Help · Audience

Verified identity

Every profile carries one of two marks:

This is not consent. Verified identity is about whether the person is real and yours. Consent is about whether they want to hear from you. A profile can have a verified identity and still not be subscribed, and that is ordinary. The two facts sit apart on every screen for exactly this reason.

Confirmed from the start — anything that comes from your store itself: an order, a checkout, a customer record. Your store is the authority on who your customers are, so what it tells the app is taken as true.

Confirmed straight away, from one of your own forms — when somebody fills in a signup form on your storefront, the address is checked at that moment: that the mailbox really exists, that it is not a throwaway domain, and that a real person browsing your store is behind it. An address that passes is confirmed immediately, and you can email them straight away — no confirmation email, no waiting for them to buy something. The welcome offer arrives while they are still on the page they signed up from.

Not confirmed yet — anything claimed from somewhere else: an email typed into your storefront outside a form, a profile pushed in through the events API, or a form signup where the check could not confirm the address. Anyone can type any address into a form, so until something backs it up, it is a claim.

Sometimes the check cannot confirm an address — the mailbox does not answer, or the checking service is briefly unavailable. When that happens:

Being unconfirmed is never a doubt about their consent. It is a question about the address, and the two are kept apart on purpose.

Catch-all domains are the one case with a setting of their own. Some domains — most work addresses — accept mail to any name at all, so the check cannot learn anything from them either way. By default, somebody on one of those domains who browsed your store before signing up is accepted and confirmed on that evidence, and the profile records that it was the browsing rather than a mailbox that vouched for them.

The switch itself is in Settings → Store, with the two numbers to keep an eye on underneath it. What it decides, what the trade is, and what "browsing" counts as are explained on the Forms page, under Catch-all addresses.

The moment your store shows the app the same email address — an order, a checkout, a customer record — the profile becomes confirmed. Automatically, and usually within seconds.

It only goes one way. A profile that has been confirmed is never un-confirmed. Nothing arriving later can walk that back.

You do not have to do anything to make this happen, and there is nothing to approve. Someone who signs up on your storefront today and buys tomorrow is confirmed tomorrow.

They are shown. They appear in the profiles screen with their mark, and you can open them and read everything the app knows about them. Hiding them would make your audience smaller than your store's own customer records with no explanation on any screen.

They are not counted. They are left out of every segment, every count, and every audience.

They are never emailed. No email you send through this app goes to a profile that has not been confirmed.

And they are never deleted on a guess. Being unconfirmed is not an accusation — it is the absence of evidence. Deleting the record would destroy the very thing that shows whether the caution was warranted, so the profile stays, and it upgrades quietly the day your store vouches for it.

Three problems, one answer.

Automated traffic. Public signup surfaces get hit by scripts that inject addresses which belong to nobody, or to somebody who never asked. Those addresses do not pass the check, so they land as claims — they never reach an audience and never receive a send. This is why you do not need to make every honest customer confirm by email. The usual way to keep a list clean is to send everyone a "click here to confirm" message, which costs you a share of every signup. Checking the address at the moment it is typed does the same job without asking anything of the people who did nothing wrong.

Typos. People mistype their own address constantly. A mistyped address cannot be corroborated by an order, so it stays out of your sends instead of bouncing off them.

Deliverability. Whether your good mail arrives at all depends on the company your mail keeps. Mail to addresses that do not exist, or that nobody asked for, is the fastest way to lose that. Refusing to send to unconfirmed addresses is the cheapest protection available, and it costs you nothing real: the people it holds back are, overwhelmingly, not people.