Ask HN: Why haven't signup confirmation emails died yet?
What is the point and why hasn't this practice died yet? Are there any benefits I'm overlooking here?
What is the point and why hasn't this practice died yet? Are there any benefits I'm overlooking here?
And after they have submitted their details (which should only be critical information — seriously, nobody likes long forms.), don't send them to a dedicated "Thanks for registering" page, its a waste of time for them for them, just take them to the homepage or where ever the magic happens, and present a banner above the content thanking them and giving any info they may need.
And overall, don't get too defensive on spammers; Lets face it, your not going to get much spam until your site is popular — so go easy and don't frustrate your users, and then tighten your defenses later down the line if required.
Those are my post-signup "rules". I love working out how not to annoy users even slightly — sadly a lot of sites don't do it very well! :)
This is exactly what we did at a popular site I used to work for. Let them in, let them go crazy, but have a "time's up!" period and a few restrictions to stop spammers.
That said, we don't do it at Justin.tv, and I think it's stupid.
2. Makes it so you can't sign someone else up surreptitiously
3. Ensures the email they enter is real
Depending on the site, these may or may not be a concern. For some sites, the drop-off rate is worth the reduction in support hassle.
2. Makes it so you can't sign someone else up surreptitiously
For some sites, the drop-off rate is worth the reduction in support hassle.
not all apps need this, so not all apps would necessarily want to use it. but if yours does, there's not really a good reason to specifically avoid using them.
just a tool in the toolbox, as it were.
I understand that it is the default settings of most blogging software, but that doesn't make it right :-)
If anyone can come up with a single valid reason why the information should be mandatory, it would at least ease my frustration.
On the other hand I have properly signed up for more than 10 times as many free services as I pay for.
For something like a paypal account, verifying your email address makes sense, if for nothing else making sure you made no typos. But for most simple sites the confirmation email seems like overkill and an unnecessary extra step.
If its to prevent spam, this is even easier to automate then cracking captcha. If its for making sure the email address is valid for future annoying emails. Just give people a reason to want email from you and they will be more then happy to use a valid address.
Quick registration and getting someone on the site as quick as possible should be the number of priority. Get rid of long registration forms and confirmation emails!
You're missing my point. When sites don't require people to respond to registration confirmation emails, I can sign up using your email address, resulting in you getting a flood of spam.
This battle was fought in the early years of the spam war -- companies would send out spam and claim that people had asked to receive the email, and when anyone complained that they hadn't, the spammers would just say "oh, someone else must have signed you up". (For more background, see the spamhaus page on this topic: http://www.spamhaus.org/mailinglists.html)
Sure, it's easy to get around, but for most users they simply comply. That been said we don't use email validation on any of our websites.
The only benefit I can name is that it confirms your ability to communicate to the user if they lose a password, etc.
And, it probably incrementally adds to the value of your company (presumably a company would rather have 500,000 confirmed email addresses than 500,000 unconfirmed ones... Of course, given drop-off...)
Plus the reasons stated above, such as validating that the person submitting the email address actually owns it.
Item 1 of the "check list" is titled "Optional registration"
One that comes to mind from my own experience is if you need a valid email address for further transactions.
You can't rely on things like captcha's, not anymore. But requiring an email address is at least a small difficulty. And if you get a whole bunch of signups from a single domain in a short period (And it's not, say, gmail) you know something's up.