You have indeed. It is called "double opt-in" and legally required in many jurisdictions, before a web site can send you regular automated emails. Otherwise it might be considered Spam.
It's Time To Kill New User Confirmation Email Links
41–50 of 50 posts
Re: It's Time To Kill New User Confirmation Email Links
#42This article misses a key point. If you want to confirm that the person who opted into your service is who they say they are. Otherwise, you're looking forward to abuse complaints from email recipients, and it only takes a few of those to suspend your Mailchimp (or whatever delivery service) account. You can also add non-compliance with spam, privacy and other laws to the list of fun things that could happen if you t…
"In the edge case, where some unauthorized person has signed up using my email, then include some directions at the bottom of the email that instruct me how to deal with the abuse. And an extra benefit: If I have a good experience with your site reporting the abuse, I’ll be more interested to legitimately check out the site." I'm not sure if I just don't understand what both of you are saying, but it seems he address…
Re: It's Time To Kill New User Confirmation Email Links
#431. It's required by law in many places. That's why newsletter/auto-responder services use double opt-in.
2. If someone or something does sign-up on your behalf, why should you have to specifically opt out? So, it's always better to have someone confirm their e-mail, instead of having random users having to "opt out" of services they never signed up for.
3. Many a times, if it's some random site, the activation e-mail can go directly into your SPAM box. If an "opt out" type e-mail ends up in your SPAM box, then you probably won't see it, and it can potentially cause more damage.
4. For features like password reminder, it is always better, security-wise, to send the reset link to an e-mail you know for sure belongs to the account holder. If you mistyped your e-mail, and never received the conformation, you'd try creating an account again. However, if the account was activated by default, and you started using it right away, then you'd have all your e-mails going to someone else.
There might be more reasons...
I don't see how e-mail confirmation can be counted as "wasted seconds." It is to protect you. It's like taking a backup of your website. Many of them don't do it, because the few minutes it takes doesn't sound worthwhile. However, if the server crashes and your data is lost, only then you realize that those few minutes could have saved months of efforts.
Re: It's Time To Kill New User Confirmation Email Links
#44The same tactic (along with 1x1px images etc) was already used by spammers to determine "alive" addresses, whose owners do read spam and do click on provided links.
That's the reason I'd be very annoyed if I'll get such email.
Re: It's Time To Kill New User Confirmation Email Links
#45Re: It's Time To Kill New User Confirmation Email Links
#46"When I’m checking my email, the last thing I want to do is context switch back to the app." Umm you are signing up for a service, when you click the "register" button, you are usually presented with a message "check your email for a confirmation link" so you go do that. Where is context switching here? Most of the users don't signup for something and then forget about it until they, by accident, stumble upon the ema…
I agree. When I sign up for a service the confirmation email is generally already in my inbox by the time I switch tabs to gmail. Then the confirmation link takes me back to the site and logs me in, no hard work involved. Also, I've never registered for a service and decided not to immediately check my email to activate my account when I'm prompted to. I can't recall a single time when I've come across a confirmation…
Re: It's Time To Kill New User Confirmation Email Links
#47Let's say that Shutterstock wanted to expand - they want to allow new users to download ANY two images they wanted for free.
Would you advise them to go with a confirmation-less email routine? If so, how do you prevent bots from creating bogus signups and then (a) stealing your images at will, (b) so that they can resell/rehost them in Russia/China and make money/compete with you, and (c) clogging up all of your bandwidth?
For example, the bot signs up with 00001@gmail.com then downloads 60MB files while another bot uses 0002@gmail.com then downloading 60MB in files, etc.
And please - no solutions that require manual intervention or cannot scale.
Re: It's Time To Kill New User Confirmation Email Links
#48Earlier quoted context omitted.
The author addresses the first issue in the paragraph preceding the one you quoted. As it currently stands, most 'confirmation e-mails' I get also provide an 'if this isn't you' section. All the author is arguing is that we can do away with the confirmation part and keep the 'if this isn't you' part for those edge cases where a person's email address has been used by someone other than said person.
But the "if this isn't you" part could be a scam. It would make you click on a link in an email you did not request, which is a bad idea.
Re: It's Time To Kill New User Confirmation Email Links
#49For all of you folks who say that confirmation emails are a bad idea, let's talk about a service in which the user can download large files once they are "confirmed". I'm thinking of a site like http://www.shutterstock.com/ . They offer two free downloads per week and those files can be up to 30MB each. Let's say that Shutterstock wanted to expand - they want to allow new users to download ANY two images they wanted…
Now, you might detect that bulkdownloadrobot.biz is a bad domain and blacklist it, but all I have to do is to register a new domain each time that happens.
So now you implement a heuristic that detects patterns of signups from domains. Now, I start buying Gmail accounts created by workers in a CAPTCHA-solving sweatshop.
You've increased my costs slightly, but you haven't solved the problem.
Re: It's Time To Kill New User Confirmation Email Links
#50Earlier quoted context omitted.
Email addresses may be unique at one point of time, but assuming that they are unique identifiers for people is problematic because they can legitimately change hands. For instance, my work email address is @ . I'm not the first at - the other one left before I joined, but two months after I took over the email address I'm still clearing up the accounts with services that made an identity assumption over email addres…
Isn't there a problem if you sign-up to services with your "temporary" work email? Get a gmail account and sit on it, what's wrong with that?