A website can look fine while enquiry emails quietly fail. Our health-check guide covers WordPress security, hosting, backups and email deliverability before a missed enquiry costs you a client.
A business website can look completely normal and still have problems happening quietly in the background.
It might load properly. The homepage might look fine. Your phone number might be correct.
But behind the scenes, there can still be issues with:
For businesses that rely on their website to generate leads, these aren’t just “website problems”.
They can become lost-enquiry problems.
Recently, we’ve been doing some deeper checks across our own email systems and a number of WordPress websites we work with. We’ve identified a few areas that we think every business owner should understand and periodically check.
This guide explains what we’re looking at, what you should look out for, and what we’re doing to help.
One of the biggest misconceptions about websites is that:
“If the website loads, it must be working.”
Unfortunately, that’s not always true.
A website is made up of multiple systems working together.
That can include:
A problem with one of those systems doesn’t necessarily make the entire website disappear.
For example, your website could continue loading perfectly while your contact form notification emails have stopped reaching you.
That’s one of the reasons website health needs to be looked at more broadly than simply asking whether the website is online.
This is one of the simplest questions a business owner can ask.
When did you last receive a genuine enquiry through your website?
If you’re normally receiving several enquiries every week and suddenly haven’t received one for two weeks, it might simply be a quieter period.
But it’s worth checking.
A contact form can sometimes successfully accept an enquiry and display:
“Thank you. Your message has been sent.”
That does not necessarily guarantee the notification email reached your inbox.
There are several systems between the customer pressing Submit and that enquiry appearing in your inbox.
Problems can occur with:
That’s why we recommend periodically submitting a real test enquiry through your own website.
Email providers are constantly changing the way they identify spam and suspicious messages.
Google, Microsoft and other email platforms increasingly look at things such as:
This is generally a good thing.
It helps protect everyone from spam, scams and phishing.
But occasionally legitimate emails can also get caught in those filters.
That could include:
This is why checking your Spam or Junk folder periodically is still worthwhile.
Mark it as Not Spam or move it back into your inbox.
That gives your email provider an additional signal that you want to receive messages from that sender.
This sounds obvious, but it’s something we regularly find during website audits.
The email address configured inside the website isn’t always the email address the business currently wants enquiries sent to.
Businesses change over time.
Staff leave.
New staff start.
Email addresses change.
An enquiry form that was originally configured to send notifications to:
might still be sending there several years later — even though John no longer works for the company.
That’s why we’re currently asking businesses to confirm:
What email address should website enquiries be sent to?
We can then compare that against the actual form notification settings.
WordPress isn’t a static piece of software.
WordPress itself, your website theme and the plugins installed on your website all receive updates over time.
Those updates can include:
Security updates are particularly important.
WordPress itself continues to release security patches when vulnerabilities are discovered. In August 2026, for example, WordPress released multiple security updates in quick succession and recommended affected websites update immediately.
That doesn’t mean WordPress is inherently unsafe.
WordPress powers more than 43% of the web, and maintaining such a large software ecosystem naturally involves finding and fixing vulnerabilities over time.
The bigger risk is often a website that hasn’t been maintained.
WordPress core is only one part of a WordPress website.
Most business websites also rely on a combination of:
Every additional piece of software creates another component that needs to remain compatible and secure.
That doesn’t mean you should blindly press Update All every time an update appears.
Updates can occasionally introduce conflicts.
A more responsible process is generally:
Your website has to live somewhere.
That is your hosting environment.
Hosting affects things such as:
The cheapest hosting option isn’t always the best environment for a business website that generates enquiries.
This becomes especially important when multiple websites are hosted inside the same environment.
Better hosting infrastructure can provide improved isolation, security controls, backups and recovery options.
We’ve written separately about why we increasingly recommend managed WordPress hosting for businesses that rely heavily on their website for leads and marketing.
Related: Managed WordPress Hosting for Businesses
This is an area most business owners understandably never think about.
Some hosting configurations allow many websites to exist within the same broader hosting account or server environment.
Depending on how that environment is configured, problems affecting one website can potentially create additional risk for other websites sharing that environment.
That doesn’t mean:
“Shared hosting = hacked website.”
There are plenty of legitimate shared hosting environments.
The important questions are:
For businesses that consider their website an important asset, stronger isolation between websites is increasingly something we look for when recommending hosting.
Another common concern is form spam.
You might suddenly start receiving enquiries for:
This can be frustrating, but it does not automatically mean someone has hacked your website.
Automated bots constantly crawl websites looking for contact forms.
We’ve previously written about this in more detail:
Related: Why Are Website Spam Enquiries Increasing?
The appropriate response might include improvements such as:
But spam and an actual website compromise are two different things.
Sometimes a hacked website is obvious.
Other times, it isn’t.
Possible warning signs include:
One particularly sneaky form of compromise is sometimes referred to as SEO spam.
An attacker may generate hundreds or thousands of pages on a legitimate website designed to rank for unrelated searches.
Your homepage may still look completely normal.
That is why security checks sometimes need to go deeper than simply visiting the website.
SEO tools sometimes report very large numbers of questionable or “toxic” backlinks.
It is important not to automatically assume this means your website has been hacked.
Anyone can create a link pointing toward another website.
You don’t control every website on the internet.
The more important question is:
Where are those links pointing?
If thousands of suspicious backlinks are pointing toward normal pages on your website, it may simply be external spam.
If they’re pointing toward strange pages that suddenly exist on your domain, that’s much more concerning and should be investigated.
This is where website security and SEO sometimes overlap.
Website security isn’t only about WordPress.
People are often the target.
A common attack might look like an email supposedly coming from:
The email may claim:
The goal is often to get you to click a link and enter your login details into a fake website.
Once attackers have genuine credentials, even a technically secure platform becomes much easier to compromise.
If an email unexpectedly asks you to log into an important account:
Don’t automatically use the link in the email.
Instead, open the service directly using your normal bookmark or browser and check your account there.
Passwords get reused.
Passwords get leaked.
People get phished.
Two-factor authentication adds an additional step when logging into an account.
We strongly recommend enabling it where available for important systems such as:
Two-factor authentication won’t prevent every attack, but it can significantly reduce the damage caused by stolen passwords.
Here’s another good question:
Who currently has access to your website?
Over several years, businesses can accumulate accounts belonging to:
That access may no longer be necessary.
Periodically reviewing WordPress users, hosting users and other important accounts is good security hygiene.
Remove access that is no longer required.
Having a backup system is important.
But simply seeing the word “Backup” somewhere in your hosting account isn’t the full answer.
Useful questions include:
A good backup strategy gives you options when something goes wrong.
Our managed WordPress hosting recommendations put significant emphasis on backups, staging, security and recovery for exactly this reason.
Your website also relies on several external systems simply to stay online.
That can include:
Even major technology platforms experience outages occasionally.
We’ve written a separate guide explaining website uptime and what can cause temporary downtime:
Related: Understanding Website Uptime: Why Downtime Happens and How We Manage It
The key point is that website health isn’t determined by one system.
It’s the combination of multiple systems working correctly.
You don’t need to be a developer to perform a basic check.
Ask yourself:
If you’re unsure about several of these, that’s not unusual.
Most business owners shouldn’t have to spend their days thinking about WordPress plugins, SMTP records and malware scans.
But someone should be checking them.
We’ve recently been conducting a broader review across our own systems and websites we support.
As part of that process, we’re looking at areas including:
We’re also asking business owners to confirm the email address that should currently receive website enquiries.
That allows us to compare what the business expects against what is actually configured inside the website.
This isn’t about assuming every website has a problem.
It’s about checking rather than assuming.
If you’ve received an email from us asking you to complete a quick website health check, please reply.
Even if your answer is simply:
“Everything looks fine.”
That is useful.
In particular, please let us know:
If our email landed in Spam, please mark it as Not Spam.
We’re contacting more than 100 business owners as part of this broader review, so we’ll be working through responses as quickly as we can.
You’re also welcome to include any other questions or concerns about your website, hosting, security or email delivery when you reply.
Websites have become increasingly important to how businesses generate leads.
At the same time, the technology behind them has become more interconnected.
Hosting matters.
Security matters.
WordPress updates matter.
Email deliverability matters.
Backups matter.
And most importantly, your enquiries actually reaching you matters.
A few simple checks can identify problems before they become expensive ones.
If you’re unsure about the health of your website, contact the team at New Wave Digital Marketing and we’ll help you work out what should be checked.
Free calculator
Most business owners have no idea how much revenue their Google ranking is leaving on the table. Find out yours in 2 minutes.
Calculate Your Value →Free · No sales call