← All guides

Single opt-in or double opt-in?

Double opt-in costs you subscribers and protects everything else. An honest accounting of the trade, and a policy that takes both sides seriously.

Deliverability · 3 min read · updated

The terms, without the marketing

Single opt-in: an address enters your list the moment the form is submitted. Double (or confirmed) opt-in: the address gets a confirmation email, and only joins the list when its link is clicked.

The confirmation click proves two things nothing else proves: the mailbox exists and receives mail, and the person who controls it actually asked. Every argument for either side is downstream of how much those two proofs are worth to you.

What double opt-in buys

  • A list that cannot contain junk. Typos, bots, and other people's addresses entered from malice or carelessness never make it in. Your bounce rate and spam-trap exposure drop to near zero at the door.
  • Evidence. A timestamped confirmation is the strongest consent record you can hold — for a provider dispute, a blocklist appeal, or a regulator. "They filled in a form" proves someone typed the address; the click proves it was them.
  • An engagement floor. Everyone on the list has already opened one of your emails and clicked it. That baseline propagates through every metric you will ever report.

What it costs

Real subscribers, in real numbers. Confirmation emails get ignored, land in spam, or arrive after the moment has passed — expect to lose a meaningful fraction of signups at the confirmation step, commonly cited in the 20–40% range and genuinely variable by audience.

The honest reframe: a fair share of the people lost at confirmation were never going to engage — an address that cannot be bothered to click once is not a subscriber, it is a liability with a timestamp. But not all of them; some real interest dies in the spam folder. The loss is real, merely smaller than the raw percentage implies.

A policy that takes both seriously

  • Double opt-in where the input is untrusted. Public forms, giveaways, lead magnets, anything incentivised — the places bots and fake addresses actually enter.
  • Single opt-in where identity is already proven. A paying customer or a product signup that already verified the address has given you the proof; a second confirmation is friction without information.
  • Validation either way. Syntax, DNS and typo-checking at the form catches gmial.com before it costs anything, whichever regime it feeds.
  • Make the confirmation email instant and plain. One sentence, one button, sent within seconds, from the name they just gave their address to. Every minute of delay costs confirmations.

Common questions

Is double opt-in legally required?

In most places, no — but consent rules differ by jurisdiction, some regulators treat confirmation as the expected standard of proof, and this is not legal advice. What is universally true: if consent is ever questioned, the confirmation click is the record you will wish you had.

Does double opt-in hurt list growth?

It shrinks the number of addresses collected, yes. It grows the number of subscribers who open, click and buy — which is the thing the list was for.

What about the confirmations that land in spam?

Send them from a warmed, authenticated transactional stream, instantly, with no marketing content — and tell people on the form's thank-you page to check their inbox. That combination recovers most of the losses.

Check your addresses now

The free InkPigeon checker runs syntax, DNS, disposable, typo and role-account analysis on any address — instantly, no signup.

Keep reading