Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It’s a good lesson but let’s not forget that completing the signup is not the goal in itself. If you look at post-signup user activity you will find many users stick around for a few minutes and then leave, never to return again.

If someone can’t be bothered to click a verification email, then removing that step is not going to magically turn them into an active user. More likely they will be one of the many people who leave after a few minutes.

I do a signup/onboarding optimization for startups, and here’s what I found from a recent project:

1) The verification email was NOT a significant bottleneck to signups. That is, most people clicked the link.

2) Removing the verification step did NOT have a meaningful impact on conversion rates.

If you don’t have a problem with user quality then sure, avoid the verification step. But if you have a good reason for the verification step then don’t sweat the drop-off rates.

And more importantly: Treat signups as a leading indicator of success, not the ultimate goal.

Edit: On second reading I see the author is talking about a verification step that requires an admin approval, which could take hours. Yeah, don’t do that.



Also removing that step means that I get 'spam' that contains scary amounts of PID in it.

I'm looking at you, Mint, who sent me someone else's financial data for months and months, and did not have an unsubscribe button (outside of user account preferences).

If a gamer uses my email address to sign up for a service, I'm gonna log into their account and change settings. Or once, in a mood, just delete their account (many services use email address as an identifier, so you can't use that service if someone used your preferred email address). I figure it's like someone accidentally giving out your number in a bar to get away from a creep. You just happened to lose the random digit lottery.

I'm never going to log into someone's financial system to do that. You're crossed a line from petty vigilantism (under duress) into "this is starting to resemble a felony" territory. It took ages to ask the right question of Mint support to get them to do something about it. And really, fuck anyone who puts people in this position in the first place.

If you are sending communications to a user repeatedly, you believe you have a relationship with them whether they want it or not. If you are collecting sensitive data on them, and then telegraphing it in those communications, then verify their goddamn contact information first.

Or, stop trying to have those conversations over unauthenticated channels.

[edit to add: and then there was the lonely guy who signed up for eight+ dating sites while I was in a rough patch with my partner and I had to scramble to unsubscribe lest she think I was planning my escape. Seriously dude, not cool]


The irony is that I finally pushed the issue because I wanted to use Mint.

But as I was trying to express what a bad idea it was and why they needed to do more than just fix my particular issue, I realized that I shouldn't have to explain this at all. And once I started questioning if maybe I was the greater fool for thinking that they would magically sort it out once I was a customer, I just got them to stop sending me someone else's budget information and never talked to them again.

But the internet is full up of stuff like this. That's just the one that was the most memorable.


I feel you. I have {commonFirstName}.{commonLastName}@gmail.com and I get so much email intended for other people. Services that don’t verify email and require you to login to unsubscribe are the _worst_


Slight tangent: A lot of people might not know that periods in the first half of a gmail address actually get ignored when relaying. They're only there visually. Some services don't check for this and you can register multiple accounts with [email protected], [email protected], [email protected] which all get forwarded to [email protected].


Just flag them as spam. This hurts the service's deliverability. Enough flags and they'll get blacklisted. Services should always at least verify that you can receive the email (by sending a confirmation link) before they start sending you information or even creating a valid account.


My wife has [uncommonFirstName]@gmail.com as her e-mail address. Her uncommon first name is still sufficiently common that she gets a lot of other people's e-mails.


This has happened to me a number of times. I'm currently subscribed to an elementary school parent system for someone else's kid. So I get emails every so often about the child being tardy or absent. There's no way for me to stop these emails or communicate with the school or the parent. I gave up and just archive the emails as they come. They'll graduate eventually right?

Same deal with dating websites and job search sites, I had a guy use my email to sign up for what must have been a job aggregator. I found out about 15 different websites had "10 new opportunities waiting" for me.

It boggles me that there is no double opt-in for something like your children's school attendence.


The first is probably just a data entry error. A parent signs up on a sheet and then an admin assistant or teacher copies it into their system.


Ah, PayPal managed to let someone set my email address as their primary email address without any verification.

Unfortunately, I wasn't able to recover and delete their account because I didn't have any of their other sign-up information. You make a good point about this action resembling a felony.


In other news, setting up accounts for a financial service and not verifying the associated email address is beyond stupid.


The client or the business? Often this sort of thing is spoken over the phone and keyed in by a distracted staff member. Maybe the customer doesn't even know they're meant to be getting emails.

Like the credit card statements I am getting from an Indian bank with no contact apart from an international phone call to India which I will not be making. And I can tell you the default encryption passwords they use on their PDF attachments is not particularly secure.


Following on to this and hopefully making it more explicit: your goal should typically be to accelerate users towards their "magic moment" (the moment when the value of your software clicks, they get it, and they suddenly can't imagine living without it), as quickly as reasonably possible. A couple of companies that did a great job at this:

- Slack used to (they still might I just haven't created a new workspace in a while) have Slackbot message you to setup your profile so that you're literally using the software as part of onboarding.

- Aircall has you get a phone number and place a call directly from your browser, then use your phone to call that number back and have it ring in your browser.

Focus on the the path to that magic moment first, ensuring that users who do sign up have an incredible onboarding experience and understand the value.

Otherwise, you're just pouring water into a leaky funnel, and you might end up even worse off. You'll spend the same amount of time and money on support for your leads, but few of them will ever convert to dollars.


Absolutely. I've always been impressed with software that lets me get the magic moment first. E.g., online visual design programs that just let me try the tool in a sandbox. Or the way Github lets you examine and download software without ever signing in. I'm much more likely to give somebody something valuable (e.g., my contact details) if they've given me something valuable first.


You definitely need to think carefully about friction for repeat users on this kind of thing, though... definitely Slack is a peculiar case because of their mind-numbing user model that leads you to having multiple accounts. but I do consulting and as a result frequently get added to other companies Slack workspaces. The deluge of "helpful" messages from Slackbot sent repeatedly in each workspace is absolutely maddening and is one of the big reasons behind my hating Slack.

You also see a similar thing with mobile apps that have a forced tutorial/onboarding intro.

Just keep in mind that every thing that you force users to do as part of onboarding is going to be annoying, and especially for users which onboard multiple times for whatever reason. Even just mobile apps repeating their first-use tutorial when you get a new phone is enough to drive a man to drink.


Yes, this is a good point. Getting the user to their magic moment is not the only thing that matters for all customer engagement, it’s just the primary focus for new customer acquisition.

This reminds me of the phrase “don’t sell past the close.” Once you have the user, focus on keeping them not selling them further. Many services have a way of saying “I’ve used this before” to skip the tutorial, for example.


Regarding the problem of repetitive Slack onboarding messages, I recently created an email filter rule that I think should solve it for me. In Gmail filter syntax:

Matches: from:([email protected]) "you have a new direct message" "from your conversation with Slackbot"

Do this: Skip Inbox

This rule might be harmful if Slack ever sends both Slackbot DMs and real-user DMs in the same email, but my guess based on emails I’ve received in the past is that Slack doesn’t do that. Before activating this rule, you can search your own email history to see if any useful emails you received in the past would have been hidden by this rule.


As someone who receives new subscriptions daily from people around the world mistyping their email address (or intentionally entering an address they don’t own), I ask that you please DON’T remove the step of verifying people’s email address!


Yes! Every time you signup with an email you should have to verify. There's someone who consistently uses my email to sign up for all sorts of things (nearly every piece of mail has his name attached to it). It's actually quiet sad, he seems to be going through hard times right now, and started signing up for what are obviously get rich quick scams.


Same here. Also please make sure that your unsubscribe link works.


When I used gmail I used to have this problem regularly. I just marked every single email I didn't intend to receive as spam which hopefully lowered their rank.


> If you don’t have a problem with user quality then sure, avoid the verification step. But if you have a good reason for the verification step then don’t sweat the drop-off rates.

If you have any contact method for the user (email, SMS, phone) you should be doing some level of verification on it. Users are clumsy, some of them don't know or mistype their own email addresses, phone numbers, etc. Verification ensures you're talking to the person you expect to be talking to.


> It’s a good lesson but let’s not forget that completing the signup is not the goal in itself. If you look at post-signup user activity you will find many users stick around for a few minutes and then leave, never to return again.

I may be the only one with the following experience so please bear with me.

I use lastpass to generate passwords and save my credentials to use on websites/apps. While for many sites I will never use the site again, in some cases after some time I find myself back on a site I had registered on before.

It may be because the site has added new features or it could be because my condition has changed. (I would like to say I came back because of the work that the website owners did in marketing/new features etc).

I am not involved in this sort of thing from day to day but I think that one should also track "𝒔𝒉𝒆 𝒅𝒊𝒔𝒂𝒑𝒑𝒆𝒂𝒓𝒆𝒅 𝒇𝒐𝒓 𝒂 𝒚𝒆𝒂𝒓 𝒂𝒏𝒅 𝒂 𝒉𝒂𝒍𝒇 𝒂𝒏𝒅 𝒉𝒂𝒔 𝒋𝒖𝒔𝒕 𝒏𝒐𝒘 𝒍𝒐𝒈𝒈𝒆𝒅 𝒃𝒂𝒄𝒌 𝒊𝒏"


That happens a lot. You just get counted as a new ACTIVE user, which for the reasons described in my first comment may be a better success indicator than signups.

Actually that’s why I run “thaw campaigns” to reactivate past (now inactive) users. Something as simple as a reintroduction email to users who’ve been inactive for 6+ months, calling out new features and benefits and success stories. It brings back a lot of people like you, whose situations changed and might now have a use for the product.


I use LastPass as well, but they have crippled their free-tier product. you used to be able to view/generate passwords in their chrome extension, now you have to go to the website to view a password. Worse yet, the website is unusable on mobile. I would not recommend it to anyone now.


You're saying that they block the features of the extension for free accounts? Strange.


Are you sure? I have never had problems and use it in multiple profiles - one paid. https://www.lastpass.com/pricing


On the subject of email verification; Why not split the difference. Verify but give a 24 or 48 hours grace?

I noticed you said "meaningful" impact and not "no impact". If your optimizing this seems like the best of both worlds in the slight increase of conversion and the security of verified email?


> let’s not forget that completing the signup is not the goal in itself

Good point....unless you're someone who's been incentivized by a higher up to optimize for this metric because that person or someone above them (maybe a VC) forgot this!


About a year ago, I started in on trying to establish myself as a Trial-to-Paid expert, since it was a thing I had a fair amount of experience with, wasn't especially well understood or appreciated, and had _significant_ benefits.

Professional and personal life obstructed this, and I've since moved on, but I'm glad to see _someone_ preaching that signup optimization isn't the holy grail.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: