Skip to content

Double opt-in explained: why every subscriber we add confirms first

Double opt-in (DOI) means every new subscriber confirms their sign-up by email before they join your list. Here's how it works, why the GDPR and DSGVO make it the safe choice, and why we use it for every client.

Published 15 September 20265 min readBy Smart Marketing

The short version

  • Double opt-in means a new subscriber confirms their sign-up by clicking a link in an email before they're added.
  • It's the clearest way to prove that a person really asked to hear from you, which is what the GDPR (DSGVO) expects you to be able to show.
  • It keeps typos, fake sign-ups and addresses that belong to someone else off your list.
  • Your list grows a little more slowly, but the people on it tend to open, click and buy more.
  • We use double opt-in for every client, on every sign-up form, without exception.

Every sign-up form we build for a client works the same way. Someone enters their email address, and before they're added to the list, they get a short email asking them to confirm. Only when they click that link do they become a subscriber.

This is called double opt-in, often shortened to DOI. We use it for every client, every form, every time. Here's what it is, why it matters under the GDPR (the DSGVO in German-speaking countries), and why we don't make exceptions.

What double opt-in actually is

Double opt-in means a person says yes twice:

  1. They sign up. They type their email address into a form on your website, tick an empty consent box if one is needed, and submit.
  2. They confirm. A few seconds later, they get an email from you: "Please confirm your subscription." They click the button, and only then are they added to your list.

The alternative, single opt-in, skips the second step. The address goes straight onto the list as soon as the form is submitted.

That sounds like a small difference. It isn't.

Why single opt-in isn't enough

With single opt-in, you never know whether the person who typed an address actually owns it. Anyone can enter anyone's address into a form: by mistake, as a joke, or on purpose.

That leads to three problems:

  • Typos. "gmial.com" and "hotmial.com" are real mistakes that real people make. Those addresses bounce, and bounces damage your reputation with mailbox providers.
  • Sign-ups that aren't real. Spam bots and fake addresses find their way onto open forms. Some addresses exist purely to catch senders who don't check who they're mailing, and hitting them can push all your email into spam.
  • People who never asked. If someone enters a friend's or colleague's address, that person receives marketing email they never agreed to. They're likely to report it as spam, and you can't show that they ever consented.

Double opt-in solves all three at once, because the link can only be clicked by someone with access to that inbox.

What the GDPR and DSGVO expect

EU rules on marketing email (in Austria the Telecommunications Act, in Germany the Unfair Competition Act) say you need a person's permission before you email them marketing, with a narrow exception for existing customers. The GDPR sets out what that permission has to look like: freely given, specific, informed and unambiguous. Just as importantly, it puts the burden of proof on you: if a subscriber, a customer or a data protection authority asks, you need to be able to show that this particular person agreed.

The GDPR doesn't mention double opt-in by name. But in practice it's the most reliable way to meet that burden of proof. In Germany and Austria in particular, double opt-in is widely treated as the standard, and relying on single opt-in leaves you with little to show if a sign-up is ever questioned.

A confirmed sign-up gives you a clear record:

  • When the person signed up, and on which form
  • What they agreed to receive
  • When they confirmed, from the email address itself

That record is what turns "we think they signed up" into "here's the proof."

Consent you can't prove is, for practical purposes, consent you don't have.

What a good confirmation email looks like

The confirmation email has one job: getting the person to click. A good one is:

  • Sent instantly. People confirm while the sign-up is fresh in their mind. Minutes of delay cost confirmations.
  • Clearly from you. Your business name as the sender, and a subject like "Please confirm your subscription to [your business]."
  • Short and plain. One sentence explaining why they're getting it, one clear button, and a note that they can ignore the email if they didn't sign up.
  • Free of advertising. No offers, no product pictures, no newsletter content, no slogans. The confirmation email isn't a marketing email yet, and promotions inside it can be treated as advertising without consent. A German court has even treated a logo and a "welcome" message as advertising, so keep it to the request, the link and your business details. Keep the discount for the welcome email that follows.

After the click, send people to a simple thank-you page on your website, then follow with that welcome email.

"But won't I lose subscribers?"

A small share of people never click, and yes, your list grows a little more slowly than it would with single opt-in.

What you lose is mostly addresses that were never going to be worth anything: typos, fakes, and people who didn't really want your email. What you keep is a list of people who took an extra step to hear from you. Those people tend to open more, click more and complain less. That's exactly the kind of list that reaches the inbox, and why a clean list beats a big one.

Double opt-in and the new tracking rules

Consent to receive email and consent to having your opens measured are two separate things under EU rules. France and Italy published detailed rules on this in 2026, which we cover in detail in our article on email open tracking and consent.

A properly built sign-up form handles both at once: a clear choice about receiving your emails, a separate clear choice about open tracking, and double opt-in to confirm it all.

How we handle it

Double opt-in is not an option you have to ask us for. It's how every sign-up works for our clients:

  • Every form confirms first. Nobody joins a client's list without clicking the confirmation link.
  • Consent is recorded. We keep when, where and how each person signed up and confirmed, so you can prove it if you're ever asked.
  • Confirmation emails are plain and fast. Sent immediately, clearly from your business, with nothing in them but the request to confirm.
  • Unconfirmed sign-ups are cleaned out. They never receive marketing email and don't sit on your list.

If your current forms add people without confirmation, or you're not sure how your existing subscribers joined, that's worth looking at together. Book a free call and we'll check where your list stands.

This article is a practical overview, not legal advice. For decisions about your specific situation, speak to a lawyer or your data protection authority.

Frequently asked questions

What does DOI stand for?

DOI stands for double opt-in. In German it's usually written Double-Opt-In. The person opts in twice: once by signing up, and a second time by confirming through a link sent to their inbox.

Is double opt-in required by the GDPR?

The GDPR doesn't name double opt-in as a legal requirement. It does require you to be able to prove that each person consented. Double opt-in is the most reliable way to do that, which is why it's treated as the standard in Germany and Austria in particular.

What's the difference between single and double opt-in?

With single opt-in, an address is added the moment someone submits a form. With double opt-in, it's only added after the owner of that address clicks a confirmation link. Single opt-in can't tell whether the person who typed the address is the person who owns it.

Can the confirmation email include a discount or advertising?

Keep it plain. The confirmation email should only ask the person to confirm their sign-up. Adding promotions to it can itself be treated as advertising sent without consent, and a German court has even counted a logo and a welcome slogan as advertising. Save the welcome offer for the email that follows confirmation.

What happens to people who never click the confirmation link?

They're not added to your marketing list, and you shouldn't send them marketing emails. Courts have only looked at the first confirmation email, so sending reminders carries some risk. The safest approach is to treat no click as a no, remove the sign-up after a short time, and keep only a brief note that a confirmation email was sent.

Let's get your emails into the inbox.

Book a free 30-minute call. We'll look at where your email stands today and exactly what we'd do to turn your list into revenue.

Free, no pressure, no obligation.