Partway through the audit we checked the domain's email authentication. That is not normally part of a website rebuild.
The domain had an SPF record. It had no DKIM and no DMARC, both of which Gmail and Yahoo have required since February 2024. And the SPF record it did have authorised the wrong machine — the web server's address rather than the mail server's.
The control panel reported that record as "Valid." It was. Syntactically it was a perfectly well-formed record. It was also wrong, and a control panel only checks the first of those things. Valid and correct are different words.
The practical effect is that for years, email Jolene sent from her own business address — class updates, replies to enquiries, invitations — was likely being filtered before anyone read it. She had no way of knowing. Nothing tells you when your mail is quietly set aside.
This had nothing to do with her website, and it was worth more to her business than the rebuild. SPF was corrected, DKIM and DMARC published, and all three confirmed in DNS rather than in a dashboard.
That distinction ran through the whole project: we verified outcomes rather than trusting reports. It caught two real failures. The first off-site backup reported success while logging "no remote despatch" six times — it was recording files as uploaded to nowhere. A plugin update reported success while silently leaving the contact form switched off. Both looked fine on the screen that was supposed to tell us.
The redirect map came from the database rather than a crawl, for the same reason. Crawling the old site found 12 addresses. Querying the posts table found 18 — six published pages no crawler could ever reach, because nothing linked to them. Each had accumulated whatever search history it had. A crawl-based migration would have quietly broken all six.
Access inherited from a previous arrangement was audited and tightened.