EthereumWebsites

The Web3 Launch Site Checklist

Twenty-eight checks across domain, content, compliance, security, and launch day — for anyone shipping a website for a token, NFT, or dApp project.

A VILLARENOVA LLC guide · ethereumwebsites.com

1. Domain & hosting

You personally control the domain registrar accountNot a co-founder, not a marketing contractor — an account you can access if everyone else disappears tomorrow.
Domain renewal is on auto-renew with a payment method that won't expireA lapsed domain is the single most common way legitimate projects lose their site to squatters.
DNS is documented somewhere outside one person's headWhich registrar, which nameservers, which records point where.
HTTPS is enforced site-wide, not just the homepageEvery page, every subdomain you use.

2. Content & copy

Every stat, price, and date on the site is one you can currently verify is trueNot "will be true soon," not a rounded-up estimate presented as fact.
No testimonials, client counts, or "trusted by" claims you can't back upIf you have zero real testimonials, the honest move is to say so or omit the section — not to write a placeholder one.
Roadmap items are dated only if the dates are real commitmentsVague roadmaps ("Q_ 2026: TBD") read as more honest than fake-precise ones you'll miss.
Team page either names real people or doesn't imply a team that doesn't existAnonymous teams are common and fine in this space — just don't imply headcount you don't have.

3. What NOT to say (compliance basics)

This is not legal advice — for anything token-related, get a real securities/crypto attorney to review before launch. These are the copy mistakes we see most often.
No promises of price appreciation, ROI, or "guaranteed returns"This is the fastest way to attract regulatory attention in most jurisdictions.
No language implying the token is a security if it isn't structured as one (or vice versa)Get counsel on this specifically — the copy has to match the actual legal structure.
Clear disclaimer that nothing on the site is financial or investment adviceStandard, visible, in the footer of every page — not buried in a terms page nobody reads.
If you reference audits, link the actual audit report"Audited" with no link or an audit of a different contract version is a common, easily-checked red flag.

4. Wallet & security

The marketing/info site does not request a wallet connection unless it strictly needs toA site that only explains the project and links to the dApp is a smaller attack surface and builds more trust than one that asks visitors to connect a wallet just to read a roadmap.
Any mint/claim flow is on its own audited subdomain or dApp, separate from the marketing siteKeeps a CMS or marketing-site compromise from becoming a wallet-drain incident.
Contract addresses are displayed and easy to copy-paste correctlyFake-contract phishing sites thrive when the real project makes the address hard to find or verify.
No third-party embeds or widgets you haven't personally vettedA compromised ad/analytics widget is a real vector for injecting a fake wallet-connect prompt.

5. SEO & technical foundation

Unique title + meta description on every page
Open Graph tags so links preview correctly on X/Discord/TelegramTest this before launch — a broken OG image on a Discord share is a bad first impression.
sitemap.xml and robots.txt present and correct
Mobile-tested at real small-screen widths (375-390px), not just a resized desktop browser
Core Web Vitals checked, not assumedA slow site quietly loses launch-day traffic before anyone reports a bug.

6. Launch day

A second person has clicked every link on the live site, not just the person who built it
Forms actually deliver somewhere you checkTest the contact/lead form end-to-end the day of launch, not the week before.
Analytics is live before the traffic spike, not added afterYou can't reconstruct launch-day numbers retroactively.
You know who to contact if the site goes down mid-launchHosting support contact, DNS provider support contact — written down, not "I'll figure it out."

7. Post-launch (week one)

Broken-link check run at least once after launch
Any "coming soon" copy has a real plan behind it, not an indefinite placeholder
Someone is actually monitoring the lead/contact inboxA site that generates interest nobody responds to is worse than no site at all.
You've decided who owns future edits to the siteAnd that person has real access — see #1.
This checklist is provided as general guidance for Web3 project sites and is not legal, financial, or security advice. Nothing in it is a substitute for a qualified attorney, security auditor, or accountant reviewing your specific project. © VILLARENOVA LLC — ethereumwebsites.com. You're free to use this checklist for your own project; please don't resell it or strip the attribution if you share it.