Single vs double opt-in: the honest trade-off (and what GDPR says)
Single opt-in: someone types their address into your form, they're subscribed. Double opt-in: they type their address, receive a confirmation email, and click it — then they're subscribed.
The debate over which to use is twenty years old and usually argued with vibes. Here's the actual trade-off.
What double opt-in costs you
Somewhere between 20% and 40% of signups never click the confirmation email. Some lose interest, some never see it (irony: confirmation emails can land in spam), some typed a fake address to grab your lead magnet — which, note, is not a loss at all.
If you measure success by list size, double opt-in looks expensive.
What it buys you
Everything downstream:
Zero typo addresses. gmial.com can't confirm. Your bounce rate thanks you.
No spam traps. Trap addresses don't click confirmation links. This alone removes a whole category of reputation risk.
Proof of consent. A timestamped confirmation click is evidence. "They filled a form once" is a claim.
Subscribers who meant it. Confirmed lists reliably show higher opens and — critically — lower spam complaints. The people most likely to hit "report spam" later are precisely the ones who wouldn't have confirmed.
A smaller list that engages is worth more than a bigger one that doesn't — not as a slogan, but mechanically: mailbox providers judge you on the ratio of wanted to unwanted mail, and unconfirmed signups sit heavily on the wrong side.
What the law says
GDPR does not literally mandate double opt-in. It requires consent that is freely given, specific, informed, unambiguous — and, crucially, demonstrable. You must be able to prove consent existed.
In practice, a confirmed opt-in with a stored timestamp is the gold-standard proof, which is why EU regulators consistently recommend it.
In Germany, treat it as mandatory. German courts have repeatedly treated unconfirmed marketing email as unlawful under competition law (the confirmation email itself is structured to be lawful to send). If you mail DACH audiences — some of the most privacy-conscious and complaint-ready recipients in the world — double opt-in isn't a best practice, it's table stakes. Austrian and Swiss expectations run close behind.
Nothing here is legal advice; talk to a lawyer for your specific situation. But the direction of travel across the EU is unambiguous.
Our recommendation
Default to double opt-in if any of these are true:
- You mail EU recipients at all (and especially DACH)
- You're building on a new domain and protecting a young reputation
- Your signups come from paid traffic or giveaways — the highest fake-address sources
The defensible case for single opt-in is narrow: low-risk audiences, checkout-adjacent signups where intent is obvious, and a tolerance for the extra hygiene work. If you run single opt-in, compensate: verify addresses at capture, mail new signups immediately while they remember you, and watch complaint rates like a hawk.
The bottom line
Double opt-in trades vanity for durability: a smaller number on your dashboard, and better deliverability, cleaner consent records, and calmer lawyers everywhere else. For EU-facing senders it's barely a decision anymore.