Double opt-in is a sign-up procedure in which an email address submitted through a form is not added to a mailing list until the owner of that address confirms the request, usually by clicking a unique link in a message sent to it. The first step records that someone typed an address. The second records that the person controlling the inbox agreed. Mail administrators and blocklist operators tend to call the same process confirmed opt-in or closed-loop opt-in, and the abbreviations DOI and COI are used interchangeably.

It exists because a web form cannot tell who is filling it in; typos, bots and pranksters can all submit someone else's address. Without a confirmation step a sender holds no evidence that the recipient asked for anything, and European law places the burden of producing that evidence on the sender.

How the confirmation loop works

The sequence has four stages. A visitor submits an address, typically alongside a consent checkbox whose wording describes what will be sent. The system stores the record in a pending state rather than on the live list. It then sends one confirmation message carrying a link with a unique token. Only when that link is followed does the record move to subscribed; if it is never followed, the address is never mailed again.

Vendors add housekeeping. IBM's documentation for Acoustic Campaign deletes contacts left in the pre-opt-in state for more than 30 days and limits resends to one per calendar day. Microsoft's Customer Insights - Journeys assigns the confirmation email a transactional purpose, keeping it outside marketing consent logic.

What the loop produces, beyond a cleaner list, is a consent record: the address, plus the time and IP address of both the sign-up and the click. German commentators have long argued it should also keep the consent wording and the confirmation email, because a log line proves neither what was agreed nor who agreed.

Double opt-in sits upstream of every paid use of an address. Confirmed lists become the hashed files uploaded to Google Customer Match, Meta custom audiences and clean rooms, where match rate decides how much becomes addressable. The loop is run by the email service provider (ESP) or customer relationship management (CRM) system. Mailbox providers such as Gmail and Microsoft never see the record, only its consequences in bounce and complaint rates.

Origin and evolution

The mechanism predates commercial email marketing. On March 15, 1993, version 1.7 of LISTSERV, the mailing list software written by Eric Thomas, added a return address verification step asking new subscribers to reply "ok", according to an account published by the newsletter platform Buttondown. Its purpose was catching broken addresses, not spam. By the late 1990s marketers called it double opt-in, against single opt-in, where a sign-up takes effect at once; anti-spam practitioners objected that the name implied a pointless second request. Uptake was slow. Aweber introduced link-based confirmation around December 2002, and about 5% of Fortune 500 companies used the method by 2004, according to Buttondown.

Legislation then diverged. The European Union's ePrivacy Directive of July 2002 required prior consent for marketing email, while the US CAN-SPAM Act of 2003 required only a working opt-out. Neither mentions confirmation. Germany supplied the case law. On February 10, 2011, the Federal Court of Justice (BGH) ruled in case I ZR 164/09, reported under the name "Double-opt-in-Verfahren", that a confirmation email cannot prove consent to telephone marketing, since nothing guarantees that a phone number entered on the form belongs to whoever clicked. The judgment was widely read as endorsing the procedure for email.

On September 27, 2012, the Higher Regional Court of Munich found in case 29 U 1682/12 that the confirmation request itself could be unlawful advertising where the sender could not prove the recipient had signed up. The higher regional courts of Celle, on May 15, 2014, and Dusseldorf, on March 17, 2016, rejected that position.

Canada's Anti-Spam Legislation (CASL) came into force on July 1, 2014 with a rule closer to Munich's: the Canadian Radio-television and Telecommunications Commission (CRTC) treats a message requesting express consent as itself a commercial electronic message, so it cannot be used to obtain that consent. The General Data Protection Regulation (GDPR), applicable from May 25, 2018, codified the burden of proof in Article 7(1). Where processing rests on consent, the controller must be able to demonstrate that the data subject consented. No method is prescribed. For telephone marketing, Germany's section 7a of the Act against Unfair Competition (UWG) has since October 1, 2021 required consent records to be kept for five years, with fines of up to 50,000 euros.

Why it matters for marketers

Three pressures meet at the sign-up form. The first is legal evidence: a confirmed address with a stored record is the most common way European senders try to meet Article 7(1). Rules differ by channel, as Alliance Digitale set out in an April 2026 guide.

The second is deliverability. Google's rules for bulk senders to Gmail, effective February 1, 2024, require a spam rate below 0.3% in Postmaster Tools. Unconfirmed lists accumulate the mistyped addresses that hard bounce and the abandoned ones that mailbox providers recycle as spam traps.

The third is data quality for paid media. A Google Ads help page reported in September 2026 concedes that its invalid traffic filters do not stop fake form submissions, and lists double opt-in alongside reCAPTCHA and server-side validationas safeguards on the advertiser's side. Junk leads also feed automated bidding.

Google applies the procedure to its own marketing: a Google Ads help page states that double opt-in is legally required for advertisers billed in Austria, Germany, Greece, Switzerland, Luxembourg and Norway.

Regulators, meanwhile, are narrowing what counts as a consented list. Italy's Garante fined Lusha 2 million euros and ordered erasure of its Italian data in July 2026. The Hessian data protection authority fined a company 10,000 euros for emailing more than 2,700 recipients using scraped contact data. And a completed form for a gated asset does not by itself authorise marketing email under the GDPR.

Limitations and disputes

The cost is attrition. Mailchimp said in October 2017 that double opt-in completion on its platform had slipped to 39%, meaning 61% of people who began a sign-up never confirmed. From October 31, 2017 single opt-in became its default, except on existing forms of EU-based customers. Practical Ecommerce has put typical confirmation at 50% to 80%, and a Campaign Monitor analysis found 46.5% of senders using the method at all.

The legal status is disputed in both directions. Google describes the procedure as a legal requirement in six countries. The GDPR demands only demonstrable consent, and German courts have treated double opt-in as a means of evidence rather than a statutory duty. Munich's 2012 reading remains a minority view, and Canada's rule removes email as a consent channel altogether.

Abuse is a separate objection. In August 2016 attackers used unprotected sign-up forms to flood targets, including US government addresses. Spamhaus, which detected the first attack on August 12, 2016, recorded one company where nine addresses were signed up more than 9,000 times in two weeks, generating 81,000 confirmation emails. Its chief executive, Steve Linford, blamed "badly-run 'open' lists" that subscribed addresses without verification, according to Krebs on Security. Yet confirmation messages are still messages. Spamhaus concluded that confirmed opt-in alone was not sufficient against the volume and recommended pairing it with a CAPTCHA.

Double opt-in and adjacent terms

Single opt-in adds an address on submission. A welcome message may follow, but nothing depends on a response.

Soft opt-in is a statutory exception, found in the ePrivacy Directive and the UK's Privacy and Electronic Communications Regulations (PECR), allowing marketing to existing customers about similar products if an opt-out was offered at collection and in every message. It involves no confirmation step.

Double consent describes Apple's App Tracking Transparency (ATT) framework obliging apps to ask users twice, once through Apple's prompt and once through their own consent tool. France fined Apple 150 million euros over the design in March 2025 and Italy followed with 98.6 million euros in December 2025. The dispute concerns tracking, not email.

Two-party approval is sometimes loosely labelled double opt-in. Access to Google's Universal Commerce Protocol on Shopify requires sign-off from Shopify and then from each merchant, and an LG Ad Solutions executive once described automatic content recognition as a "double opt-in experience". Neither confirms an address.

Recent developments

On July 27, 2026, the Administrative Court of Dusseldorf, in case 29 K 9714/24, upheld a data protection warning against a company whose only evidence of consent was an email address, a sign-up IP address with timestamp and a confirmation IP address with timestamp: a registration at 17:22:20 on June 29, 2023, confirmed at 17:27:41. The complainant said he had been in Denmark that day. The court held that such entries establish neither a link to the complainant nor the content of any consent, and noted that the company could not produce the confirmation email its own process description said it stored. The regulator had told it in October 2022 that valid double opt-in requires complete, printable documentation. The judgment was not final when reported in August 2026.

Measurement of confirmed lists is narrowing as well. France's data protection authority, the CNIL, adopted a recommendation on March 12, 2026 treating email tracking pixels as consent-requiring, which makes the open rate of even a confirmed list harder to observe. The separate double-consent dispute also moved: in August 2026 Germany's Bundeskartellamt gave Apple four months to redesign its ATT prompt.

Timeline

  • March 15, 1993: LISTSERV 1.7 adds return address verification for new subscribers
  • Late 1990s: Marketers adopt the term double opt-in to distinguish confirmed sign-ups from single opt-in
  • July 2002: The EU ePrivacy Directive requires prior consent for marketing email
  • December 2002: Aweber introduces link-based subscription confirmation
  • 2003: The US CAN-SPAM Act sets an opt-out regime without a consent requirement
  • February 10, 2011: The BGH rules in I ZR 164/09 that email confirmation cannot prove consent to telephone marketing
  • September 27, 2012: The Higher Regional Court of Munich treats a confirmation request as potential unlawful advertising
  • May 15, 2014: The Higher Regional Court of Celle rejects the Munich position
  • July 1, 2014: Canada's CASL comes into force
  • March 17, 2016: The Higher Regional Court of Dusseldorf also rejects the Munich position
  • August 12, 2016: Spamhaus detects the first wave of subscription bombing through unconfirmed sign-up forms
  • October 31, 2017: Mailchimp makes single opt-in the default for hosted forms outside the EU
  • May 25, 2018: The GDPR applies, including the Article 7(1) duty to demonstrate consent
  • October 1, 2021: Section 7a UWG introduces a five-year documentation duty for telephone marketing consent in Germany
  • February 1, 2024: Gmail bulk sender requirements take effect
  • March 12, 2026: The CNIL adopts its recommendation on email tracking pixels
  • July 27, 2026: The Administrative Court of Dusseldorf rules that email, IP and timestamp logs do not prove consent
  • September 17, 2026: Google's help page recommending double opt-in against invalid leads is reported

Summary

Who. Senders of marketing email and the ESPs and CRM platforms that run their sign-up forms operate double opt-in. Mailbox providers, blocklist operators such as Spamhaus, data protection authorities and courts judge its results.

What. A two-step subscription procedure: an address submitted through a form is held pending until its owner clicks a confirmation link, producing a record intended to prove consent. It is also called confirmed or closed-loop opt-in.

When. The mechanism dates to LISTSERV 1.7 on March 15, 1993, acquired its marketing name in the late 1990s, was shaped by German rulings from 2011 onwards and by the GDPR from May 25, 2018, and was tested again by the Dusseldorf judgment of July 27, 2026.

Where. It sits at the point of collection, upstream of email sends, CRM lead scoring and customer list uploads to advertising platforms. It is most entrenched in Germany, Austria and Switzerland, where courts and platforms treat it as the default.

Why. Because a form cannot verify who submitted an address, and European law makes the sender prove consent. The procedure improves list quality and deliverability, but costs sign-ups, can itself be abused, and proves nothing if its records are not kept.