Single opt-in is a way of adding people to an email list where they are subscribed the moment they submit a sign-up form, with no confirmation step. The alternative, double opt-in, asks them to click a link in a confirmation email before they join.
How single opt-in works
A visitor enters their address, presses the button and is added to your list. Most platforms send a welcome or thank-you email straight away, and the person receives your regular emails from the next send. At no point is there proof that the address is real, that it belongs to the person who typed it, or that it was typed correctly.
That is the trade-off. Single opt-in captures everyone who submits the form, including people who would never have bothered to confirm. Double opt-in loses some genuine subscribers who miss or ignore the confirmation email, but every address that gets through is proven to work and to be wanted.
Why it matters
In the UK, single opt-in is lawful. PECR requires consent for most marketing emails to individuals, and that consent must meet the UK GDPR standard, but neither law requires it to be confirmed by a second email. What the law expects is that you can show consent was given: which form, what wording and when. Single opt-in is fine if your records do that.
The risks are practical rather than legal. Without confirmation you will collect:
- typos such as “gmial.com”, which bounce or, worse, reach spam traps set up on misspelt domains;
- fake addresses entered to get a discount code;
- bot sign-ups, sometimes in large numbers, which can include people who never asked to hear from you;
- real people subscribed by someone else as a prank or in malice, who then report your emails as spam.
Each of these harms your sender reputation. For a small shop with a modest, well-protected form, the risk is low. For a business running prize draws or paid social campaigns that drive thousands of sign-ups, it is much higher.
Common mistakes
- Confusing confirmation with consent. Single opt-in is about whether you confirm the address, not whether you need consent. The form still needs clear wording, a privacy notice link and unticked boxes.
- No bot protection. A single opt-in form without a honeypot field or CAPTCHA is an open door.
- No welcome email. Without one, nobody notices a bad address until the first campaign bounces, and genuine subscribers forget they joined.
- Never removing non-engagers. Addresses that never click or open anything after joining are likely to be bad. Mailing them indefinitely hurts you.
How to act on it
If you use single opt-in, put safeguards around it. Add real-time address validation so obvious typos are caught as people type, protect the form from bots, and send a welcome email immediately. Then watch how new subscribers behave: if a batch from one form or one campaign shows high bounces or no engagement at all, look at that source.
Consider double opt-in for higher-risk sources, such as competitions and giveaways, while keeping single opt-in for checkout and your main newsletter form. Store a consent record for every subscriber and keep it for as long as you keep emailing them.
Choosing the right method for each source is part of setting up email properly within a digital marketing strategy.
