Article content and detailed guides remain in English. The selected language applies to controls and quick instructions.

Back to articles

Email Consent Types Explained: Opt-In, Opt-Out and What They Mean for Your List

On this page

Having someone's email address is not the same as having their permission to email them. Email consent is the basis for legitimate email communication, and different types of consent carry different levels of legal protection and practical reliability.

When you extract email addresses from files, the extraction step itself does not establish consent. The addresses you extract are data points. Whether you may contact those people depends on what kind of consent exists (or does not exist) between you and each recipient.

Understanding the types of consent helps you decide which extracted addresses you can use and how.

Express opt-in

Express opt-in means the person explicitly agreed to receive emails from you. They took a deliberate action: checking a box, filling in a form, clicking a confirmation link, or verbally agreeing.

Express opt-in is the strongest form of consent. The person knows who you are, what they signed up for, and that they will receive emails.

Where you see it: Newsletter sign-up forms, event registration forms with an email consent checkbox, account creation flows, written agreements that include an email communication clause.

Strength: High. The person made an informed choice. They are less likely to mark your messages as spam, and you have a clear record of their consent.

Single opt-in

Single opt-in means the person submitted their email address through a form or sign-up process, and they were added to the list immediately. There is no additional confirmation step.

Most web forms use single opt-in by default. The person enters their address, clicks submit, and they are on the list.

Limitation: There is no verification that the person who submitted the form actually owns the email address. Typos, fake submissions and malicious sign-ups can add addresses to your list that do not belong to willing recipients.

Double opt-in

Double opt-in adds a confirmation step after the initial sign-up. After someone enters their email address, a confirmation email is sent to that address. The person must click a link in the confirmation email to complete their subscription.

This verifies two things: the email address is valid, and the person who owns the address actually wants to receive your emails.

Strength: The highest quality consent. Every address on a double opt-in list is verified and intentional. Bounce rates and complaint rates tend to be lower because there are no accidental or fraudulent sign-ups.

Trade-off: Some people who sign up will not complete the confirmation step. This reduces list growth compared to single opt-in, but the resulting list is more reliable. See Double opt-in explained.

Implied consent

Implied consent means there is an existing relationship between you and the recipient that makes it reasonable to expect they would be open to receiving your emails, even though they did not explicitly sign up for them.

Examples:

  • A customer who purchased from you (transactional relationship).
  • A client who signed a contract with you (business relationship).
  • A colleague you have exchanged business cards with (professional relationship).
  • A member of your professional association (membership relationship).

Implied consent is weaker than express consent. The person did not specifically agree to receive marketing emails from you. They agreed to a business relationship, and email communication is a reasonable extension of that relationship.

Important: Different laws treat implied consent differently. Canada's Anti-Spam Legislation (CASL) recognises implied consent but gives it an expiration date: it lasts for two years after a purchase or the end of a business relationship. The GDPR generally requires a legal basis for processing that goes beyond implied consent for marketing. CAN-SPAM does not require prior consent but mandates an opt-out mechanism in every commercial email.

Opt-out consent

In an opt-out model, you may send emails to people until they tell you to stop. The recipient's consent is assumed unless they take action to withdraw it.

The US CAN-SPAM Act follows this model for commercial email. You may send a commercial email to someone who has not opted in, as long as you include a working unsubscribe mechanism, honour opt-out requests within 10 business days, include your physical address, and do not use deceptive subject lines or headers.

Practical reality: Just because CAN-SPAM allows opt-out consent does not mean it is a good idea to email everyone whose address you can extract. Recipients who did not expect your email are more likely to mark it as spam, which damages your sender reputation and can lead to blacklisting.

No consent

Some addresses on an extracted list may belong to people with whom you have no relationship and no basis for contact. An email address found in a public document, a directory or a file of unknown origin does not come with consent attached.

Sending to these addresses is legally permitted under CAN-SPAM (as long as you follow its requirements), but it is risky from a deliverability perspective and may violate other laws (GDPR, CASL) depending on the recipient's location.

How This Applies to Extracted Lists

When you extract email addresses from files using Email Extractor, the tool finds addresses. It does not evaluate or record consent status. That responsibility is yours.

Assessing consent for extracted addresses

For each extracted address, ask:

  1. Where did this address come from? The CSV with sources download from Email Extractor tells you which file each address was found in.
  2. What is my relationship with this person? A current client has an existing business relationship (implied consent). A random address from a public directory does not.
  3. Did they opt in to my communications? If the address came from a sign-up form export, yes. If it came from a contract they signed for a different purpose, probably not specifically for marketing.
  4. Which laws apply? This depends on where the recipient is located and where you operate. See GDPR, CAN-SPAM and CCPA.

Practical recommendations

For addresses with express opt-in: You are in the strongest position. Send as planned, with a working unsubscribe option.

For addresses with implied consent (existing business relationships): You have a reasonable basis for contact. Keep messages relevant to the relationship, include an unsubscribe option, and be aware of jurisdiction-specific rules (CASL's time limits, GDPR's legitimate interest requirements).

For addresses with no clear consent: Proceed with caution. If you operate under CAN-SPAM only, you may send with proper opt-out mechanisms, but expect higher complaint rates. If GDPR or CASL applies, you may need to obtain consent before sending.

For addresses on your suppression list: Do not send, regardless of consent status. A suppression list entry means the person has actively told you to stop. See What is an email suppression list.

If you have extracted a list of addresses where consent is unclear, you can build consent rather than discarding the list entirely:

  1. Send a single, clear introductory message explaining who you are and why you are reaching out.
  2. Include a prominent option to opt in to future communications.
  3. Include an equally prominent option to opt out.
  4. Only add people who actively opt in to your ongoing email list.
  5. Add anyone who opts out (or does not respond, if your policy is conservative) to your suppression list.

This approach respects the recipient's choice while giving you a path to build a permission-based list from extracted data.

Extract emails

Explore tools

Verify emails

Check address validity before using your list.

ZeroBounce

Email Verification

Verifies email lists and provides tools for monitoring deliverability.

Useful when list cleaning and sender health belong in one workflow.

Explore ZeroBounce (opens in a new tab)