Double opt-in
Double opt-in is a subscription method where a new subscriber must confirm their email address by clicking a link in a confirmation message before being added to your list. It proves the address is valid and that the person genuinely consented, producing a cleaner, more engaged and more compliant list than single opt-in.
How it works
After someone submits a signup form (the first opt-in), the system sends a confirmation email; only when they click its verification link (the second opt-in) are they added as an active subscriber. Unconfirmed addresses are never mailed.
Why it matters
Double opt-in filters out typos, fake addresses and bots, which lowers bounces and spam-trap risk. It also creates a clear consent record that helps satisfy stricter privacy regimes like GDPR — at the cost of a slightly smaller list.
What should a double opt-in confirmation email contain?
One clear action and enough context to recognise it. The sender name should match the brand on the form, the subject should say what is being confirmed, and the body should repeat what the person signed up for and how often they will hear from you. A single prominent confirmation button, with the same link in plain text beneath it, covers readers whose client blocks buttons.
Send it the moment the form is submitted, while the person is still thinking about it. Leave out extra promotions and links to other pages; every additional element competes with the one click that matters. If no confirmation arrives after a day, one reminder is reasonable, and after that the address should be dropped rather than mailed again. Keep the confirmation link valid for a reasonable window, such as a few days, so a person who opens it late is not met with an error page.
How do you measure what confirmation costs you?
Track the confirmation rate: confirmed addresses divided by form submissions over the same period. In a hypothetical month with 1,000 submissions and 720 confirmations, the rate is 72%, and the 280 missing are some mix of typos, bots and people who never saw the email.
Watch the trend more than the number. A sudden fall usually means the confirmation email itself is landing in spam or failing to send, so test it the same way you would test a campaign, including its SPF, DKIM and DMARC results. The confirmation message is often the least-monitored email a company sends.
Which consent details should be recorded for each subscriber?
Enough to show later who agreed to what, and when. A typical record holds the submission timestamp, the page or form it came from, the exact consent wording shown at the time, the confirmation timestamp, and the IP address or other technical details your privacy notice covers. GDPR requires a controller to be able to demonstrate that consent was given, and a stored confirmation record is one practical way to do that. What your organisation must keep, and for how long, is a question for counsel; our overview of GDPR for email outreach explains the wider framework.
Does double opt-in have any role in cold outreach?
Not in the first message. Cold prospects have not filled in a form, so there is nothing to confirm, and B2B cold email relies on other rules such as honest headers and a working opt-out under the CAN-SPAM Act. Double opt-in matters where cold outreach turns into marketing: a prospect who asks for a guide or a newsletter should be confirmed before joining that list. Confirmed sign-ups also keep typo addresses out, which is one of the ways a spam trap enters a list. Autocloz records opt-in consent with an auditable trail and honours opt-outs on every channel.
How Autocloz handles it
Autocloz captures opt-in consent with an auditable record and honors opt-outs across every channel, so the permission trail behind a confirmed subscriber is preserved for compliance and deliverability.
FAQ
Is double opt-in required by law?
Not explicitly by most laws, but it is a strong way to demonstrate consent under GDPR and produces cleaner lists. Some regions and providers effectively expect it; it is best practice for marketing lists even where single opt-in is permitted.
Does double opt-in reduce list size?
Yes, somewhat — some people never confirm — but the subscribers you keep are validated and genuinely interested. The result is higher engagement, lower bounces and complaints, and better long-term deliverability than a larger unconfirmed list.
Related terms
Cold email deliverability is the share of your outbound cold emails that actually reach the recipient's inbox (not spam, not blocked). It depends on domain authentication (SPF, DKIM, DMARC), sender reputation, mailbox warmup, list hygiene and content — not just whether the email was 'sent'.
DMARC (Domain-based Message Authentication, Reporting & Conformance) is an email standard that tells receiving mail servers what to do with messages that fail SPF or DKIM checks — and sends you reports. It prevents spoofing of your domain and is now effectively required by Gmail and Yahoo for bulk senders.
SPF (Sender Policy Framework) is an email-authentication standard that lets a domain owner publish, in DNS, the list of mail servers allowed to send email on the domain's behalf. Receiving servers check the sending IP against that list to help detect spoofing and decide whether to trust the message.
DKIM (DomainKeys Identified Mail) is an email-authentication method that attaches a cryptographic signature to each message. The receiving server verifies the signature against a public key in the sender's DNS, proving the message wasn't altered in transit and genuinely came from the signing domain.