Chrome has started testing the Email Verification Protocol, a proposal that makes it possible to confirm that a user controls a specific email address without sending a verification message.
Technology could reduce friction in subscription and registration forms. However, it is still being tested through an origin trial and should not be seen as a universal replacement for double opt-in, consent or email marketing best practices.
Contents
- Overview
- What is double opt-in, and why is it still used?
- Why can the current process create friction?
- What is the Email Verification Protocol?
- How does verification work without sending an email?
- Can EVP replace double opt-in?
- Technical verification is not consent
- What could change in email marketing?
- What could the impact be on database quality and deliverability?
- Limitations and open questions
- What should brands do now?
- Conclusion
- Start by improving what you already control
Overview
There is a point where many registrations are left incomplete: after taking a certain action, the user has to leave the website, open their inbox, find a confirmation message and click a link.
This step exists for good reasons. It confirms that the address is valid and that the person has access to the corresponding email account. This is known as double opt-in.
At the same time, it introduces an interruption at an important point in the user journey. When someone is creating an account, subscribing to a newsletter or completing a checkout, any additional step can increase the risk of abandonment.
Chrome introduced the Email Verification Protocol, or EVP, to try to reduce this friction.
The proposal allows the browser to communicate directly with the email provider to verify that the user controls the address. Everything happens without sending a confirmation email or requiring the person to leave the website.
The technology is currently being tested through a Chrome origin trial, with Gmail participating as an email provider. However, this does not mean that it is widely available or that it will definitively replace the current process.
What is double opt-in, and why is it still used?
Double opt-in is a two-step confirmation process used to validate new contacts.
In practice, it works as follows:
- The user completes a subscription, registration or checkout form.
- They receive an automated message at the address provided.
- They open the message and click a confirmation link.
- Only after that click is the address considered confirmed.
This process helps solve several problems.
First, it confirms that the address exists and that the user has access to the corresponding inbox. It also helps reduce typing errors. For example, someone might enter gmial.com instead of gmail.com without noticing.
Double opt-in also makes it more difficult to use fake addresses, create automated registrations or submit someone else’s address without their permission. It can also contribute to creating a stronger record of consent, depending on how the process is implemented and documented.
For these reasons, it continues to be considered a best practice for managing contact databases.
Why can the current process create friction?
Despite its advantages, double opt-in introduces an additional step into the user journey. This friction can have several causes.
Context switching
The user is on the website, focused on an action, but has to open another application or browser tab to continue.
The need to open the inbox
The person has to access their webmail or email application and look for the confirmation message. In some cases, the message may appear in a promotions or spam folder.
Potential delivery delays
Even with a good sending infrastructure, the message may take a few seconds or minutes to arrive. During that time, the user may lose interest, close the page or start doing something else.
Abandonment before confirmation
Some people complete the form but never click the link. The result is a group of contacts who showed interest but did not complete the registration.
What is the Email Verification Protocol?
The Email Verification Protocol is a proposed open protocol that allows the browser to communicate directly with the email provider.
Its purpose is to confirm that the user controls the address they entered, without requiring a verification message to be sent. Instead of waiting for the person to open their inbox and click a link, the browser handles the confirmation in the background. Once the process is complete, the website receives a signed token proving that the address was verified by the relevant provider.
The user remains on the website throughout the process. They do not need to open their email, copy a code or switch applications.
The proposal is being developed publicly and has been presented as a progressive enhancement to existing flows. In other words, it could complement the current process when available, without preventing websites from keeping their usual methods as an alternative.
How does verification work without sending an email?
The technical process includes several security steps, but the flow can be explained simply.
1. The user selects the address
In a compatible form, the user chooses the address from Chrome’s autofill suggestions. At this initial stage, manually entering the address is not sufficient.
2. The browser identifies the provider
Chrome identifies the address domain and looks for the service responsible for the corresponding account. For example, in the case of a Gmail address, the browser may contact Google’s account service.
3. The provider confirms the session
The provider checks whether there is an active session associated with that address in the same browser profile. This means that the user must be signed in to the relevant email account.
4. A verification token is created
After confirming the session, the provider generates a verification token. The browser associates that token with the website and the form that initiated the request.
5. The website validates the token
When the form is submitted, the website receives the token through a hidden field. The website verifies elements such as:
- The address provided.
- The origin of the request.
- The provider’s signature.
- A unique value associated with the form.
6. The user remains on the website
The entire process takes place without interrupting the browsing experience. The user only sees a subtle indication that the address has been confirmed by the provider.
The first time it is used, an authorisation request is displayed. After this initial authorisation, the process may take place more quietly.
For verification to work during the origin trial:
- The user must have an active session with the email provider.
- That session must be open in the same Chrome profile.
- The address must be selected from the autofill suggestions.
- The email provider must participate in the protocol.
- The website must be registered for the origin trial and have implemented the process.
Manual address entry is not yet supported in the initial trial, although it is planned for a future version. When any of these conditions are not met, the website does not receive the token and must fall back on its usual confirmation method.
Can EVP replace double opt-in?
EVP could take over part of the role currently performed by double opt-in, but the two concepts are not necessarily equivalent.
The protocol confirms that:
- The address exists.
- The provider participates in the process.
- There is an active session associated with the address.
- The user completing the form controls that session at that moment.
This provides technical proof of control over the address. However, it does not necessarily prove that a message sent by the brand reached the inbox.
EVP does not test sender reputation, message deliverability or how messages will be handled by the email provider. For this reason, businesses may continue to send welcome or onboarding emails even when verification is completed through the protocol.
Technical verification is not consent
It is also important to distinguish verification from consent. Confirming that a person controls an address does not, by itself, mean that they have authorised the sending of commercial communications. Nor does it automatically prove that consent was freely given, informed, specific, unambiguous and properly recorded.
The applicable rules will depend on the market, the purpose of the processing, the relationship with the contact, the company’s internal policies and any existing legal or contractual obligations.
Businesses should therefore not remove or change their consent processes simply because an address has been verified through EVP.
Any change should be legally assessed and validated according to the markets in which the organisation operates.
The protocol may eventually simplify the technical validation of an address. By itself, however, it does not remove the need to collect and demonstrate consent when required.
What could change in email marketing?
If EVP is widely adopted by browsers, email providers and websites, it could affect different areas of email marketing. These effects are possible, but they are not guaranteed.
Less friction in forms
Users could confirm their address without leaving the website, simplifying form completion, newsletter subscriptions, account creation, service registration and other processes that depend on email validation.
Potential increase in completion rates
A process with fewer steps could reduce the number of people who abandon the registration before completing it. However, the actual impact will depend on the audience, device, browser and how the form is designed.
Better quality of collected addresses
An address validated directly with the relevant provider is less likely to be nonexistent or entered incorrectly.
Fewer typing errors and fake addresses
Because the user must choose an address already recognised by Chrome, errors such as misspelled domains may become less common. The process could also make it more difficult to use invented addresses or addresses belonging to third parties.
Faster onboarding
In SaaS services, online stores and platforms that require account creation, the user could move to the next stage more quickly. For example, they could immediately access the platform, complete a purchase or begin configuring the service without waiting for a message.
Potentially less dependence on confirmation emails
If the protocol achieves significant adoption, some businesses may rely less on the traditional confirmation link. Even so, an alternative method will still be necessary for cases where EVP is unavailable. At this stage, confirmation email remains the most widely supported and compatible mechanism.
What could the impact be on database quality and deliverability?
Collecting verified addresses could contribute to cleaner databases. If there are fewer invalid or incorrect addresses, the number of bounces during initial sends may also decrease.
However, it would not be accurate to say that EVP directly improves deliverability, as deliverability will continue to depend on several factors.
Consent and expectations
Do contacts know that they signed up? Do they understand what type of messages they will receive and how frequently? A valid address does not compensate for a lack of consent or poorly managed expectations.
Content quality and relevance
Messages need to be useful and relevant to the recipient’s interests. Irrelevant content can lead to low engagement, unsubscribes or complaints.
Sending frequency
Sending too frequently can overwhelm contacts. On the other hand, sending too infrequently can also cause them to stop recognising the brand or forget that they signed up.
Sender reputation
The reputation of the sending domain and IP addresses will continue to influence whether messages reach the inbox.
Domain authentication
Configurations such as SPF, DKIM and DMARC will remain essential for demonstrating the legitimacy of email sends.
Engagement, complaints and unsubscribes
Email providers analyse how recipients interact with messages. Opens, clicks, replies, deletions, spam complaints and unsubscribe requests will continue to generate important signals.
EVP may confirm that an address is valid. It does not confirm that the contact wants to receive messages, that the content is relevant or that the sender’s infrastructure is properly configured. A technically valid address can still create deliverability problems if it belongs to someone who does not recognise or want to receive the communications.
Limitations and open questions
The potential of EVP should be assessed in light of its current limitations.
The technology is still being tested
EVP is available through an origin trial. Origin trials are experiments used by Chrome to collect feedback before potentially making a feature more widely available.
There are usage limits, and the implementation may change. Some technical parts of the protocol are also still under development.
Adoption depends on several parties
For the protocol to work at scale, it will need to be adopted by:
- Browsers.
- Email providers.
- Services responsible for the accounts.
- Websites that collect addresses.
If any of these parties does not support the technology, another confirmation method will be required.
Gmail’s participation does not represent the entire market
Gmail is participating in the origin trial as a provider. Its participation is relevant because of its scale, but it does not mean that every provider will adopt the protocol, nor does it guarantee that the technology will receive widespread support after the trial ends.
An alternative method is still required
Websites should treat the token as optional. When the token is not received or validation fails, the flow should continue through the traditional method, such as sending a confirmation link.
Adoption outside Chrome remains uncertain
To become a true standard, the protocol will need to be accepted by other browsers. As long as it is limited to the Chrome ecosystem, its coverage will inevitably remain partial.
There are questions about privacy and interoperability
Although the proposal includes measures intended to limit the information shared between the website and the provider, several issues still need to be monitored.
These include:
- How different providers will implement the protocol.
- Compatibility between browsers.
- The authorisation experience shown to users.
- The handling of multiple accounts in the same browser.
- The relationship between technical verification and consent.
- Token security and validation.
- The evolution of the technical specifications.
These issues continue to be discussed in the public forums associated with the proposal.
What should brands do now?
Stay calm. There is no need to rebuild subscription or registration processes yet. However, there are some practical steps that brands can begin taking.
1. Follow the progress of the origin trial
Marketing, product and technology teams should follow the updates published by Chrome. It may also be useful to monitor the development of the proposal and see whether other browsers or providers show interest.
2. Do not remove double opt-in prematurely
Double opt-in remains a widely supported method for confirming that a contact has access to their inbox. Depending on how the process is implemented, it may also play an important role in demonstrating consent.
It should therefore not be removed simply because a new experimental technology has appeared.
3. Review abandonment points
Brands can already analyse:
- How many people complete the form.
- How many receive the confirmation message.
- How many click the link.
- How long they take to confirm.
- Which devices or sources have the highest abandonment rates.
This analysis is valuable regardless of how EVP develops.
4. Improve confirmation messages
A confirmation email should include:
- A clear subject line.
- A recognisable sender.
- A simple explanation.
- A visible confirmation link.
- An indication of what will happen after the click.
It is also important to optimise the page displayed after confirmation, ensuring continuity in the contact’s experience.
5. Ensure consent is recorded
Businesses should maintain an appropriate record of elements such as:
- Date and time.
- Contact source.
- Form used.
- Consent wording displayed.
- Purpose stated.
- Version of the accepted terms.
- IP address, when applicable and legally appropriate.
EVP does not remove this requirement.
6. Prepare fallback mechanisms
Any future implementation should assume that automatic verification may fail. The flow must be able to direct the user to a traditional confirmation email whenever:
- The browser does not support the protocol.
- The provider does not participate.
- There is no active session.
- The address is entered manually.
- The token is not received.
- Validation fails.
7. Consider testing when the technology is more mature
Once there is greater stability and coverage, it may make sense to test EVP with a limited group of users.
Before testing, metrics should be defined, such as:
- Percentage of forms that receive a token.
- Successful token validation rate.
- Percentage of users directed to the fallback method.
- Registration completion rate.
- Average time to completion.
- Quality of the collected addresses.
- Impact on consent and auditing processes.
Conclusion
The Email Verification Protocol aims to solve a real problem: the interruption caused by the traditional confirmation process.
By allowing the browser to validate the address directly with the provider, EVP could simplify subscription, registration and checkout forms. It may also help reduce errors, improve the quality of collected addresses and speed up onboarding experiences.
However, it is important not to jump to conclusions.
The technology is being tested through an origin trial, depends on the participation of several parties and is not yet widely available. It is not a universal replacement for double opt-in and does not remove requirements related to consent, proof of consent, contact management or deliverability.
The future of verification may be simpler for users. For brands, it will continue to require what it has always required: clear processes, properly documented consent, security, well-maintained databases and communications that people genuinely want to receive.
Friction may decrease. Responsibility will remain with brands.
Start by improving what you already control
While the Email Verification Protocol continues to be tested, your campaign results still depend mainly on the quality of the processes you already use.
With E-goi, you can create forms and landing pages, configure double opt-in flows, automate welcome journeys and keep consent records and contacts organised within the same platform.
Try E-goi and build a contact database that is ready for the present and whatever comes next.
Main source: “Test the Email Verification Protocol with an origin trial”, Chrome for Developers, published on 8 July 2026.
Leiriense, colecionador de moedas de 2€ e apaixonado por marketing. Trabalha nas áreas de CRM, automação e lifecycle marketing há 3 anos, sempre com o objetivo de criar comunicações mais relevantes e aproximar marcas e pessoas.