expected result | Chrome | Safari | Firefox | Edge | iOS Safari |
|---|---|---|---|---|---|---|---|---|---|
| FORM-01 | Submit a form filled in correctly | Any form: contact, sign-up, checkout | 1. Fill every field with valid values. 2. Submit. | A confirmation is shown on screen and the data arrives where it should: inbox, database or admin. | | | | | |
| FORM-02 | Submit with required fields empty | Same form | 1. Leave the required fields empty. 2. Submit. | Each empty field is marked with a message beside it. Nothing is sent. | | | | | |
| FORM-03 | Invalid values are refused | Same form | 1. Enter an email without an @ and letters in a phone field. 2. Submit. | A message beside each field says what is wrong. Everything else typed is kept. | | | | | |
| FORM-04 | Submit pressed twice | Same form | 1. Fill it in. 2. Click submit twice quickly. | One record and one email, not two. The button is disabled or shows progress after the first click. | | | | | |
| FORM-05 | Long and unusual input | Same form | 1. Paste 2,000 characters into a text field. 2. Enter a name with an apostrophe and an accent, like O'Brien or José. | The form accepts it or gives a clear limit. The saved value reads exactly as typed. | | | | | |

## Navigation and links (NAV)

| ID | Journey | Preconditions | Steps | Expected result | Chrome | Safari | Firefox | Edge | iOS Safari |
|---|---|---|---|---|---|---|---|---|---|
| NAV-01 | Every menu link goes somewhere | The live or staging site | 1. Click each link in the header, menu and footer. | Each opens the right page. None returns an error or a blank page. | | | | | |
| NAV-02 | No broken links in the content | As above | 1. Run a link checker over the site, or click through the main pages. | No link returns a 404 or 500. Links to other sites still work. | | N/A | N/A | N/A | N/A |
| NAV-03 | The 404 page | As above | 1. Open the site with a made-up path, like /no-such-page. | A not-found page in the site's design, with a way back to the home page. | | | | | |
| NAV-04 | The back button | Mid-way through any multi-step flow | 1. Press the browser's back button. | It returns to the previous page with what was typed still there, or warns before losing it. | | | | | |

## Layout and screen sizes (LAY)

| ID | Journey | Preconditions | Steps | Expected result | Chrome | Safari | Firefox | Edge | iOS Safari |
|---|---|---|---|---|---|---|---|---|---|
| LAY-01 | Phone width | Window at 375 px wide, or a phone | 1. Open each main page. 2. Scroll to the bottom. | No sideways scrolling. No text cut off. Buttons are big enough to tap. | | | | | |
| LAY-02 | Tablet width | Window at 768 px wide | 1. Open each main page. | The layout fits, with no overlapping columns or squashed images. | | | | | N/A |
| LAY-03 | Wide desktop | Window at 1440 px or wider | 1. Open each main page. | Content stays readable. Lines of text do not stretch across the whole screen. | | | | | N/A |
| LAY-04 | Dark mode, if the site supports it | System set to dark | 1. Open each main page. | Every page follows, text stays readable, and no logo or icon disappears into the background. | | | | | |

## Sign-in and sessions (SESS)

| ID | Journey | Preconditions | Steps | Expected result | Chrome | Safari | Firefox | Edge | iOS Safari |
|---|---|---|---|---|---|---|---|---|---|
| SESS-01 | Sign in and land in the right place | An existing account | 1. Open a page that needs sign-in. 2. Sign in. | You land on the page you asked for, not always the home page. | | | | | |
| SESS-02 | Session expires | Signed in | 1. Leave the tab idle past the session limit, or clear the session cookie. 2. Click something. | You are sent to sign in with a message. Nothing you typed is silently lost. | | | | | |
| SESS-03 | Two tabs open | Signed in, two tabs on the site | 1. Sign out in tab A. 2. Use tab B. | Tab B stops showing private data and asks you to sign in. | | | | | |
| SESS-04 | Sign out clears the session | Signed in | 1. Sign out. 2. Press back. | The private page does not reappear. Reloading asks you to sign in. | | | | | |
| SESS-05 | Sign in again after signing out | Signed out after SESS-04 | 1. Sign in again. | It works first time, with no stale error or loop. | | | | | |

## Speed (PERF)

| ID | Journey | Preconditions | Steps | Expected result | Chrome | Safari | Firefox | Edge | iOS Safari |
|---|---|---|---|---|---|---|---|---|---|
| PERF-01 | Slow network | Network throttling on in the browser's developer tools | 1. Load the home page and the main journey. | Text appears first and the page is usable before every image loads. No blank screen. | | N/A | N/A | N/A | N/A |
| PERF-02 | Large images | Developer tools open on the network tab | 1. Load the image-heavy pages. | No single image is several megabytes. Images are sized for the screen they show on. | | N/A | N/A | N/A | N/A |
| PERF-03 | Nothing jumps while loading | A normal connection | 1. Load a page and start reading at once. | Text does not move as images, fonts or banners arrive. | | | | | |

## Accessibility (ACC)

| ID | Journey | Preconditions | Steps | Expected result | Chrome | Safari | Firefox | Edge | iOS Safari |
|---|---|---|---|---|---|---|---|---|---|
| ACC-01 | Keyboard only | No mouse | 1. Use Tab, Shift-Tab, Enter and Space to complete the main journey. | Every link, button and field can be reached and used, in a sensible order. | | | | | N/A |
| ACC-02 | Focus is visible | As above | 1. Tab through a page. | You can always see which element has focus. | | | | | N/A |
| ACC-03 | Images have alt text | Any content page | 1. Inspect each meaningful image. | Each has alt text that says what it shows. Decorative images have empty alt. | | N/A | N/A | N/A | N/A |
| ACC-04 | Text contrast | Any page | 1. Check body text, buttons and placeholder text with a contrast checker. | Body text meets 4.5:1 against its background. Large text meets 3:1. | | N/A | N/A | N/A | N/A |
| ACC-05 | Zoom to 200% | Browser zoom at 200% | 1. Open the main pages. 2. Complete the main journey. | Nothing overlaps or disappears, and the journey can still be completed. | | | | | |

## Search and sharing (SEO)

| ID | Journey | Preconditions | Steps | Expected result | Chrome | Safari | Firefox | Edge | iOS Safari |
|---|---|---|---|---|---|---|---|---|---|
| SEO-01 | Title and description | Any public page | 1. View the page source. | Each page has its own title and meta description, not the same one site-wide. | | N/A | N/A | N/A | N/A |
| SEO-02 | Social preview | A public page URL | 1. Paste the link into a chat app or social post draft. | The preview shows the right title, description and image. | | N/A | N/A | N/A | N/A |
| SEO-03 | robots.txt | The live site | 1. Open /robots.txt. | It exists and does not block the whole site. Staging is the one that should be blocked. | | N/A | N/A | N/A | N/A |
| SEO-04 | Sitemap | The live site | 1. Open /sitemap.xml. | It loads, lists the public pages, and every URL in it opens. | | N/A | N/A | N/A | N/A |

## Security basics (SEC)

| ID | Journey | Preconditions | Steps | Expected result | Chrome | Safari | Firefox | Edge | iOS Safari |
|---|---|---|---|---|---|---|---|---|---|
| SEC-01 | HTTPS everywhere | The live site | 1. Open the site with http:// typed in front. | It redirects to https://. The browser shows no certificate or mixed-content warning. | | | | | |
| SEC-02 | No secrets in URLs | Signed in | 1. Use the site and watch the address bar. | No password, token or personal detail appears in any URL. | | N/A | N/A | N/A | N/A |
| SEC-03 | Password fields | The sign-in and sign-up forms | 1. Type a password. | It is masked, it can be pasted, and a password manager can fill it. | | | | | |
| SEC-04 | Repeated wrong passwords | An existing account | 1. Enter a wrong password ten times. | Attempts are slowed or blocked with a clear message. The right password works again afterwards. | | N/A | N/A | N/A | N/A |
| SEC-05 | Private pages need sign-in | Signed out | 1. Paste the URL of a signed-in page. | You are asked to sign in. No private data shows, even briefly. | | | | | |

## Emails the site sends (MAIL)

| ID | Journey | Preconditions | Steps | Expected result | Chrome | Safari | Firefox | Edge | iOS Safari |
|---|---|---|---|---|---|---|---|---|---|
| MAIL-01 | Every email arrives | A test inbox you can read | 1. Trigger each email: welcome, verification, password reset, receipt, contact form. | Each arrives within a few minutes, in the inbox, not in spam. | | N/A | N/A | N/A | N/A |
| MAIL-02 | Links in emails work | The emails from MAIL-01 | 1. Click every link and button in each email. | Each opens the right page on the live site, not staging or localhost. | | | | | |
| MAIL-03 | Email reads on a phone | The emails from MAIL-01 | 1. Open them in a phone mail app. | Readable without zooming. Sender name and subject make sense. | N/A | N/A | N/A | N/A | |

## Payments (PAY)

| ID | Journey | Preconditions | Steps | Expected result | Chrome | Safari | Firefox | Edge | iOS Safari |
|---|---|---|---|---|---|---|---|---|---|
| PAY-01 | Pay with a test card | Test mode, the provider's test cards | 1. Buy something with a card that succeeds. | The order is confirmed, the receipt matches the price shown, and you are charged once. | | | | | |
| PAY-02 | A declined card | As above | 1. Pay with the provider's decline test card. | A clear message, the basket is kept, and no order is created. | | | | | |

## Cookies and consent (COOK)

| ID | Journey | Preconditions | Steps | Expected result | Chrome | Safari | Firefox | Edge | iOS Safari |
|---|---|---|---|---|---|---|---|---|---|
| COOK-01 | Reject non-essential cookies | A fresh private window | 1. Open the site. 2. Choose reject or essential only. | The banner closes, the site works, and no analytics or ad cookies are set. | | | | | |
| COOK-02 | The choice is remembered | After COOK-01 | 1. Visit another page. 2. Return the next day. | The banner does not come back each page. The choice can be changed later from a link. | | | | | |

## Errors and empty states (ERR)

| ID | Journey | Preconditions | Steps | Expected result | Chrome | Safari | Firefox | Edge | iOS Safari |
|---|---|---|---|---|---|---|---|---|---|
| ERR-01 | Server error | A way to make a request fail, or the network turned off mid-action | 1. Submit an action while it fails. | A plain message says it did not work and what to do. No raw error text or code. | | | | | |
| ERR-02 | Empty lists | A new account with no data | 1. Open each list page: orders, messages, projects. | Each says there is nothing yet and how to add the first one. No blank area. | | | | | |
| ERR-03 | Search with no results | Any search box | 1. Search for a string that matches nothing. | A message says nothing matched. The search term is still in the box. | | | | | |

Record results per browser

Import the checklist into qarunbook and each check gets a result for each browser, with the name of the person who checked it. When a check fails, raise an issue from it with the steps and the browser. Developers see it on the board, and if GitHub is connected, each new issue can be filed in the repository as well.

When a fix is marked done, the check goes back for a retest rather than passing on its own. It passes again when someone has checked it on the browser where it failed.