With single opt-in, submitting a form is enough to start receiving mail. With double opt-in, the form produces a request, a confirmation email goes out, and consent is only granted once the recipient clicks through.
The difference sounds procedural. It is actually the difference between having evidence and having an assertion.
What the second step proves
A single opt-in tells you that someone typed an address into a form. It does not tell you that the person who owns the address did the typing. Mistyped addresses, deliberate sign-ups of other people, and bot submissions all look identical to a genuine one.
The confirmation click proves the address holder acted. That is a materially
stronger record, and it produces a separate, timestamped confirmed consent
event you can point to later.
The trade-off, stated honestly
You will lose subscribers. Some proportion never opens the confirmation, and that gap is real — it is the reason single opt-in remains popular.
What you lose is mostly addresses that would never have engaged. What you gain is a list with a higher engagement average, fewer spam traps, fewer complaints, and a provable consent record. Since engagement and complaint rate are two of the strongest inputs to sender reputation, the smaller list frequently delivers better in absolute terms.
Where it is not optional
Some jurisdictions effectively require confirmed consent for marketing email, and the direction of travel across privacy regimes has been toward stronger evidence rather than weaker. Treating double opt-in as the default is the cheaper position to hold.
Making the confirmation email work
- Send it immediately. Interest decays in minutes.
- Say what they signed up for and how often they will hear from you.
- One clear call to action and nothing else competing with it.
- Set expectations for what arrives after they confirm.
In practice
Opt-in mode is set per capture form, so a lead-magnet form and a newsletter form can differ where that is justified. The confirmation is recorded as its own consent event with its own source and timestamp, separate from the original request — which is what makes the resulting record hold up.