Checklists
A Website Hosting Checklist for Local Businesses
A practical checklist for domains, DNS, hosting, email, backups, security, ownership and supplier handover.
This checklist helps a local business understand and control the services behind its website. Complete it before a migration, after a staff or supplier change, and as part of an annual digital housekeeping review.
Domain and ownership
- We know the domain registrar and can sign in.
- The registrant and recovery details are current and business-controlled.
- Renewal is enabled or diarised, with a valid payment method.
- More than one trusted person knows how emergency access works.
- A supplier cannot retain the domain simply because it built the website.
DNS
- We know which provider hosts authoritative DNS.
- We have a record of the current DNS zone.
- We can identify the website and email records.
- Old verification and service records are reviewed before removal.
- Planned changes have an owner, time and rollback route.
Hosting account
- The account is registered to a current business email address.
- Multi-factor authentication is enabled if available.
- Former staff and suppliers no longer have unnecessary access.
- We understand the normal renewal price and contract term.
- Storage, processing and traffic limits suit the website.
- We know how to export files and databases.
Website software
- Core software, themes and extensions are supported and maintained.
- Somebody is responsible for updates.
- Important changes are tested away from the live site where practical.
- Unused administrator accounts and plugins are removed.
- Licences do not depend on a supplier account we cannot access.
Backups and recovery
- We know what is backed up and how often.
- We know how long backups are retained.
- At least one suitable copy is separate from the live environment.
- The restore process and responsible person are documented.
- Recovery has been tested proportionately to the site's importance.
Email and forms
- We know who provides business email.
- MX, SPF, DKIM and DMARC records are documented.
- Website forms have been tested recently.
- Form messages go to a monitored mailbox.
- There is a visible alternative contact route if a form fails.
- Departing staff accounts follow a defined handover and retention process.
Security and privacy
- HTTPS works across the site without mixed-content warnings.
- Administrator passwords are unique and stored appropriately.
- Personal data collected by forms is limited to what is needed.
- Privacy information reflects the tools actually in use.
- Non-essential tracking is not added without a considered consent approach.
Performance and usability
- Important pages work on a small mobile screen.
- Images are sized and compressed sensibly.
- Contact, booking and purchase journeys are tested end to end.
- Third-party widgets earn their performance and privacy cost.
- Accessibility issues are included in maintenance, not deferred indefinitely.
Supplier handover pack
Keep a short, secure record of providers, account owners, renewal dates, emergency contacts and system dependencies. Do not put passwords in an ordinary shared document; store them through an appropriate password-management process.
The goal is not paperwork for its own sake. It is to ensure that a domain expiry, staff departure or supplier dispute does not leave the business unable to operate its own website.
