## Implement double opt-in signup

1. On signup, store the email as pending in your own database with a signed confirmation token. Do not create a Resend contact yet; unconfirmed addresses must never enter segments or broadcasts.
2. Send the confirmation email as a transactional send to the address the user typed. If it bounces, you learn the address is bad before it ever touches your list.
3. Make the confirmation link single-use and time-boxed, for example 24 hours. When clicked, flip the record to confirmed and only then create the Resend contact.
4. If the link expires unclicked, keep the address out of your audience. Sending marketing to someone who never confirmed is how complaint rates spike.
5. Protect the signup form with CAPTCHA. Bots sign up fake addresses with no friction, and double opt-in alone does not stop them from polluting your pending table.
6. Log the confirmation event with timestamp and IP. Under CAN-SPAM and CASL you need clear consent evidence, and the click record is it.
7. After confirmation, fire your welcome automation from the confirmed event so the first mail they receive is the welcome, not a broadcast they never asked for. Docs: https://resend.com/docs/knowledge-base/audience-hygiene