MAILCRAFT
Home Features Pricing About Blog Contact Log in Get Started →
List management

Double opt-in: cost, benefit and when it is necessary

Smartfon z logo Gmaila na drewnianym blacie

Double opt-in is consent confirmed in a second step: the address joins the list only once the recipient clicks a link in a confirmation email. No extra form, no survey at signup. It is about one piece of proof: this mailbox exists and somebody controls it. With single opt-in the address lands in the database right after the form is submitted, with no verification. A detail? On paper, yes. And it decides how your domain looks to the large mailbox providers.

What double opt-in is and how it differs from single opt-in

Technically, a few things happen between the steps. The record is saved in a pending state. The system generates a confirmation token with an expiry date and ties it to the address. Along with it, it stores the date, the time, the IP address of the person signing up and the wording of the clause that person saw. The click on the link switches the state to confirmed and closes the evidence set. Without a click the record expires and should not go into any send. None.

And one more distinction people trip over regularly. Confirmed opt-in means active confirmation by the recipient. A welcome message with no confirmation link is still single opt-in, just better dressed. Nobody confirmed anything, so the proof stays one-sided.

The subject keeps coming back because the way senders are judged has changed. Filters look at recipient behaviour: opens, replies, moves to spam, deletion without reading. Declarations in the footer interest nobody. What counts is whether the people on your list react like people who signed up deliberately.

Cost: what the second step really takes from you

Some signups will not confirm consent. The list grows slower and that is the whole cost, described honestly. I will not give you a percentage, because it depends on the traffic source, the industry and the quality of the confirmation email – any invented number would be a fiction.

The losses come from several places. The confirmation email falls into the Promotions tab or into spam. Somebody signs up on a phone while queuing at the till and never goes back to the mailbox. There is a typo in the address, so the confirmation physically has nowhere to arrive. That last case actually works in your favour, more on that in a moment.

There is the implementation cost on top. You need a thank-you page after signup, a separate confirmation page, handling for an expired token and a simple path to resend the link. A few views and a bit of logic, not a project for a whole quarter. With sales leads there is also a delay: the rep calls later, because they are waiting for the confirmation.

The second step hurts most in these scenarios:

  • campaigns with paid traffic, where you pay for every signup up front,
  • contests and prize draws with a short time window,
  • signups at the till in a physical shop,
  • mobile forms, where switching to the mail app breaks the context.

Benefit: sender reputation, bounce and complaints

Confirmation sifts out typos and mailboxes that do not exist. The bounce happens on one email to one address, not on the first campaign to the entire database. Bounce drops before it has time to do harm. The same effect can be had earlier, before the signup, by checking that the address is correct without sending a message.

This matters, because hard bounces and complaints are the signals that make the large providers tighten delivery. First the messages land in spam, then throttling appears, at the end a block. Getting out of that takes weeks and requires cutting volume, cleaning the database and patience. Keeping the signals low is simply cheaper.

Spam traps do not pass the confirmation step either. Nobody clicks on an address copied from somebody else’s database, scraped off a website or inherited from a previous agency, because there is no human behind it. Double opt-in cuts them out automatically, with no manual audit.

From our practice warming up new IPs and domains: a list with confirmed consent behaves predictably. Opens and clicks come from people who remember the moment they signed up, so the warmup curve does not jump. With a database without confirmations, every larger batch is a lottery.

No promises: double opt-in does not bypass filters and does not guarantee the inbox. It improves the quality of the signals the filters measure. That is all. And that is quite enough.

When double opt-in is necessary

There are situations where the second step stops being a choice:

  1. a new domain or new IP in the warmup phase, where you have no history yet,
  2. traffic from ads and contests, meaning signups motivated by a prize, not by content,
  3. forms with no protection against bots,
  4. an import of a database of uncertain origin, including after taking over a project,
  5. sending to markets with stricter practice, German-speaking countries in particular,
  6. sensitive industries: finance, health, anything with higher-risk data.

Single opt-in with decent hygiene is enough when you control the source. A closed base of customers who bought and gave their address in the order. A panel with a login, where the address serves for authentication. Signups verified some other way, for example with an SMS code or a transaction confirmation.

The practical rule is simple: the less you control the source of the address, the stronger the proof of consent you need.

Tip: if you are starting from a new domain, treat double opt-in as part of the warmup, not as a lifetime restriction. Once the reputation is stable you can revisit the decision for selected, well controlled signup sources.

Consent and the law: GDPR and PKE article 398

GDPR requires you to demonstrate consent, not merely to hold it. The difference is practical: during an inspection or after a complaint you have to show the proof. A timestamp, an IP address, the exact wording of the clause and the version of the form the person signing up saw. The sentence “we had a checkbox” is not proof.

The Electronic Communications Law, article 398, covers consent to marketing communication and applies to B2B contacts as well. A company address does not release you from asking for consent. I repeat it at every training session for sales departments, because work mailboxes are still taken for territory without rules.

The law does not impose double opt-in outright. But in practice it is the easiest proof to defend: a click on a link from a specific address, at a specific time, tied to the saved record. Hard to challenge.

Consent itself has to be separated from the terms of service and the privacy policy. It has to be written so it can be understood, without three consents crammed into one sentence. And it has to be as easy to withdraw as it was to give – an unsubscribe link in every message, working immediately. A refusal also has to leave a permanent trace, so that the same address does not come back into the next send.

Compliance as a property of the infrastructure

We treat this as part of the product, not a note at the end. The sending infrastructure and the data sit in Poland, on our servers. The list does not travel outside the sender’s control and does not pass through intermediaries you would have to declare in your record of processing activities.

How to implement double opt-in without losing signups needlessly

Send the confirmation email immediately after signup. The subject line has to say plainly what it is about. Inside, one clear link and nothing besides: no graphics, no banners, no starter offer, no three buttons to social media. A light text message gets through better and gives the recipient no reason to hesitate.

Before you send anything, authenticate the sender. SPF, DKIM and DMARC are the minimum. On top of that a correct Return-Path in the same domain and a PTR record for the sending address. The confirmation email goes through exactly the same filters as a campaign – if it does not arrive, the whole mechanism loses its point.

The page after signup should say specifically what to look for: from which sender, with what subject line. Add a reminder about the Promotions tab and the spam folder. Set the token to a sensible expiry and give a simple path to resend the link, with no login and no contact with support.

One reminder after a day is enough. Then stop. Carrying on sending campaigns to unconfirmed addresses cancels the whole construction and comes back to you as complaints.

Signup forms, automation of the confirmation email and managing the state of the record are standard elements of the sending platform’s features, so you do not have to build the second step from scratch on your own back end.

Tip: measure the deliverability of the confirmation message and the confirmation rate separately. A drop in confirmations almost always starts with a delivery problem, not with the wording of the email. If you watch only one metric, you will be rewriting copy instead of fixing DNS records.

This whole mechanism is easier to maintain when the sending and the data stand in one place. Our email marketing platform with its own sending servers was built for exactly that: control over IP reputation instead of sharing a pool with unknown senders.

What to do with a list built without confirmation

Do not send to the whole database at once from a new IP. That is the shortest road to a block and the most common mistake when migrating from a previous provider. I have seen it a dozen or so times.

Run a reactivation campaign instead, asking for consent to be confirmed. Send in batches, starting with the most active segments: recent orders, recent clicks, fresh signups. Those addresses will give good signals and build history before you move into the older layers of the database.

Clean up technically before you send. Remove duplicates, role addresses of the office@ or contact@ kind, obvious typos in the domains of popular providers. A dozen or so minutes of work that saves weeks of rebuilding reputation.

Unsubscribe the addresses that stay silent after reactivation. Keeping them costs twice over: it drags down engagement rates and inflates the bill for a database nobody reads. With billing that depends on database size you see it straight away in the monthly cost of sending.

Honestly about the limits: some list hygiene steps are handled manually today, or by exporting to a spreadsheet. Automated cleaning is on our roadmap, but it is not there yet and I am not going to pretend it is.

Summary: when the second step is worth paying for

Double opt-in costs you part of your signups. It pays back with lower bounce, fewer complaints and predictable sender reputation. That is an exchange, not a loss.

The decision depends on two things: where the addresses come from and how old your sending infrastructure is. Not on what the competition happens to be doing.

Turn it on by default with a new domain, with paid traffic and with databases of uncertain origin. Consider single opt-in only when you have full control over the signup source and can prove it.

Whatever you choose, three things stay compulsory: proof of consent with a full set of metadata, sender authentication at the DNS level and regular list cleaning. Without them even the best designed signup will not save deliverability.