Skip to content
Compliance

Email consent and double opt-in

Consent is the legal and practical foundation of sending. What GDPR and CAN-SPAM actually require, how double opt-in proves it, and where single opt-in is defensible.

Consent is the answer to the only question that ultimately matters in email: did this person ask for this mail? The law asks it, mailbox providers measure its absence through complaints and traps, and double opt-in is the mechanism that answers it with evidence. A subscriber enters their address, receives a confirmation message, and clicks to confirm; only then does the address join the list. The unconfirmed simply never enter, and with them go the typos, the bots, and the enemies who signed someone else up.

What the law actually requires

GDPR (with the ePrivacy rules alongside) requires consent for marketing mail to EU recipients that is freely given, specific, informed, and unambiguous, and, critically, demonstrable: the sender must be able to prove who consented, when, and to what. Double opt-in is not literally mandated by the GDPR text, but German case law and supervisory authorities treat it as the standard of proof, which for anyone mailing German or Austrian audiences makes it effectively required. CAN-SPAM in the US takes the opposite architecture: no prior consent needed, but honest headers, a physical address, a visible opt-out honored within 10 business days, and no mailing after opt-out. Canada's CASL sits closer to GDPR, requiring express or implied consent with records.

The deliverability case, independent of law

Confirmation typically costs 20 to 30 percent of raw signups, and most of what it removes is not people: typo domains that feed typo traps, bot submissions, and addresses entered by someone other than their owner, the population that later becomes bounces and complaints. The confirmed list starts every reputation metric ahead: lower complaint rates because everyone provably asked, lower bounce rates because every address provably works, and engagement rates unburdened by dead weight. A smaller list of people who completed two deliberate steps outperforms a larger unconfirmed one on essentially every metric that reaches revenue.

Making confirmation convert

A confirmation flow that loses fewer real subscribers

  1. 1

    Send the confirmation instantly

    Seconds matter: the subscriber is at their inbox now. A confirmation arriving minutes later lands after attention moved on.

  2. 2

    Make the message unmistakable

    Clear sender name, a subject like "Confirm your subscription", one prominent button, nothing else competing. This is transactional mail; treat it that way.

  3. 3

    Set expectations on the form and the thank-you page

    Tell people a confirmation is coming and to check spam if needed. The instruction measurably lifts completion.

  4. 4

    Authenticate the confirmation stream flawlessly

    A confirmation mail in the spam folder is a lost subscriber; this stream deserves your best deliverability, not your marketing pool.

  5. 5

    Expire the unconfirmed

    Addresses that never confirm get one reminder at most, then deletion. They are not a segment; they are noise with a retention policy.

Where single opt-in is defensible

Contexts where the address is already verified upstream, an account signup that required email verification, a paid customer relationship, narrow the case for a second confirmation, and US-only consumer brands under CAN-SPAM face no legal push. The trade being made should be named honestly: single opt-in accepts typo traps, bots, and forged signups into the database in exchange for the 20 to 30 percent, and then leans on hygiene and validation to manage what confirmation would have excluded. For EU audiences, for any list that partners or imports feed, and for anyone who has met a spam trap before, confirmed opt-in remains the default that needs no defending.

Frequently asked questions

Is double opt-in legally required under GDPR?
The regulation requires demonstrable consent rather than a specific mechanism, but German and Austrian enforcement practice treats confirmed opt-in as the proof standard. Mailing DACH audiences without it is a documented legal risk.
Does the confirmation email itself need consent?
A single confirmation message to complete a subscription the person initiated is broadly accepted as legitimate, provided it contains no marketing. Repeated reminders to unconfirmed addresses drift into exactly the territory the rules exist for.
Should I re-confirm an old list I am unsure about?
A re-permission campaign (one message asking recipients to confirm continued interest, silence means removal) is the standard rescue for lists with murky provenance, and the honest accounting is that most of the list was already gone; the campaign just makes it official and safe.
Do purchased lists become compliant if recipients confirm?
The confirmation request itself is unsolicited mail to people who never asked, which violates the consent rules it tries to satisfy and lights up the traps seeded in purchased data. There is no compliant path through a bought list.

Key takeaways

  • Consent is the foundation the law demands and providers measure; double opt-in is the mechanism that proves it
  • GDPR wants demonstrable consent with records, CAN-SPAM wants honest mail and honored opt-outs, CASL sits between
  • Confirmation filters typos, bots, and forged signups, buying lower complaints and bounces for a 20 to 30 percent signup cost
  • Treat the confirmation message as top-priority transactional mail and expire whoever never clicks
  • Single opt-in is defensible where addresses are verified upstream; purchased lists are compliant nowhere
Double opt-in and email consent: GDPR and CAN-SPAM | Inbox Theory