---
title: Consent and double opt-in
description: What counts as consent, what we record, and what happens when somebody leaves.
---

A form submission is not consent. Anyone can type anyone's address into
a box on the open internet, and plenty of people do, out of malice or
mistyping. It becomes consent when somebody proves they can read that
inbox.

That is why double opt-in is the default on every topic.

## How it works

1. Somebody submits your form. We create the contact and record the
   subscription as **pending**.
2. We email them a confirmation link, from your brand.
3. They click it. The subscription becomes **subscribed**, and we store
   the moment and the IP address it came from.
4. `contact.subscribed` fires on your webhook.

Until step 3, they are not on your list and no campaign will reach
them.

## What we keep as evidence

For every confirmed subscription we store when the confirmation was
sent, when it was clicked, and the IP address that clicked it.

This is what answers a complaint months later. "Someone says they never
signed up" is unarguable without it and a thirty-second lookup with it.

## Turning it off

A topic can skip confirmation, and sometimes it should: you might be
migrating a list that was already double opted-in elsewhere, or have
another lawful basis for contacting these people.

It is a per-topic setting and it is deliberately not the default. If
you turn it off, you are asserting you already have consent, and you
are accountable for that assertion. Your deliverability is the first
thing that suffers if you are wrong.

## Confirmation links expire

A confirmation link is good for 14 days. After that it is refused and
the person can sign up again.

A link that works forever is a link that still works when the message
is forwarded, or found in a shared mailbox two years later.

## Unsubscribing

Every campaign carries an unsubscribe link, and we add the headers that
let Gmail and Outlook show their own one-click button. Both are
required, not optional, and we will not send without them.

By default the link unsubscribes from the **topic**, not from
everything. Someone tired of your weekly digest keeps getting your
product announcements, which is usually what they meant.

Recipients can also open a preferences page and choose per topic, or
leave entirely. The preferences page only shows topics they already
have a relationship with — never your full catalogue, which would tell
them about mail they are not receiving.

## When somebody leaves, they stay gone

An unsubscribed contact cannot be resubscribed through the API. Not
with a secret key, not by importing them again, not by posting the form
again.

`POST /v1/contacts` with an unsubscribed address refuses with
`contact_unsubscribed` and changes nothing.

Only the person themselves can undo it, from a link in mail you already
sent them. This one is not configurable: an opt-out that your next CSV
import can quietly reverse is not an opt-out.

## Bounces and complaints

Both suppress the address automatically, and you do not need to handle
it yourself.

A **permanent bounce** means the address does not exist. We stop
sending to it.

A **complaint** means they pressed "report spam". We stop sending to
them immediately, and treat it as the strongest possible signal — far
worse for you than an unsubscribe, because mailbox providers are
watching that number.

Soft bounces (a full mailbox, a server having a bad afternoon) do not
suppress on their own. Repeated ones eventually do.