# Double Opt-In

Double opt-in means a new subscriber has to click a link in a confirmation email before they can receive campaigns. It keeps mistyped and malicious addresses off your list, which protects your bounce and complaint rates. See [Sending Health](/docs/concepts/sending-health).

## It is always on for public signups

There is no per-form, per-list or workspace setting. Every public signup works the same way: an embedded or hosted [form](/docs/platform/forms), the hosted subscribe page at `/subscribe/LIST_ID`, and the subscribe block on a [landing page](/docs/platform/landing-pages).

The one exception is a signup with no list. A form set to **No list (collect only)** subscribes the person straight away and sends no email, because the confirmation link is tied to a list.

## Which entry points create which status

| Entry point                                       | Status                                          | Confirmation email |
| ------------------------------------------------- | ----------------------------------------------- | ------------------ |
| Form, subscribe page or landing page, with a list | Pending                                         | Yes                |
| Form with **No list (collect only)**              | Subscribed                                      | No                 |
| `POST /api/v1/contacts`                           | Subscribed, unless you send a `status`          | No                 |
| `POST /api/v1/events` for an unknown email        | Pending                                         | No                 |
| Stripe or WooCommerce integration                 | Pending, or Subscribed if you opt in (below)    | No                 |
| Shopify integration                               | Follows the customer's marketing consent        | No                 |
| CSV import                                        | Subscribed, unless the file has a status column | No                 |
| **Add contact** in the dashboard                  | Subscribed                                      | No                 |

- Only the public signup paths send a confirmation email. A contact created as Pending through an event or an integration stays Pending until the person signs up through a form and confirms, or you change its status.
- An event is never an opt-in. A purchase or a custom event creates a Pending contact, not a Subscribed one. See [Events](/docs/api/events).
- Stripe and WooCommerce do not record marketing consent. When you connect one in **Settings > Integrations**, new customers arrive as Pending unless you tick **Subscribe these customers to marketing automatically**. Shopify does record consent: opted-in customers are Subscribed and opted-out customers are Unsubscribed.
- In a CSV, a `status` column of `pending` or `unconfirmed` imports a row as Pending. `subscribed`, `confirmed` and similar values import it as Subscribed.

## The confirmation email

Flomailr sends "Confirm your subscription to LIST NAME" under your workspace's from name (or its name, if no from name is set). It comes from your verified custom domain if you have one, otherwise from the shared address. It says the person will not receive email until they confirm, and has one **Confirm subscription** button. Replies go to your reply-to address if you set one. The hosted subscribe page tells the person to check their inbox, and a form shows its own success message.

Two limits stop a form from being used to flood someone's inbox:

- An address that is still Pending does not get a second confirmation within 24 hours.
- No address gets more than two confirmations in 24 hours.

## What confirming does

The link is signed for one list and one contact. Clicking it:

- sets the contact to Subscribed and adds them to the list
- records a consent entry with the source `double_opt_in`
- starts any automation with the **New subscriber joins** trigger

If the link is invalid, the page says so and offers to subscribe again.

Some signups behave differently:

- **Already subscribed:** nothing changes. The contact is added to the list.
- **Unsubscribed before:** the status is left alone and a confirmation email goes out. Clicking it resubscribes them and clears their old unsubscribe entry. A form cannot resubscribe someone on its own.
- **Bounced:** refused. A bounced address is never resubscribed.
- **Suppressed by a bounce, complaint or hand-added block:** nothing is written. The visitor still sees the usual success message, so the form does not reveal who is suppressed. Confirming never lifts these.

## Pending contacts do not receive mail

Campaigns go to Subscribed contacts only, for lists and segments alike. Automation emails also skip anyone who is not Subscribed. A Pending contact can sit on a list, but nothing is sent to them.

The contacts table shows Pending contacts by default, with their own status chip, because an unconfirmed signup is still a live prospect. Flomailr does not expire or delete them. See [Contacts](/docs/platform/contacts), [Lists](/docs/platform/lists) and [Compliance](/docs/concepts/compliance).
