Help · Audience
Verified identity
Every profile carries one of two marks:
- Verified identity — this came from your store's own records, or your store has since confirmed it.
- Not confirmed yet — somebody typed this address somewhere, and nothing from your store has backed it up.
This is not consent. Verified identity is about whether the person is real and yours. Consent is about whether they want to hear from you. A profile can have a verified identity and still not be subscribed, and that is ordinary. The two facts sit apart on every screen for exactly this reason.
How a profile is born
Confirmed from the start — anything that comes from your store itself: an order, a checkout, a customer record. Your store is the authority on who your customers are, so what it tells the app is taken as true.
Confirmed straight away, from one of your own forms — when somebody fills in a signup form on your storefront, the address is checked at that moment: that the mailbox really exists, that it is not a throwaway domain, and that a real person browsing your store is behind it. An address that passes is confirmed immediately, and you can email them straight away — no confirmation email, no waiting for them to buy something. The welcome offer arrives while they are still on the page they signed up from.
Not confirmed yet — anything claimed from somewhere else: an email typed into your storefront outside a form, a profile pushed in through the events API, or a form signup where the check could not confirm the address. Anyone can type any address into a form, so until something backs it up, it is a claim.
When a form signup is not confirmed
Sometimes the check cannot confirm an address — the mailbox does not answer, or the checking service is briefly unavailable. When that happens:
- The person is accepted and thanked exactly like everybody else. They are never told their own address looks wrong, and they never see a different screen. Turning a real customer away at the moment they were about to buy from you is the worst thing this could do, so it does not do it.
- Their consent is real and is recorded. They asked to hear from you, and that is true whatever the check said.
- The person is simply not emailed yet — and the moment they place an order, they are confirmed automatically, with nothing for you to do.
Being unconfirmed is never a doubt about their consent. It is a question about the address, and the two are kept apart on purpose.
Catch-all domains are the one case with a setting of their own. Some domains — most work addresses — accept mail to any name at all, so the check cannot learn anything from them either way. By default, somebody on one of those domains who browsed your store before signing up is accepted and confirmed on that evidence, and the profile records that it was the browsing rather than a mailbox that vouched for them.
The switch itself is in Settings → Store, with the two numbers to keep an eye on underneath it. What it decides, what the trade is, and what "browsing" counts as are explained on the Forms page, under Catch-all addresses.
How a profile becomes confirmed
The moment your store shows the app the same email address — an order, a checkout, a customer record — the profile becomes confirmed. Automatically, and usually within seconds.
It only goes one way. A profile that has been confirmed is never un-confirmed. Nothing arriving later can walk that back.
You do not have to do anything to make this happen, and there is nothing to approve. Someone who signs up on your storefront today and buys tomorrow is confirmed tomorrow.
What unconfirmed profiles can and cannot do
They are shown. They appear in the profiles screen with their mark, and you can open them and read everything the app knows about them. Hiding them would make your audience smaller than your store's own customer records with no explanation on any screen.
They are not counted. They are left out of every segment, every count, and every audience.
They are never emailed. No email you send through this app goes to a profile that has not been confirmed.
And they are never deleted on a guess. Being unconfirmed is not an accusation — it is the absence of evidence. Deleting the record would destroy the very thing that shows whether the caution was warranted, so the profile stays, and it upgrades quietly the day your store vouches for it.
Why this protects you
Three problems, one answer.
Automated traffic. Public signup surfaces get hit by scripts that inject addresses which belong to nobody, or to somebody who never asked. Those addresses do not pass the check, so they land as claims — they never reach an audience and never receive a send. This is why you do not need to make every honest customer confirm by email. The usual way to keep a list clean is to send everyone a "click here to confirm" message, which costs you a share of every signup. Checking the address at the moment it is typed does the same job without asking anything of the people who did nothing wrong.
Typos. People mistype their own address constantly. A mistyped address cannot be corroborated by an order, so it stays out of your sends instead of bouncing off them.
Deliverability. Whether your good mail arrives at all depends on the company your mail keeps. Mail to addresses that do not exist, or that nobody asked for, is the fastest way to lose that. Refusing to send to unconfirmed addresses is the cheapest protection available, and it costs you nothing real: the people it holds back are, overwhelmingly, not people.
Where you see it
- The Identity column on the profiles screen.
- The line under the name on a profile's own page, with the date it was confirmed.
- Your home screen, which reports both numbers side by side: how many profiles are confirmed and subscribed out of all your profiles, and how many are not confirmed yet. The second number never hides inside another one.
- The metric charts, which count profiles with a verified identity only — the same profiles your segments are built from.