Mailchimp double opt in is usually turned on for one of two reasons: a compliance conversation that ended with somebody saying the list needs verified consent, or a run of bad sending metrics that looked like it was caused by junk signups. Both are reasonable. What tends to be missing from the decision is a clear picture of the second step itself, because the confirmation click is not free. It sits between a person filling in a form and that person existing in the audience at all, and everyone who does not click simply is not there.
That gap is the whole subject. This covers what the switch turns on, the places it cannot be turned on, what happens to the people in between, and how to tell whether the trade is worth making on a given form.
What the switch actually turns on
Double opt in is a chain of screens and messages, not a single setting, and each link can be edited except one.
A potential subscriber fills in the signup form and submits it. A reCAPTCHA box follows, and Mailchimp's documentation is explicit that this step is required and cannot be turned off or edited on its hosted forms. Then a signup thank you page appears, whose only job is to tell the person to go and check their email. An opt in confirmation email arrives containing a unique URL. Clicking it produces a confirmation thank you page. A final welcome email can follow, and this one is disabled by default, which is worth knowing because the moment of confirmation is the most attentive a new subscriber will ever be.
Both of the thank you pages can be replaced with a redirect to a page on a site of your own, which matters more than it sounds. The default confirmation page is generic, and a redirect turns the end of the chain into something that can carry a next step rather than a full stop.
Single opt in skips the middle. The person is added to the audience the moment they submit. Mailchimp's documentation notes that reCAPTCHA still filters fake signups on hosted forms regardless of which method is chosen, and that embedded and pop up forms need reCAPTCHA enabled separately in audience settings. That last detail undercuts the most common argument for double opt in, which is spam prevention. A bot filter already exists on both paths.
Where it can and cannot be enabled
This is the constraint that decides the question for a lot of teams, and it is easy to read past.
Mailchimp's own note on the subject states that double opt in for email contacts can only be enabled for Mailchimp signup forms. A form integration or the API is outside its scope. So an intake form built elsewhere, a job application form, a grant submission, an event booking, or a WordPress contact form that pushes addresses into an audience, does not gain a confirmation step by flipping this setting. The confirmation step belongs to Mailchimp's hosted and embedded signup forms specifically.
Where it does apply, the setting lives per audience. The path is Audience, then the Contacts drop down to pick the audience, then the three dot overflow menu, then Audience settings, then the Form settings section, then Edit beside the email opt in settings, then a choice between Single opt in and Double opt in, then Save opt in setting. Accounts with several audiences can also make global changes on the Opt In Settings page, and the choice is offered whenever a new audience is created.
One regional default catches people out. If the primary contact address on the account is in the EU, Mailchimp's documentation states that some audiences may already use double opt in as the default. A team that never made this decision may already be living with its consequences, which is a good reason to check the current setting before attributing a growth problem to anything else.
SMS follows different rules. Double opt in for SMS is managed on the opt in management tab of the SMS settings page, is required in some countries, and is required in order to send abandoned cart text messages. Disabling it while an abandoned cart SMS flow is active pauses sending and strips the related disclosures from signup forms and landing pages. That is not a preference, it is a dependency.
Pending is the status that decides the cost
The honest accounting of double opt in lives in one contact type, and Mailchimp documents it clearly.
A person who has completed a signup form but has not confirmed is a pending contact. Three facts about that state matter. Their address is not added to the audience until they confirm, and they cannot be viewed in the audience at all. They do not count toward the monthly contact limit. And after 60 days without confirmation, the address and any other information they provided is removed and deleted.
Put together, that means a form filled in by a real person who never clicks the link produces nothing durable. No contact, no record in the audience view, and after two months no data at all. For a newsletter, that is the intended behaviour and arguably a benefit: the list stays clean and the billing tier stays honest, since pending contacts do not consume the plan allowance.
For anything that is not a newsletter, it is a data loss event. An applicant who filled in a recruitment form, a member who submitted a renewal, a resident who filed a facility request: if the confirmation click is what admits them to the system, the ones who do not click are invisible to the people who were supposed to process them. Nobody gets an alert about a submission that never became a contact.
Measuring that loss is harder than it should be, and the reason is the same invisibility. Because pending contacts cannot be viewed in the audience, the audience view cannot show how many people submitted and never confirmed. The count has to come from the form side instead, by comparing how many people reached the signup thank you page against how many contacts appeared as subscribed over the same period. Redirecting that thank you page to a page of your own, which Mailchimp supports, makes the first half of that comparison measurable in ordinary web analytics. Without it, the number of people lost at the confirmation step is not recorded anywhere.
It is also worth being precise about the neighbouring statuses, because the phrase list hygiene gets used loosely. Unsubscribed and non subscribed contacts both count toward the monthly contact limit and both can still receive transactional email. Cleaned contacts, produced by hard bounces and repeated soft bounces, do not count toward the limit. So the billing benefit people expect from double opt in, fewer contacts on the plan, is smaller than it looks, because bounced addresses were already outside the count.
How the two methods compare in practice
| Single opt in | Double opt in | |
|---|---|---|
| Contact exists after form submission | Yes, immediately | No, only after the confirmation click |
| Bot filtering | reCAPTCHA on hosted forms | reCAPTCHA on hosted forms |
| Counts toward monthly contact limit before confirming | Yes | No, pending contacts are excluded |
| Unconfirmed data retained | not applicable | Deleted after 60 days |
| Works with the API or a third party form | Yes | No, Mailchimp signup forms only |
| Required for abandoned cart SMS | No | Yes |
| Visible in the audience while unconfirmed | not applicable | No |
Mailchimp's guidance on choosing between them is narrower than the general advice that circulates online. Its documentation suggests double opt in where audience growth is not the focus, or where open rates have been low or abuse complaints have appeared, and single opt in where growth speed matters and the friction of checking an inbox is a cost worth avoiding.
The useful reframing is that double opt in is a deliverability instrument, not a consent instrument. Consent comes from the wording on the form and the lawful basis behind it. Anti spam law in most jurisdictions, including CAN SPAM in the United States and CASL in Canada, requires permission rather than a specific confirmation mechanism. A clearly worded checkbox on a single opt in form is consent. A confirmation click is evidence of a working mailbox and a live human, which is a different and narrower thing.
Where the confirmation step does not belong
There is a category of form where turning this on causes damage that never shows up in the email reports, because the loss happens before anything is sent.
Anything where the submission is a request that a person has to answer belongs in that category. A recruitment application, a grant or funding submission, a course enrolment, a repair request, a facility booking, a membership application. In each of those, the submission is the start of a conversation that someone at the organisation has to carry: read it, decide, reply, and record that the reply happened. Inserting a step where the applicant has to go to a different inbox and click a link before their submission becomes visible to the person handling it is a straightforward way to lose applicants who wanted to apply.
The marketing subscription and the intake request are two different jobs, and they behave badly when they share a mechanism. The subscription wants a confirmed, cheap, engaged list, and double opt in serves it well. The intake request wants zero drop off, an owner, a status, and an audit trail of the reply, and none of those four things is what an email platform is built to hold. When both run through the same audience, the settings that protect the first will quietly damage the second. The practical answer is to separate them: keep the newsletter on the Mailchimp signup form with double opt in if the metrics call for it, and handle submissions that require a human reply somewhere that keeps the submission, the owner, the status, and the response on one screen. The use cases where that distinction bites hardest are the ones with a deadline attached, because a submission lost to an unclicked confirmation link cannot be recovered after the window closes.
One more practical note for teams that keep both in Mailchimp: because the setting is per audience, a separate audience for the intake path can run single opt in while the newsletter audience runs double. That is cheaper than it sounds only up to a point, since the Free plan is limited to contacts under 250 and paid plans cap the number of audiences, so audience count is itself a metered resource.
What to change first
Check whether the setting is already on, since an EU primary contact address may have made double opt in the default without anyone choosing it, and check it per audience rather than assuming the account behaves uniformly. Then separate the two jobs: leave the newsletter behind the confirmation click if deliverability needs it, and move anything that ends in a written reply onto a path with no confirmation gate, where each response carries its own owner and status. Halict is built for that second path, and the pricing is worth comparing on the axis that actually grows, which is people handling responses rather than contacts stored.
Q1. Do pending contacts count toward the Mailchimp contact limit?
No. Mailchimp documents that pending contacts, meaning people who submitted a signup form but have not confirmed, do not count toward the monthly contact limit. They also cannot be viewed in the audience, and after 60 days without confirmation their address and any other information they provided is removed and deleted.
Q2. Can double opt in be enabled for contacts added through the API or a third party form?
No. Mailchimp's documentation states that double opt in for email contacts can only be enabled for Mailchimp signup forms. Addresses arriving through the API or a form integration are outside the scope of the setting, so a confirmation step for those paths has to be built wherever the form lives.
Q3. Will turning off double opt in lose the contacts who are currently pending?
Contacts who have not confirmed are not in the audience, so switching to single opt in does not retroactively admit them. Anyone still inside the 60 day window remains unconfirmed and is deleted at the end of it, which means the change applies to new signups rather than recovering old ones.
Q4. Does double opt in reduce spam signups more than single opt in?
Both methods use reCAPTCHA on Mailchimp's hosted forms, and Mailchimp's documentation notes that reCAPTCHA is required and cannot be turned off there, so bot filtering is present either way. Double opt in adds verification that a mailbox exists and a human read it, which is a deliverability benefit rather than an extra bot filter.
Q5. Is double opt in required by law?
Anti spam laws such as CAN SPAM in the United States and CASL in Canada require permission before sending marketing email, not a specific confirmation mechanism, and the exact requirements vary by country. A clearly worded consent statement on a single opt in form can satisfy permission, so the choice between methods is usually a deliverability and data quality decision rather than a legal one. Check the rules that apply where the recipients are.
