Don’t require a user to be interested twice: lessons on reducing signup friction
bbirnbaum.com
bbirnbaum.com
If someone can’t be bothered to click a verification email, then removing that step is not going to magically turn them into an active user. More likely they will be one of the many people who leave after a few minutes.
I do a signup/onboarding optimization for startups, and here’s what I found from a recent project:
1) The verification email was NOT a significant bottleneck to signups. That is, most people clicked the link.
2) Removing the verification step did NOT have a meaningful impact on conversion rates.
If you don’t have a problem with user quality then sure, avoid the verification step. But if you have a good reason for the verification step then don’t sweat the drop-off rates.
And more importantly: Treat signups as a leading indicator of success, not the ultimate goal.
Edit: On second reading I see the author is talking about a verification step that requires an admin approval, which could take hours. Yeah, don’t do that.
I'm looking at you, Mint, who sent me someone else's financial data for months and months, and did not have an unsubscribe button (outside of user account preferences).
If a gamer uses my email address to sign up for a service, I'm gonna log into their account and change settings. Or once, in a mood, just delete their account (many services use email address as an identifier, so you can't use that service if someone used your preferred email address). I figure it's like someone accidentally giving out your number in a bar to get away from a creep. You just happened to lose the random digit lottery.
I'm never going to log into someone's financial system to do that. You're crossed a line from petty vigilantism (under duress) into "this is starting to resemble a felony" territory. It took ages to ask the right question of Mint support to get them to do something about it. And really, fuck anyone who puts people in this position in the first place.
If you are sending communications to a user repeatedly, you believe you have a relationship with them whether they want it or not. If you are collecting sensitive data on them, and then telegraphing it in those communications, then verify their goddamn contact information first.
Or, stop trying to have those conversations over unauthenticated channels.
[edit to add: and then there was the lonely guy who signed up for eight+ dating sites while I was in a rough patch with my partner and I had to scramble to unsubscribe lest she think I was planning my escape. Seriously dude, not cool]
But as I was trying to express what a bad idea it was and why they needed to do more than just fix my particular issue, I realized that I shouldn't have to explain this at all. And once I started questioning if maybe I was the greater fool for thinking that they would magically sort it out once I was a customer, I just got them to stop sending me someone else's budget information and never talked to them again.
But the internet is full up of stuff like this. That's just the one that was the most memorable.
Same deal with dating websites and job search sites, I had a guy use my email to sign up for what must have been a job aggregator. I found out about 15 different websites had "10 new opportunities waiting" for me.
It boggles me that there is no double opt-in for something like your children's school attendence.
Unfortunately, I wasn't able to recover and delete their account because I didn't have any of their other sign-up information. You make a good point about this action resembling a felony.
Like the credit card statements I am getting from an Indian bank with no contact apart from an international phone call to India which I will not be making. And I can tell you the default encryption passwords they use on their PDF attachments is not particularly secure.
- Slack used to (they still might I just haven't created a new workspace in a while) have Slackbot message you to setup your profile so that you're literally using the software as part of onboarding.
- Aircall has you get a phone number and place a call directly from your browser, then use your phone to call that number back and have it ring in your browser.
Focus on the the path to that magic moment first, ensuring that users who do sign up have an incredible onboarding experience and understand the value.
Otherwise, you're just pouring water into a leaky funnel, and you might end up even worse off. You'll spend the same amount of time and money on support for your leads, but few of them will ever convert to dollars.
You also see a similar thing with mobile apps that have a forced tutorial/onboarding intro.
Just keep in mind that every thing that you force users to do as part of onboarding is going to be annoying, and especially for users which onboard multiple times for whatever reason. Even just mobile apps repeating their first-use tutorial when you get a new phone is enough to drive a man to drink.
This reminds me of the phrase “don’t sell past the close.” Once you have the user, focus on keeping them not selling them further. Many services have a way of saying “I’ve used this before” to skip the tutorial, for example.
Matches: from:(notification@slack.com) "you have a new direct message" "from your conversation with Slackbot"
Do this: Skip Inbox
This rule might be harmful if Slack ever sends both Slackbot DMs and real-user DMs in the same email, but my guess based on emails I’ve received in the past is that Slack doesn’t do that. Before activating this rule, you can search your own email history to see if any useful emails you received in the past would have been hidden by this rule.
If you have any contact method for the user (email, SMS, phone) you should be doing some level of verification on it. Users are clumsy, some of them don't know or mistype their own email addresses, phone numbers, etc. Verification ensures you're talking to the person you expect to be talking to.
I may be the only one with the following experience so please bear with me.
I use lastpass to generate passwords and save my credentials to use on websites/apps. While for many sites I will never use the site again, in some cases after some time I find myself back on a site I had registered on before.
It may be because the site has added new features or it could be because my condition has changed. (I would like to say I came back because of the work that the website owners did in marketing/new features etc).
I am not involved in this sort of thing from day to day but I think that one should also track "𝒔𝒉𝒆 𝒅𝒊𝒔𝒂𝒑𝒑𝒆𝒂𝒓𝒆𝒅 𝒇𝒐𝒓 𝒂 𝒚𝒆𝒂𝒓 𝒂𝒏𝒅 𝒂 𝒉𝒂𝒍𝒇 𝒂𝒏𝒅 𝒉𝒂𝒔 𝒋𝒖𝒔𝒕 𝒏𝒐𝒘 𝒍𝒐𝒈𝒈𝒆𝒅 𝒃𝒂𝒄𝒌 𝒊𝒏"
Actually that’s why I run “thaw campaigns” to reactivate past (now inactive) users. Something as simple as a reintroduction email to users who’ve been inactive for 6+ months, calling out new features and benefits and success stories. It brings back a lot of people like you, whose situations changed and might now have a use for the product.
I noticed you said "meaningful" impact and not "no impact". If your optimizing this seems like the best of both worlds in the slight increase of conversion and the security of verified email?
Good point....unless you're someone who's been incentivized by a higher up to optimize for this metric because that person or someone above them (maybe a VC) forgot this!
Professional and personal life obstructed this, and I've since moved on, but I'm glad to see _someone_ preaching that signup optimization isn't the holy grail.
Bots? Idle new accounts are probably deleted after a number of days. Password? A reset/creation link can be sent to your email the next time you try to login. Payment? That's only important if you're going to use the software -- it can be handled when appropriate.
Unless your service has some major expense or limited resource associated with account setup (ex. assigning the user a new phone number), I would love to see more signups like this. The lack of friction made me feel so happy as a customer and I instantly had a positive impression of the service because it already felt like it was adding value by making my life easier. I wouldn't be surprised if this also has a positive impact on their conversion rate.
I've seen services forget that, and then it's possible to sign up with someone else's email address, use the account, and have someone else get spammed or harassed. That needs to be part of your threat model. "What if a bot signs up" is about protecting your service and people using it. "What happens if someone signs up with someone else's information" is about protecting other people, who may have nothing to do with the service.
If I get an unsolicited email for a service I don't recognise, that has a link in it and a message asking me to click on it, should I click on it?
Commmon advice is don't click on links in mails you aren't expecting. It just confirms your address is real for spam harvesting.
I'm also not sure what you're afraid of. If your account has been in existence for long enough, you already get a lot of spam. It just gets blocked or filtered. The vast majority of your emails that actually get to your inbox are from people trying to do the right thing, not people trying to screw you over.
My bad for lack of clarity.
I meant whether the address has a person reading it, making it a more valuable target, perhaps added to a commercially sold database.
I don't know if or how much this happens. But it's obviously an available signal.
> If your account has been in existence for long enough, you already get a lot of spam.
True! I got 6000 spam a day at one point. Thankfully it went down to 1000 a day and has slowed since.
> It just gets blocked or filtered.
Unfortunately not so well. The vast majority is filtered, but that still leaves too much getting through (I got about 80 in the last 45 hours), and in conjunction with such a high level of false positives that good things go to the spam bucket, a problem both as a recipient and a sender.
Gmail is not immune either; I often find critical false positives in my Gmail spam folder.
Spam is not a solved problem, and the solutions are causing other problems.
I don't have solutions, but I don't agree that it's "just" blocked or filtered. If only email was that reliable!
I don’t think email works the way you seem to think it works.
The messaging is not standard so you have to do all sorts of special case parsing because each provider can give a different message. And ignoring these messages will hurt your ability to deliver email.
So if your plan is to hide your address from people, again, I don't see the point.
"Email providers already tell people sending email when an address is real or not." suggests a level of reliability of signal that simply doesn't exist. I have an infinite number of email addresses that you could send to, which would not give you a bounce, and none of which will reliably land in front of a human's eyeballs.
I'm sure Apple is good about this now, but many years ago someone had used my Gmail address for their Apple ID. I wanted to switch my Apple account to use my Gmail, but couldn't because someone else's account used it. Support told me they couldn't do anything about it. I don't know why it didn't occur to me to do this first, but I just reset their password, changed the email address to something else, and reclaimed my email.
I understand it’s the other user’s fault for using your email address in the first place, but I wonder if you could have contacted them to warn them about the change (since they would lose access to their Apple account instantly, with no recovery option). I’m not blaming you. I’m just wondering how it would be done, if needed.
I assume that user, when signing up with your email, either a) made a mistake b) was being unhelpful c) or didn’t understand he whole email/ID concept.
https://www.ftc.gov/tips-advice/business-center/guidance/can...
From what you said it appears every single one of their emails is a violation.
I don't know how much time it will take you to actually pursue that or whether it will be worth the time, but I'm sure lots of people will be very happy if you make Comcast lose a bunch of money.
Nope. I will never click a link in some spam mail I receive. Even if you claim that your service is "legitimate".
If you want to be allowed to email me, you must often a double opt-in. And that is a click to confirm the address.
Many services don't send regular emails, and only ask for an email so that 1) everyone has a unique identifier without having to make up a unique username, and 2) they can do password resets. For such services, the procedure above makes sense to reduce friction.
That happens to me all the time as I have a very generic email address (one of the first users of Gmail). Someone seems to have registered to Facebook with my email and now I can't disassociate it. People searching me by my email address on Facebook end up with that random guy.
They don't think "Reset password" applies to them. Why should they reset their password when they next login if they never made one in the first place etc...
The other day when Google was having issues (the same day that a bunch of Android apps were crashing due to a bad map data push), I was unable to log into my bank, unable to pay my electric bill, and a half dozen other things I needed to do that day.
Because Google's servers were down, core service providers were unable to do anything either because they block access to their site without recaptcha approving the entry.
To me, as a technologist, as a builder of software, this is absolutely and entirely unacceptable. Captcha needs to be something you can self host.
I don't understand this habit of handing Google a knife and then telling them where to stab you.
- We started out with self generated and self hosted captcha. It was too easy to beat. Complexity of the image generation turned up until eventually it was easier to just outsource it to someone else. Going to throw out a guess here that reCAPTCHA is far from simple, and likely exceeds what most teams would want to run internally.
- Google has an uptime that's significantly higher than most companies. I'm not defending any of Google's habits or business practices, but I personally wouldn't bet that most companies can run software more reliably than Google.
- As someone else mentioned, fail open is an option in situations like these (depending on the threats you're trying to protect against). For something with a high probability of failure, this could make sense, but I would have a hard time imagining a team allocating time to deal with the case "when Google is down" unless it's truly life or death software (think: surgical robots, autopilots, etc)
I found that generating math questions in a captcha style (curved / with other noise drawing over) and requiring that questions to be answered in a box is unbeatable. The bad actor would require very good OCR and after that also good math parser to answer. Easy for human, very hard for automation. And the script was like 50 lines long that did that.
reCAPTCHA changed to its current model to try to significantly reduce friction in the "hopefully normal" case (down to just a check box if all goes well) because every ounce of friction you add to critical inflection points in your product translates to meaningful lost opportunity.
Even if this wasn't a problem, and it were trivial to create something that's easy for humans and hard for computers, it's just not worth most companies' time. Would they rather spend a few days properly implementing and testing a captcha solution, then whatever unknown time on future bug fixes and support, or setup reCAPTCHA in 30 minutes and move on to things that produce value for their customers?
As for visual impaired ones, I agree this one is harder to crack. Usually you do it by audio, which in itself is more then 50 lines of code, but here is my personal approach. Absolutely none is stopping you to have, for visual impaired ones, a separate step like the one described in OP, where you have mail activated. You see visual impaired users have infinitely more patience then normal "visual" ones. They are used for web to not be friendly, so they won't mind going through extra hoops if they want your service. So a checkbox saying "I am visual impaired and I want registration by e-mail" or something equivalent and you're good to go.
Was this a mistake on the bank's part, or Google's?
Even if it's not Google's reCAPTCHA - is it so hard to make something like this that only Google can provide it? Surely the big players would want this component under their control exactly for reasons like "we don't want to have an outage due to a provider outage". Or at least, fail over to a less-preferred backup. Like if Cloudflare had such a service.
https://blog.cloudflare.com/moving-from-recaptcha-to-hcaptch...
My bank once required me to fill a reCAPTCHA to change my password. Yes, Google's tracking on my bank's website. I asked my financial adviser to reset my password for me to increase the cost of using reCAPTCHA for my bank. I told them it didn't work because of reCAPTCHA not working on my computer, which is actually true because I block it.
Some are using reCAPTCHA to detect bots, but I see many sites that appear to be using it specifically to slow down users. Users are to be respected but customers are to be mined for their money. Sometimes that means making things more difficult than is strictly necessary. If an onerous reCAPTCHA is required to delete an account or qualify for a price discount, so be it.
There is a reason it is so much more difficult find one's way out of a casino than it is to walk in.
This is basically how "e-stamp" system proposals were supposed to work for email; but they never took off because email is an ossified system. The web is not ossified; individual websites are free to implement something like this.
If you're worried about spammers just throwing a GPU farm at the problem: the overlap between spammers and people who own crypto-mining operations is small; and the people who own crypto-mining operations have much-more-profitable things to point them at. So this should mostly stymie spammers—individuals will be okay with sitting around on the page for a couple minutes to complete the action, but it'll throttle spammers' actions way down, to the point where it's mostly not worth it to attack that site any more, vs. some other site (i.e. it'll have the same relative-deterrent effect that putting a club on your car does.)
You could even frontload the work, turning it from a proof-of-work system into a proof-of-stake system. Have the user "buy in" with a large hash workload during user registration; and then trust them from then on. (This is the better approach for a mobile app: direct them to register on the app's website on a PC, and then you can trust that user on the much-lower-powered mobile device, despite that device never generating a token.)
-----
An effectively strictly-equivalent approach is to just charge the user a dollar to complete certain actions.
One famous example of this is the SomethingAwful forums, where registrations cost $10. You can register as many times as you like—i.e. if your account gets banned, there's nothing stopping you from just coming right back again—but you'll need to pay another $10. Seems to work fine, in terms of making it too costly to keep doing anything the site bans people for.
Charging a buck is extremely simple, and fair. The SA example tickles me.
I wonder if the folks who dislike reCAPTCHA would be willing to choose to pay $1 if given the option between the two.
Another commenter said that the market rate for reCAPTCHA solving is 1c each, so $1 is probably more than most would pay.
You may not agree and I respect this, but this is actually my point (and I don't have an answer to this question - I wish I had, though, and you have a point!).
I wish that people stop thinking soon that reCAPTCHA is a solution at all.
Then, it will open people to start thinking hard on this problem and hopefully find good solutions that fits their exact situation. There may not be one size fits all, but many good solution for each situation. We would not know without thinking.
I wonder if you could ask the user to trace a shape/pattern with their mouse? Or you draw a few animating dots with a canvas, and ask them to click the blue ones?
Fundamentally, though, you likely either piss people off by challenging their humanity, or violate their privacy by silently tracking their behavior, or break accessibility by evaluating the way they interact with your site against "normal" (bad for folks with screen readers, lynx, etc I'd assume).
If you want to solve this legal is your best bet. Make the things bots are doing illegal, and then track down the owners. It is hard but the criminal system is the only thing we have.
Absolutely a no-go: let me first try it for free and then I will add the credit card details, if I'm interested
Good friction (verifying emails, asking a question in the signup form, collecting a CC upfront) can result in more paying customers as you’re optimizing your experience towards people who are actually interested in buying your service.
Rather than trying to cast a wide net and wasting resources on poor leads who want zero friction.
So, without that step, you can't say "has nothing to do with hoping people forget to cancel."
But for any business that requires some amount of human support for users, it can be much easier to convert 15 out of 100 signups than out of 1000.
There are other components. Credit card entry acts like a captcha, but it’s actually a useful part of the process (unlike clicking street signs).
And the marginal cost of a free trial is low, but it’s not zero. If I can have less free trial customers but end up with similar paying customers, that’s a win.
There’s not only one reason.
If you really think a captcha is necessary, limit it. For example, require that a captcha is required for two account registrants with a 24h period from the same ip. Don’t require captchas for logins unless a reasonable limit of attempts has been exceeded (5 wrong passwords within 24h by the same ip for example).
If your site is small, a captcha is often overkill. A hidden input can trick pretty much any automated spam bot (if input empty, real user, otherwise bot). Just make sure you do enough research so accessibility readers also work with that field properly.
If a spammer targets you, you can always active a captcha manually, although by the time you realize it, it might be too late.
Keep in mind that a captcha only adds friction to the spammer (and users). Bypassing reCAPTCHA is possible for any motivated spammer for only a few cents/captcha. There are services that have humans in developing countries solve them for you. Coupled with a headless chromium, you can easily build a reputation so that google will let you through. For testing credit cards, this setup is definitely used and most likely worth it. So a captcha will not always save you from bots.
Also keep in mind that hacker news does not have a captcha and the amount of spammers is minimal.
2. Identify a target for some kind of account takeover attack. (Assuming you have other details needed for takeover.)
3. Rent botnet.
4. Perform thousands of signups for the target's email address starting shortly before your attack.
If the account's only security notifications (e.g., password reset, etc.) are in the form of emails, the flood of spam will usually keep the target from seeing them until too late.
These are real attacks, frequently seen in the wild.
In any site that creates a community or has any kind of interaction between its users, spammers and spambots will ruin the site for everyone else.
It's hard for me to take people seriously who rail against recaptcha yet don't seem to realize why we use it nor pitch a real alternative. Or that spammer protection is overrated because their obscure blog doesn't get much spam.
It's easy to enumerate what sucks about something, but you can't just stop there.
Depends on your size and resources. Imagine you're basically scrappy with a very small and tight budget and still trying to validate your idea, and you're using one of those providers that gives you a free quota (like Google App Engine), you don't want 'spammers' to drain your free allotment of resources. I know someone who has a small niche blog in the health sector whose blog was repeatedly targeted by spammers/bots. He repeatedly saw increases in his bills till he had someone audit his blog and try to block the bots
I have found that simply throwing a reCaptcha onto your form forces you to make a bad choice between protecting the user's privacy and creating a mostly-seamless experience: if you don't want most of your users identifying school buses, you need to send all their behavior to Google.
To get around that, I've tried layering a number of different approaches. These include outright throttling/blocking repeated form submissions from the same ip; using a honeypot field; using a third-party email verification/validation service; showing captchas only under certain very restrictive circumstances (heuristics that make a guess/overall traffic patterns); etc. It's more work, and still a bit cat-and-mouse but at least I don't feel like I'm pissing off every potential customer
I have seen spammers signing up just to send short message via welcome email ("Hi firstname," -> "Hi check this foo.com,") to their targets. The worst thing that can happen from that is that your domain/email servers end up in the blacklists.
For the majority of users, they won't see a captcha challenge and it is a seamless experience with no added friction.
Those who have lots of tracking/privacy protections however will more likely be flagged as a potential bot and usually have tougher challenges as a result.
And it achieves that by surveilling all user activity on your site, not just on the signup form.
>reCAPTCHA works best when it has the most context about interactions with your site, which comes from seeing both legitimate and abusive behavior. For this reason, we recommend including reCAPTCHA verification on forms or actions as well as in the background of pages for analytics.
https://developers.google.com/recaptcha/docs/v3
A privacy minded programmer/company might restrict the scripts to the minimal set of pages, but I'd imagine most sites would blindly follow that advice and put it on every page because they think more data = better.
This usually stops simple spam bots that are aimed at that particular off-the-shelf forum software.
Manually approve someone who registers ... then discover they're a spam bot?
I recently had an incident with Chime Bank like this, where someone enrolled every public email address at my company with them. I sent them an abuse report and they told us to block their domains. Real great solution, guys.
I was getting questions where I'm just not sure what the right answer is.
Which pictures have traffic lights? And then some pictures where I can barely make out a traffic light far away in the background. Does this count?
Which pictures have busses? Is the blurry white vehicle a large passenger van or a small bus? I don't know.
Then the most absurd one, I was asked to select tiles containing a bicycle, on a picture like this:
https://www.bikecleveland.org/wp-content/uploads/2015/04/Sha...
Does a representation of a bicycle count? I don't know.
And then when there is just a few pixels of an object going into a tile, am I supposed to select it?
Here's a video (not mine) of the sort of thing I mean: https://www.youtube.com/watch?v=GGBsopLvwwo
Likewise. It's randomly difficult to get through, and if you have third party content blocking it just doesn't show up. I just hit back pretty often just counting the times I knew it was there any was a reason the page wasn't working.
Originally:
> Users couldn’t get started on their own. They had to first leave their email address and then wait for me to send them an email with a link allowing them to register and start building their Cortado email.
Afterly:
> As soon as users click the submit button, they get an email verification message in their inbox, which they can click on to set a password and get started.
So, what changed? In both cases users have to submit their email address and interact with a(n) (automated?) registration/sign-up email. In the second case there's the added hurdle of a captcha (which sounds worse).
With the new process, they go through the signup process immediately.
"wait for me" literally means "wait for human to create email and send it to new user".
Wow, yeah. That doesn't seem good.
When a product is really early - still being developed, basically - you want to control the number of users you expose to it.
Every batch of users will improve the product but it is unlikely that users will stick around beyond one or two uses.
So you drip it out to users in small batches, and "wait for me" really lends itself well to this.
Someone invites you to a conference and you just click the link, enter your name and go.
Imagine what Zoom would be like if you had to sign up, verify your email, schedule a meeting, and then invite people to that meeting.
I think they drew the wrong conclusion from their data. I don't think it was the double signup that was the problem, it was the delay between signing up and getting the confirmation email.
I think the real lesson here is that confirmation emails need to be short (addressed in the article) and quick.
I know that if I don't get the confirmation email within about a minute, I give up.
• Let users use the product immediately after registration (if possible). Don't make them wait for the verification email. Can haunt them with pop-ups afterwards to get that verification and double-opt-in.
• Support single sign-on via Google, Facebook, Apple, Twitter, etc.
• When people try to login unsuccessfully (wrong password), send them an email to login via a link. This was a big growth hack for Uber to increase reactivation rates.
I have a <common-name>@gmail.com account and get to see the shitshow that happens when people signup for services don't validate email. Many people screw up email entry and end up with accounts outside of their control.
What I see, every year:
- $50-200 of gift cards emailed to me from a guy in Australia.
- Various memberships for gyms
- Various loyalty programs.
- An active airline points program, which sent a password request in cleartext a few years ago.
There are a number of popular web services (Spotify was the most recent) that I haven't signed up for because they keep asking for information I don't want to give them or had to think about, such as gender. Every time I'd start the sign-up process, fill in some information, then be confronted with a question where I wasn't sure what the answer was or why I needed to provide the information, and give up. This even delayed me creating an email account by about a year.
Agree. This is especially important today where information is being traded without user's knowledge.
Asking for information you don't need automatically makes privacy conscious folks suspicious of your site/service.
It also gives the impression that you (the business/service) haven't 'thought' through your process (maybe you just did a copy and paste from a template somewhere)
i thought everyone was giving junk info to all the websites. :)
I highly recommend reading "Don't Make Me Think, Revisited: A Common Sense Approach to Web Usability". It doesn't take long to read but is packed with wisdom. It covers the points that Ben makes in his blog post.
https://www.amazon.com/Dont-Make-Think-Revisited-Usability/d...
20 year old me after putting on some AXE body spray
It honestly amazes me how often I see this. No screenshots or even a description. Maybe a line or two and the page looks mostly like an email scraper. SELL ME YOUR PRODUCT.
PNG/8 or any decently compressed JPEG format will work if you have bandwidth limitations.
I clicked on Try it free expecting to go from a typical startup Wordpress site to a JavaScript signup form where I’d fill in an email, password etc.
Instead, bam, I’m in the app with an anonymous account and ready to roll. A big button up top lets me add my email and password later if I like what I’m seeing. Really nice work.
Use federated login. Almost everyone has an account somewhere - Facebook, Amazon, Apple, Google, Github, Twitter, Microsoft etc.
https://www.bart.com.hk/why-you-need-to-be-very-careful-abou...
What happens with multiple login choices is people forget what service they used, or end up accidentally creating another account (if it couldn't be auto-linked), or delete their fb/twitter/whatever and then lose access to things they didn't intend. Or get banned and forcibly lose access.
It also means you're relying on more 3rd party dependencies. And having the overheard of managing those, keeping updated with API/policy changes.
It's one of those things that seems simpler at first, but ends up being more complicated on both sides.
It is great because the friction to start using the service is low but you can add additional stuff after you know that you want to use it. Few services do exactly this. They will lock down your account and ask you to add a password after a day.
The support surface only increases over time and we found it not to be worth it.
These systems usually put log in and sign-up in the same flow so they are really saying:
"Do you remember if you signed up before? Which one of the 7 ways of we're presenting as an array of 4 or so buttons with secondary account selectors did you use?
If you pick the wrong one now you're going to get another account and have multiple discounts, reputation, credit, etc to manage.
Good luck!"
If you're lucky enough to still have the welcome email it'll sometimes narrow it, but not really. If I clicked on Facebook, selected my business account, then I'd get email in a Google account, which is exactly what I'd get if I had selected Google and the business account directly.
However, that's a different service and a different token which is usually enough to mess things up and create a different account.
What's worse is often if you're not logged in and then you get prompted to create an account in the flow. Let's say you haven't been there in 5 years.
Now you don't know if you've signed up or not so you Russian roulette yourself and if you're lucky, this time, it'll be a new account.
Because if it's the 5 year old account often it'll trigger all these legacy catch up things "oh redirect to the new terms of service. Give tour of new website, notify about mobile app, what were we doing? I completely forgot"
On Priceline for instance, if you sign up for a credit card to get $100 off the flight and then click an existing account to complete the transaction and not a new account, it gets completely confused and your discount vanishes.
It's a complex solution for a simple problem that appears to be friendly but in practice becomes user hostile because it's creating mountains of edge cases most have no interest in fully supporting.
It also gives a very poor understanding of how many human users you have. Those account creating metrics sure look great! Then you dig in and realize a bunch of people have 3 or 4 accounts, mostly unwittingly because there's an interface to encourage creating multiple unconnected accounts.
They don't realize it. They'll be on one device and stayed logged in. Then they get a new phone, forget how they logged in and bam, new account.
Your users would really prefer if it was just 1 account. A lot of your support load would go down if it was 1 account, you'd get better sales, have higher reviews, but here we are anyway.
And in the end, with a bunch of choices it's just another form of the memory game, which is the same cognitive user flow of the password, since 99% of users just reuse a handful of passwords on every site.
What makes it worse is even though only one flow in the multiple login system is the one you want, every other one will still work.
It's like being forced to take home the goat in a web version of Monty Halls Let's Make a Deal. Instead of seeing an error you're stuck with a new account that nobody on any side of the business flow wants.
Don't pick a name for your service that when googling it results in a full page of links to the coffee style and not to your service. (So how do I actually visit Cortado??)
EDIT: Found it after clicking around to your About page: https://cortadomail.com/
And what's the stack?? :)
How many of these were real losses and how many were people who put the wrong email address in the box, only to realize when they didn't get the verification email?
I have a very early gmail address, first initial + last, name. I can't tell you how many verification emails I get that I never signed up for. Those aren't the bad ones though, the bad ones are when I get emails about Kay's upcoming surgery and follow-up appointments, Kim's yarn orders and Ken's mortgage documents. (All of these are real examples).
Strong email verification flows aren't just anti-bot. They're a level of defense against clumsy users.
But regarding "signup friction" – the best way to reduce signup friction is to eliminate the need for signups.
I'd like a version of Cortado that was hosted and just used a URL rather than sending junk into my inbox. Maybe call it Cortado Reader or something.
Or better yet, some sort of syndication protocol (we could call it RSSS for Ridiculously Simple Syndication System) for the web.
ReCaptcha may be seen as useful to cut down on the number of bots but it screws things up royally when trying to navigate in private mode, or using a VPN.
Seconding this. As a holder of firstname at a-mainstream-email-service, I've had to unsubscribe to mailing lists far too often.
If a service doesn't offer me a way to unsubscribe, sometimes I have to recover the offending account's password and request for the account to be deleted.
I have never had to deal with that.
And then hitting "Yes" does just that, and I'm in.
The same workflow could be used for shipping info and CC info.