Double opt-in

Not generally available yet. We're still rolling this one out, so the Require confirmed opt-in (double opt-in) checkbox in Settings is greyed out and marked Coming soon — you can see it, but you can't switch it on, and neither can we accidentally switch it on for you. Everything on this page describes how it behaves once you have it. If you'd like it turned on for your account, get in touch and we'll add you to the early group.

Nothing changes for you in the meantime: with double opt-in off on every list, sign-ups work exactly as they always have.

Double opt-in adds a confirmation step to subscribing: after someone signs up on a form, they get an email asking them to click a link before they start receiving anything from that list. It's a second, active step from the person themselves — proof they really want to hear from you and typed their address correctly — rather than a checkbox alone. That tends to mean a cleaner list and better deliverability, since every subscriber has actively confirmed they want your mail.

Double opt-in is off by default, and it's set per subscription list, not for your whole account. Turning it on for one list doesn't touch any other list, and it doesn't change anything for people already subscribed — they're grandfathered in, so no existing subscriber is asked to re-confirm.

Steps

Turn on double opt-in for a list

  1. Go to Settings → Email, and find Subscription lists.
  2. On the list you want to protect, check Require confirmed opt-in (double opt-in).
  3. That's it — there's nothing else to configure. New sign-ups to this list now go through the confirmation step described below. Everyone already subscribed to the list stays subscribed with no action needed from them.

What changes on the contact record

Before you switch it on, a list shows every contact as Subscribed unless they've unsubscribed — with no confirmation step, anyone who hasn't opted out is on the list.

After you switch it on, two new states appear on that list. Contacts you'd already emailed before the switch are grandfathered in and keep showing as subscribed. Everyone else — contacts who were never mailed on this list — moves to Never asked, and new sign-ups pass through Awaiting confirmation until they click the link.

Adding the opt-in to a form

Consent capture is never added to a form automatically. When you ask the assistant to build a form that collects an email address, and you have at least one list with double opt-in switched on, it asks whether the form should also offer email sign-up, and which lists. Nothing is added unless you say so — a contact-us or quote-request form collects an email too, and that isn't a newsletter sign-up.

Say yes and pick your lists, and the form gets a short block with one unticked checkbox per list. Each checkbox shows that list's description, so the description you wrote in Settings is the wording people actually read before they tick. It's worth re-reading those descriptions before you publish a form — that text is your record of what someone agreed to.

To take the opt-in off a form later, just ask to remove it. Redesigning a form for other reasons keeps the opt-in in place.

How someone subscribes

  1. Someone fills out one of your published forms that includes the subscription-list component, and ticks the list(s) they want.
  2. If a ticked list requires double opt-in, they receive an email asking them to confirm.
  3. They click the confirmation link.
  4. They're now subscribed. Only after that click will they receive marketing email for that list — nothing goes out to them on it before they confirm.

If a form includes a list that doesn't require double opt-in, ticking that one subscribes them immediately, exactly as before this feature existed. The two behaviors can sit side by side on the same form.

The 7-day confirmation window

A confirmation link stays valid for 7 days. If someone doesn't click it in that time, the request is recorded as expired and the link stops working. They were never sent marketing email for that list while their confirmation was pending, and they still won't be after it expires — an unconfirmed person is never mailed. The record of the original request is kept; nothing is deleted, and they're free to sign up again for a fresh confirmation email.

Automations and the 24-hour hold

This is the part that generates support questions, so it's worth reading closely.

If a journey tries to email someone whose confirmation is still pending, it waits and retries for up to 24 hours. After that the journey moves on without them. If they confirm later, they can still receive future emails, but they will not receive that journey's message.

The 24-hour journey hold and the 7-day confirmation window are two different things. Someone can confirm on day 3 — well within the 7-day window — and still have missed a journey message that gave up on them after 24 hours. Confirming makes them subscribed going forward; it doesn't replay anything a journey already moved past.

Imported contacts

Contacts you import are not sent a confirmation email — an import should never turn into a mass mailing. Instead, an import can mark contacts as subscribed directly, recorded alongside a required statement from you about where that consent came from (for example, "collected via in-store sign-up sheet, March 2026"). Those contacts are marked subscribed, but the system also records that they did not go through the confirmation-link flow, so the two kinds of opt-in are never confused with each other later.

You set this up on the import itself, under Subscription consent:

  1. Upload your file and open the import card — see Importing contacts.
  2. In Options, find Subscription consent and choose a list under Record consent on. Only lists with double opt-in switched on are offered, because those are the only lists where this record is ever read. If the list you want isn't there, turn double opt-in on for it first.
  3. Fill in Where did this consent come from? This is required — the list isn't saved until you write something, and the import won't start without it. Be specific: "collected at our 2026 trade-show booth; paper opt-in forms retained" is worth having a year from now, "yes" isn't.
  4. Run the import as usual.

Leave Record consent on set to Don't record consent — the default — and the import touches no subscriptions at all and behaves exactly as it always has. Nothing changes for any import you were already running.

When you do set it, here's what happens to those contacts:

  • They can be mailed on that list straight away.
  • They're recorded as subscribed but not double opted-in, because no confirmation round-trip happened. The two stay distinguishable on the contact afterwards.
  • No confirmation emails go out, however many contacts are in the file.
  • Your statement is stored word-for-word against every contact the import subscribes.
  • Anyone already on the list is left exactly as they are — including anyone who has opted out, and anyone with a confirmation still pending. Re-running an import can never resurrect an opt-out or flip a pending request to confirmed.

The same thing is available through the import API if you're importing programmatically.

Unsubscribing is unchanged

Double opt-in doesn't change how unsubscribing works. One-click unsubscribe still works exactly as before, and an unsubscribe always overrides an opt-in — including a pending or confirmed one. If someone unsubscribes, they stop receiving mail regardless of what their confirmation status says.

The preference centre comes with double opt-in. It's on when at least one of your subscription lists has double opt-in switched on, and off when none of them does. There's no separate setting to find — turning double opt-in on for a list turns the preference centre on for your whole account, and turning it off everywhere turns the preference centre off again.

While it's on, your marketing email footers carry an Email preferences link alongside Unsubscribe. That link opens a page showing every list that person is on — not just the double-opt-in ones — with a checkbox for each, so instead of choosing between "all of it" and "none of it", they can drop the one list they're tired of and keep the rest.

While it's off, the footer keeps your sending provider's own preferences link instead, and your own preference page doesn't answer.

Worth knowing before you switch it off: preference links stay valid for 90 days, so at any moment there are live ones sitting in inboxes. Turning double opt-in off on your last list switches the preference centre off for all of them at once — anyone who clicks an older link gets the "this link is no longer valid" page rather than their checkboxes.

Nothing is lost and nobody is stranded without a way out: everyone's subscriptions stay exactly as they were, the Unsubscribe link in the same footer is untouched and keeps working, and switching double opt-in back on brings the still-in-date links back to life. But if you're planning to turn double opt-in off, expect some recipients to hit that page.

Other things worth knowing while it's on:

  • No login required. The link is personal to the recipient and works for 90 days from the day the email was sent. Nothing is shown until it's opened, and forwarding the email forwards that person's link, so treat it the way you'd treat an unsubscribe link.
  • Only the boxes they were shown are changed. A list created after the email went out isn't touched, so an old email in someone's inbox can never quietly unsubscribe them from something new.
  • Changes apply within a minute or so. The page confirms straight away and the change lands shortly after.
  • Unticking every box is a full unsubscribe from the lists shown, recorded exactly like any other unsubscribe and mirrored to your sending provider.
  • After 90 days, the link stops working. They'll see a page saying the link is no longer valid — never their data, and never an empty checklist either. It tells them to use the link in a more recent email, or reply and ask you directly; there's no separate self-service "send me a new link" page.
  • If the page can't load their preferences, it says so and changes nothing. A brief outage shows a "try again shortly" message rather than an empty list of unticked boxes — an empty list would look exactly like an unsubscribe when nothing actually happened.

Two things other than the double-opt-in setting also switch the link back to your sending provider's own preferences page:

  • You haven't published a web page or form through the app yet. Publishing anything — a landing page, a signup form — switches it over to your own page automatically.
  • We can't reach your own page for any reason. The footer keeps the provider's working link rather than shipping one that goes nowhere.

What's recorded as proof

For every opt-in, the system keeps:

  • When the person asked to subscribe.
  • When they confirmed (if the list requires it).
  • The IP address and browser they used.
  • The exact wording of the consent text they were shown at the time.

That last point matters: the wording is captured the moment someone submits, so editing your list's description later doesn't rewrite what a past subscriber actually agreed to.

Texting back in (SMS)

This is a separate, simpler mechanism from the list-based double opt-in above — text messaging doesn't have a per-list confirmation click. If someone who had opted out of texts sends your opt-in keyword (for example START) back to your number, that's recorded as evidence too: when they sent it and the phone number they texted from. It shows up on their contact timeline as "Opted in via SMS."

Tips

  • A resend of the confirmation email is limited to 3 per address per day. This is an anti-abuse measure — it stops the confirmation flow itself from being used to spam someone.
  • If someone submits the same form twice before confirming, that refreshes their existing pending request rather than sending a second confirmation email.
  • If you're planning to turn on double opt-in for a list that already has active subscribers, remember they're grandfathered in automatically — you don't need to (and shouldn't try to) get them to re-confirm.

FAQ

Q: Do I have to turn this on? A: No. It's off by default and stays off unless you turn it on for a specific list.

Q: If I turn it on, do my current subscribers have to confirm again? A: No. Enabling double opt-in only affects new sign-ups from that point forward. Everyone already subscribed to the list stays subscribed.

Q: A contact says they never got the confirmation email — what happened? A: A few possibilities: it's sitting in spam, they mistyped their address, or they've hit the 3-per-day resend limit and need to wait. If more than 7 days have passed since they signed up, their request has expired and they'll need to sign up again for a new confirmation email.

Q: Someone in a journey didn't get their email — why? A: If they hadn't confirmed their subscription yet, the journey holds for up to 24 hours waiting for them, then moves on without sending. This is separate from the 7-day confirmation window — they might confirm later and still have missed that particular journey message.

Q: Can I bulk opt-in a list of contacts I imported without confirmation emails going out to all of them? A: Yes — imports never trigger confirmation emails. They're marked subscribed directly, along with a required note on where that consent came from. Set it under Subscription consent on the import card, or through the import API.

Q: The list I want isn't in the Subscription consent dropdown — why? A: Only lists with double opt-in switched on appear there. On a list without it, the record would never be read by anything, so offering it would only be misleading. Turn double opt-in on for the list in Settings → Email → Subscription lists and it shows up.

Q: I picked a list but the import won't start. A: The statement about where the consent came from is required, and the list isn't saved without it. Fill in Where did this consent come from?, or set the dropdown back to Don't record consent.

Q: Does an unsubscribe ever lose to a pending or confirmed opt-in? A: No. Unsubscribing always wins, regardless of confirmation status.