What is double opt-in?

Double opt-in, defined
Double opt-in requires a subscriber to confirm a signup by clicking a link in an email sent to the address they entered, proving both that the mailbox exists and that its owner wanted the mail.

The confirmation click is the only evidence that reaches past what any technical check can establish. Verification tells you a mailbox accepts mail. A click tells you a person is reading it and asked for more.

It is the single strongest defense against spam traps, and the reason is mechanical: a trap address cannot click. Whoever planted it is not confirming your subscription.

Under GDPR the confirmation record is also your evidence. A timestamp, an IP and the wording shown at signup turn consent from an assertion into something you can produce.

The confirmation mail has to arrive and be obvious. Send it within seconds, put the link above the fold, and make the subject line say what it is, or you lose real people to an unread inbox.

How ZapBounce reports it

Consent is invisible to an SMTP probe, and we never imply otherwise. A verified address on a single opt-in list is a reachable mailbox whose owner may have no idea who you are, and our results say nothing about which.

Where the missing 260 signups went

Suppose 1,000 people fill in your form this month and 740 click the confirmation link. It's tempting to read the other 260 as lost subscribers. Break them down first. In a plausible mix, 45 mistyped their address, so the confirmation bounced or reached a stranger. Another 90 were scripts. Some 25 used a throwaway mailbox to grab the download.

That leaves about 100 real people who saw the email and didn't click, or never saw it because it landed in spam. This group is the true cost, and it's also the part you can shrink with a faster, clearer confirmation message.

Compare the two lists a quarter later. The single opt-in version has 1,000 rows, a few dozen hard bounces and some recipients who never asked to be there. Your confirmed version has 740 rows, and every one of them has already opened an email from you once.

The attack that confirmation quietly blocks

Subscription bombing is a harassment technique. Someone runs a script that enters a victim's address into thousands of newsletter forms, burying their inbox so they miss a fraud alert or a password reset. Your form becomes one of the weapons, and you don't find out.

With single opt-in, you then mail that victim every week until they report you. When the form is confirmed, they get one message from you, don't click it, and never hear from you again. Blocklist operators have listed sending platforms over this exact pattern, which is a large part of why the platforms push confirmation.

Verification at the form still earns its place beside the click. A confirmation email sent to a mistyped address is a bounce against your domain, and it arrives on your transactional stream, which you least want damaged. Catching the typo while the visitor is still on the page lets them fix it, and a person who fixes a typo goes on to confirm.

Double opt-in: common questions

How many subscribers does double opt-in cost?

Commonly 20 to 30 percent of raw signups. Most of that is typos, bots and abandoned intent rather than people you would have kept.

Does verification replace double opt-in?

No. Verification checks whether a mailbox exists. Confirmation checks whether its owner wants your mail. Only one of those is consent.

Is double opt-in required by GDPR?

The regulation demands demonstrable consent rather than a specific mechanism. A confirmation click is the cleanest way to demonstrate it.

See this on your own list

100 free checks a month, and the unknowns come back labeled.