Automated Launch-Gate Validation for BSSD: SEO, Compliance, and Deliverability Verification
Overview
The Burial at Sea San Diego (BSSD) outreach engine deployment follows a four-item gate checklist that validates infrastructure, search visibility, and compliance requirements before the first-send campaign launches. This post covers the automated and manual verification workflow, the infrastructure decisions behind each gate item, and how the process prevents launch-day incidents.
What Was Done
The launch gate for burialsatseasandiego.com runs on a nightly cadence (configured to repeat through Jul 8, 2026) and checks four critical items before outreach begins:
- Item 1: Google Business Profile (GBP) claimed — Requires manual verification and setup; estimated 15 minutes to complete
- Item 2: Google Search Console (GSC) verified — Requires domain ownership proof and indexing check; estimated 10 minutes
- Item 3: 403 errors fixed (robots.txt + sitemap.xml) — Fixed and verified live on 2026-07-05 returning HTTP 200
- Item 4: Unsubscribe endpoint live — CAN-SPAM compliance requirement; must return 200 and process requests
Automated checks verify items 3 and 4 via curl requests to the live site. Manual gate items (1-2) are tracked in /Users/cb/icloud-jada-ops/bssd-crm/LAUNCH-GATE-2026-07-08.md, reviewed daily and gated until all four items reach FIXED or VERIFIED status.
Technical Details: Why Each Gate Item Matters
Item 3: HTTP 403 Resolution (robots.txt + sitemap.xml)
Search engines and crawlers require robots.txt and sitemap.xml to be publicly accessible and return HTTP 200. A 403 response (Forbidden) signals to Googlebot that these files are intentionally blocked, which:
- Prevents indexing of the domain entirely (Google honors 403 as a hard block)
- Stalls GBP listing approval
- Breaks organic search visibility before outreach even begins
The fix involved adjusting CloudFront or origin web server access control rules to allow public read access to these two files. Verification runs:
curl -I https://burialsatseasandiego.com/robots.txt
# Returns: HTTP/1.1 200 OK
curl -I https://burialsatseasandiego.com/sitemap.xml
# Returns: HTTP/1.1 200 OK
Item 4: Unsubscribe Endpoint (CAN-SPAM Compliance)
The CAN-SPAM Act requires every marketing email to include a working unsubscribe link. The outreach engine validates that this endpoint:
- Responds with HTTP 200 and accepts POST/GET requests
- Processes subscription removals within 10 business days
- Returns a confirmation page (not an error or timeout)
A failing unsubscribe endpoint exposes the campaign to FTC penalties and ISP complaints, making this a mandatory gate blocker. The endpoint is tested via:
curl -v https://burialsatseasandiego.com/unsubscribe?email=test@example.com
# Must return 200, not 301/302/404/500
Infrastructure and Architecture Decisions
Gate file location: /Users/cb/icloud-jada-ops/bssd-crm/LAUNCH-GATE-2026-07-08.md — A single-source-of-truth markdown table tracking gate status, expected resolution dates, and action owners. This file is reviewed nightly by the automation and referenced in pre-send approval workflows.
DNS and CDN: The domain burialsatseasandiego.com is served via CloudFront (CDN) with origin configured to allow public access to static files (robots.txt, sitemap.xml) while protecting the application layer behind access control rules. This prevents 403 errors for SEO-critical files while maintaining security for dynamic endpoints.
Automation scope: The nightly check repeats through Jul 8 via a scheduler (likely cron or AWS EventBridge) invoking the gate validation script, which runs curl requests against the live site and compares results against expected HTTP 200 responses. Manual items (GBP, GSC) are tracked in the gate document and updated by the campaign owner.
Key Decisions
Why gate Items 1-2 are manual: GBP and GSC verification require human-in-the-loop steps (clicking confirmation emails, verifying DNS records, claiming business listings). These can't be automated without OAuth scopes that would complicate deployment, so they're tracked as CB-ACTION-NEEDED with estimated completion times.
Why Item 3-4 are automated: HTTP status codes and endpoint availability can be verified with simple curl requests. Automating these reduces human error and catches infrastructure issues (misconfigured CloudFront, broken origin routing) before they block the campaign.
Why the Monday night deadline: The first send is scheduled for Tuesday Jul 8. The gate review happens daily through Jul 6 (end of business Sunday); if any item is still red (not FIXED or VERIFIED), the campaign HOLDS. This 24-hour buffer gives the team time to resolve issues without rushing into launch day.
What's Next
On Monday Jul 7, the gate is re-checked. If all four items are green, the campaign proceeds to first-send on Jul 8. If any item remains red, a HOLD recommendation is issued to the board, and sends are postponed until resolution. The unsubscribe endpoint is flagged as non-negotiable — without it, the campaign cannot launch regardless of other gate status.