Guide
Single vs double opt-in: which to choose and what it costs
Last reviewed 19 September 2026
Single opt-in puts an address on a list the moment a form is submitted. Double opt-in, properly called confirmed opt-in, puts it there only after somebody clicks a link in one confirmation email. Double opt-in loses a fifth to a third of sign-ups and removes almost every address that was never going to read anything, which makes it the right default for a sender with no reputation to spend. Single opt-in is defensible only where a bad address is cheap and rare.
This is the decision almost every new sender meets first, usually as a toggle in a settings page with no explanation next to it, and the advice available on it is unusually bad in both directions: one side treats a confirmation step as a legal obligation it is not, and the other treats it as a tax on growth. Both are wrong in the same way. It is a trade, the terms of the trade are knowable, and which side of it you should be on depends on a small number of facts about your own situation rather than on a principle.
What the two actually do differently
Single opt-in: an address is typed into a form and starts receiving mail. Double opt-in: an address is typed into a form, receives exactly one message asking whether it really was them, and starts receiving mail only if the link in that message is clicked. Everything downstream — the welcome message, the preferences page, the tagging, the unsubscribe — is identical. The whole of the difference is one email and one click.
The name is a misnomer and it has done real damage, because “double” makes it sound like a second form or a second act of typing. It is neither. From the reader’s side it is one extra click, in a message they were expecting, within seconds of asking for it. The industry term is confirmed opt-in, which describes the mechanism accurately, and the guide on it in this cluster takes the mechanism apart in full.
One consequence is worth stating plainly, because it is what makes the promise mean anything: under double opt-in an address that never confirms receives exactly one message, ever, and then nothing. That is not a setting to be softened with reminders every few days. A confirmation step that keeps mailing the unconfirmed is single opt-in with extra steps.
The case for single opt-in, stated properly
There is a real argument, and dismissing it is how the other side of this debate lost people’s trust. Every extra step in a funnel loses some of the people in it, and this one is measurable: the sign-ups that never complete a confirmation are people who did ask for the thing. Some of them meant it. A confirmation email that landed in Promotions, or arrived looking like a phishing attempt, or said “Confirm your subscription” without naming what was being subscribed to, loses readers for reasons that have nothing to do with intent.
The argument is strongest in three situations. Where the address was not typed at all but came from a transaction you can already verify — somebody who bought something, booked something, or signed into an account — a confirmation click proves nothing you do not already know. Where the list is tiny and every address arrived from somebody you can name, the failure modes a confirmation step catches barely exist. And where the mail is transactional rather than promotional, the reader is expecting it and did not subscribe to anything.
What the argument is not is an argument about growth. “Double opt-in costs me subscribers” is true and beside the point unless the subscribers it costs were going to read something. The honest version of the single opt-in case is narrower and much stronger: in my situation a bad address is rare, and when one gets in it is cheap to discover. If both halves of that are true, single opt-in is a reasonable choice. If either is false, it is the expensive one.
The case for double opt-in, which is not mainly about consent
The usual argument for a confirmation step is consent, and it is a good argument that undersells the mechanism. The concrete problem is that a form accepts any string shaped like an address, and a meaningful share of what arrives is not the person at the keyboard. Typos are the largest category, and they are unrecoverable: one transposed character and you are mailing a stranger indefinitely with no way to find out. Then there are addresses typed by somebody who wanted the download but not the mail, a colleague’s address, and — at any scale at all — form submissions that are not human.
To a mailbox provider, every one of those is indistinguishable from you having bought a list. They bounce, or they sit and never engage, or they report the mail as spam, and all three are measured against your domain. A confirmation link removes almost all of them before any of it counts, because none of those categories clicks a link. That is the argument in one sentence, and it is an operational argument rather than an ethical one.
The quieter benefit is evidentiary. A confirmation click is a timestamped act by whoever reads that mailbox. When somebody insists a year later that they never signed up, that record is the only thing that settles it, and a form submission is not a substitute: it proves a browser sent you a string. The guide on the GDPR in this cluster deals with what a consent record has to contain; what matters here is that one of these two options generates the record as a side effect and the other requires you to build it.
| What differs | Single opt-in | Double opt-in |
|---|---|---|
| Which addresses reach the list | Every string the form accepted, typos, borrowed addresses and non-human submissions included | Only addresses whose owner clicked a link in one message |
| How many sign-ups survive to the list | All of them | A fifth to a third fewer, and almost all of the loss sits in addresses that would never have read anything |
| What you hold if consent is disputed | A form submission, which proves a browser sent you a string | A timestamped click by whoever reads that mailbox |
| Exposure to a spam trap | Full, because a trap address that was typed or harvested is mailed like any other | Near zero, because a trap does not click a confirmation link |
| Where a mistake becomes visible | In a complaint rate weeks later, which nothing reports to you | At the confirmation step, the same day, as a sign-up that did not complete |
| What the mistake costs to undo | A domain reputation rebuilt over weeks, on the domain that also carries your invoices | Nothing — the addresses you did not get were addresses you could not have used |
The three facts that decide it for you
The choice is not a values position, and treating it as one is why the argument has run for twenty years without converging. It comes down to three questions about your own situation, all of which you can answer today.
First: how much does one wrong address cost? If your mail goes out once and is never repeated, a wrong address is one unwanted message. If it is a sequence, the same wrong address receives a week of unwanted mail from a sender the reader does not recognise, which is the exact profile of a complaint. Second: would you find out? A form submission you cannot verify produces a silent failure — the mail is accepted, filed into spam, and counted as delivered — so the answer is usually no, and not for months. Third: whose domain is carrying it? A reputation is built on the domain in your signature, and on a small sender that domain is frequently the same one that carries invoices and password resets. A subdomain can be retired in an afternoon. A root domain cannot.
This site takes a side on the back of those three, and says so rather than presenting a balanced view it does not hold: confirm every address, on every route onto the list, with no toggle. The condition under which that is wrong is a sender whose addresses arrive already verified by a transaction, and for that sender the confirmation step is genuinely redundant. Everybody else is choosing between a smaller list that arrives and a larger one that gradually does not, and the second failure is invisible while it is happening.
Where the single opt-in case actually holds, and where it only looks like it does:
- It holds for an address that came from a completed purchase, a booking or an account sign-in, because the transaction verified it more strongly than a click would.
- It holds for transactional mail — a receipt, a password reset, a shipping notice — which nobody subscribed to and nobody expects to be asked about.
- It does not hold because a form has a consent checkbox on it. A checkbox records what the submitter claimed, not who owns the address.
- It does not hold because the sign-ups are “high intent”. Intent is exactly what a mistyped address also has, and the typo is the largest category of bad address there is.
- It does not hold because the list is imported from somewhere reputable. An import is the route onto a list that most often skips a confirmation step the sign-up form enforces.
What the confirmation step really costs, and how much of it is avoidable
Somewhere between a fifth and a third of people who submit a form never click the confirmation. Anyone quoting a smaller number is describing their own audience rather than yours. That is a real cost and it should be stated plainly rather than argued away, because it is the entire reason single opt-in persists.
The part worth working on is that most of the loss is not refusal. It is a confirmation email that arrived looking like nothing in particular. The message has one job and every additional element lowers the click rate on the only thing that matters in it: name the specific thing they asked for rather than “our newsletter”, say in one sentence what arrives after the click and when, give one obvious link with the same URL as plain text underneath, and put nothing else in it at all. The companion guide with a confirmation email written out in full is the place that does this properly.
The cost that is genuinely fixed is the delay, and it is smaller than it looks. A reader who confirms does so within seconds, because they are still on the page they signed up from. What that buys is that the first real message arrives to somebody demonstrably paying attention, which is the best engagement signal you will ever generate on a new address.
Switching a list that already exists
Turning confirmation on is the easy half: from that moment, new addresses confirm. The awkward question is the addresses already on the list, which arrived under the old rule, and the wrong answer is to mail all of them a confirmation request and delete whoever does not click. That is a re-permission campaign, it is a large send to an unengaged list, and it is one of the most reliable ways to damage a sending reputation in a single afternoon.
The proportionate version is to leave the existing list alone and treat engagement as the filter instead. Addresses that click or reply are confirmed by behaviour more strongly than by a form. Addresses that have shown nothing for months are the ones to stop mailing, on a sunset window that applies automatically rather than when you remember. If you do decide to ask for re-permission, send it in small batches to the most recently engaged first, watch the complaint rate between batches, and stop if it moves.
The step that matters more than either is auditing the routes onto the list rather than the setting on the form. A tool that enforces confirmation on its own sign-up page will frequently take an unconfirmed address through an import, an API call, an integration with a shop, or a second form somebody built two years ago. A confirmation step that one route skips is not a confirmation step; it is a default.
What the law says, which is less than both sides claim
Neither the GDPR nor the American CAN-SPAM Act names double opt-in. The GDPR requires that consent be freely given, specific, informed and unambiguous, and that you be able to demonstrate it; it prescribes no mechanism, and a confirmation click is the cheapest and most durable way to satisfy the demonstration part rather than a requirement in itself. CAN-SPAM requires no opt-in at all — it governs how you mail people, not how you acquired them.
Some jurisdictions are stricter. Canada’s anti-spam law requires express or implied consent with records to back it, and the penalties are not theoretical. If you publish in English you have readers in more than one country, so the workable answer is to run the strictest version everywhere rather than maintain several lists under several rules. The guides on the GDPR and on CAN-SPAM in this cluster go through both properly; what matters for this decision is that nobody is choosing between legal and illegal here, which is why the argument has to be made on the operational grounds above.
Common questions
What is the difference between single and double opt-in?
Under single opt-in an address joins the list the moment a form is submitted. Under double opt-in it joins only after somebody clicks a link in one confirmation email, and an address that never clicks receives exactly that one message and nothing else. Everything after the join — the welcome message, the tagging, the unsubscribe — is identical. The whole of the difference is one email and one click, which is why the industry calls it confirmed opt-in rather than double.
Is single opt-in ever the right choice?
Yes, in two situations. Where the address arrived through a completed transaction — a purchase, a booking, an account sign-in — it has already been verified more strongly than a click would verify it. And where the mail is transactional rather than promotional, nobody subscribed and nobody expects to be asked. Outside those, single opt-in is a bet that a wrong address is rare and that you would find out, and on a list built from a public form neither half is usually true.
How many sign-ups does double opt-in cost?
A fifth to a third of the people who submit a form never confirm, and anyone quoting a smaller figure is describing their own audience rather than yours. Most of that loss is not refusal, though: it is a confirmation email that landed in Promotions or arrived without naming the thing it was confirming. The share that survives is concentrated in exactly the addresses worth having, which is why a smaller confirmed list usually out-performs a larger unconfirmed one.
Can I switch an existing list from single to double opt-in?
Turn confirmation on for new sign-ups and leave the existing list alone. Mailing everyone a confirmation request is a large send to an unengaged list and is one of the quickest ways to damage a sending domain. Let engagement be the filter instead — a click or a reply confirms an address more strongly than a form does — and sunset the addresses that have shown nothing for months. Then audit every route onto the list, because imports and integrations routinely skip the step the form enforces.
Which opt-in method do mailbox providers prefer?
They do not publish a preference, and it is worth being precise about that: what Google and Yahoo publish are authentication requirements and a spam complaint threshold, not a rule about how you collect addresses. The preference is implied rather than stated. Complaints come overwhelmingly from people who do not recognise the sender, and the surest way to be unrecognised is to have been added to a list by a typo or by somebody else, so a confirmed list sits below the threshold almost by construction.
If a bad address in your list is rare and cheap, single opt-in is a reasonable choice and you should make it deliberately rather than by leaving a toggle alone. For everybody else the trade is a fifth to a third of sign-ups against a list where every address was reachable and wanted the mail, and that trade is worth taking every time — then spend the effort you saved arguing about it on the confirmation email, which is where most of the loss actually is.
Sources
Read next
This page is part of Email deliverability for small senders: what decides it, which is the complete guide to the subject.
- Email deliverability for small senders: what decides it
What deliverability is, how SPF, DKIM and DMARC fit together, and what the Google and Yahoo bulk sender rules require of a small sender.
- Gmail and Yahoo bulk sender requirements: the 2024 rules
The Gmail and Yahoo bulk sender requirements in force since February 2024: who counts as a bulk sender, what each rule asks, and how to check you meet it.
- Confirmed opt-in (double opt-in): what it costs and buys
What double opt-in (confirmed opt-in) is, what it costs you in list size, and why the mailbox providers have settled the argument.
- Confirmation email template for double opt-in
Three confirmation emails written out in full: plain, warm, and re-permission for an imported list, with the reasoning for every line.
- How to set up SPF, DKIM and DMARC for a sending domain
The order to do it in: a dedicated sending subdomain, SPF, DKIM, DMARC at p=none, two weeks of reports, then quarantine and reject.
- GDPR and email courses: consent, records, and erasure
What the GDPR text actually requires for an email list: consent under Art. 4(11), the burden of proof in Art. 7(1), erasure under Art. 17.
- CAN-SPAM for course senders: the footer checklist
The seven CAN-SPAM requirements from the FTC compliance guide, what they mean for an email course, and how the law differs from GDPR and CASL.
- Unsubscribe requirements: one-click and List-Unsubscribe
What one-click unsubscribe requires under RFC 8058, the two-day honouring window in the Google and Yahoo rules, and what the endpoint must return.
These guides are about the format rather than about any particular tool. What this site itself does is on the home page, and the rest of the set is on the guides index .
Elsewhere on this site
The rest of this site comes at the same subject from other directions: guides on the format itself, a tool for one job each, a page for each kind of work, what to check when choosing software, a course written out in full, the courses people have actually published here, and one definition or figure at a time.
Free tool
DMARC, SPF and DKIM checkerBy the work you do
Email courses for therapists and wellbeing practitionersChoosing software
Email course software, tool by toolDefinition
DMARCDefinition
Suppression list
Thinking of writing one of these?
5dayemail hosts a five-to-ten day email course: you write it once, and everyone who joins your list gets one email a day, in order, starting from the day they confirm.
Accounts are opened a few at a time rather than by signing up. Leave your address and you will be written to when the next ones open.
One message, when there is room. No course emails, no newsletter, and the address is not passed on. Ask and it is deleted; what is kept, and for how long, is in the privacy policy.