Getting Started
Consent and double opt-in
What counts as consent, what we record, and what happens when somebody leaves.
A form submission is not consent. Anyone can type anyone’s address into a box on the open internet, and plenty of people do, out of malice or mistyping. It becomes consent when somebody proves they can read that inbox.
That is why double opt-in is the default on every topic.
How it works
- Somebody submits your form. We create the contact and record the subscription as pending.
- We email them a confirmation link, from your brand.
- They click it. The subscription becomes subscribed, and we store the moment and the IP address it came from.
contact.subscribedfires on your webhook.
Until step 3, they are not on your list and no campaign will reach them.
What we keep as evidence
For every confirmed subscription we store when the confirmation was sent, when it was clicked, and the IP address that clicked it.
This is what answers a complaint months later. “Someone says they never signed up” is unarguable without it and a thirty-second lookup with it.
Turning it off
A topic can skip confirmation, and sometimes it should: you might be migrating a list that was already double opted-in elsewhere, or have another lawful basis for contacting these people.
It is a per-topic setting and it is deliberately not the default. If you turn it off, you are asserting you already have consent, and you are accountable for that assertion. Your deliverability is the first thing that suffers if you are wrong.
Confirmation links expire
A confirmation link is good for 14 days. After that it is refused and the person can sign up again.
A link that works forever is a link that still works when the message is forwarded, or found in a shared mailbox two years later.
Unsubscribing
Every campaign carries an unsubscribe link, and we add the headers that let Gmail and Outlook show their own one-click button. Both are required, not optional, and we will not send without them.
By default the link unsubscribes from the topic, not from everything. Someone tired of your weekly digest keeps getting your product announcements, which is usually what they meant.
Recipients can also open a preferences page and choose per topic, or leave entirely. The preferences page only shows topics they already have a relationship with — never your full catalogue, which would tell them about mail they are not receiving.
When somebody leaves, they stay gone
An unsubscribed contact cannot be resubscribed through the API. Not with a secret key, not by importing them again, not by posting the form again.
POST /v1/contacts with an unsubscribed address refuses with
contact_unsubscribed and changes nothing.
Only the person themselves can undo it, from a link in mail you already sent them. This one is not configurable: an opt-out that your next CSV import can quietly reverse is not an opt-out.
Bounces and complaints
Both suppress the address automatically, and you do not need to handle it yourself.
A permanent bounce means the address does not exist. We stop sending to it.
A complaint means they pressed “report spam”. We stop sending to them immediately, and treat it as the strongest possible signal — far worse for you than an unsubscribe, because mailbox providers are watching that number.
Soft bounces (a full mailbox, a server having a bad afternoon) do not suppress on their own. Repeated ones eventually do.
Updated at, Saturday, October 10, 2026