Reducing Friction with New Email Capture

Problem: The widespread use of Substack has created an expectation in market behavior that when you sign up for a newsletter, you’re signed up — but Ghost requires the new subscriber to “confirm your subscription” within 24 hours, and if they don’t, neither the subscriber nor the newsletter creator knows.

I’ve heard this is for a few reasons, to reduce spam signups, and to meet GDPR requirements, which Substack chooses to interpret differently.

So here’s another idea: What would it take to be able to see who input their email to sign up for the newsletter but then never “confirmed” their subscription?

Having this feature would be quite helpful at least for me in retaining newsletter signups that I’m getting, particularly from in-person events.

Context: I participate in storytelling and open mic events on evenings and weekends, where I perform stories from my newsletter. At the end, I plug the newsletter, and typically at these events a handful of people will make a point of coming up to me to tell me how much they enjoyed the performance and that they signed up and can’t wait to get my newsletter.

Except by the next day, only one new subscriber actually comes through. What I suspect is happening is that in the moment on their phones at the event they’re going to the site and inputting their email, but then by the next day or after the weekend is over they either never see the confirmation email, or they do and they think they’ve confirmed but it’s too late.

It’d be great if I could see that and then have the ability to add them manually or follow up. I get this may be kept invisible due to spam signups but it would be nice to have the choice whether to see this or not, and personally, I would know inherently based on the proximity of signups to events I do whether the emails are spam or actual people interested.

Open to any other ideas people might have with how to reduce the friction of signing up for a Ghost newsletter.

I think you’re missing the point. That confirmation email they need to click on proves the email receipient is bona fide and wants to give you their permission to email then your newsletter. It’s a handbrake system for a reason.

Given the law changes around the world, be glad it’s there.

Anyone can use a random email address and enter it on any website.

There are new GDPR regulations coming into play on the 19th June and it’s hitting harder at email marketing, so I’m glad I’m not on Substack. Your legal obligations when it comes to protecting personal data is a serious element of running a small business. Just like your contracts and insurances. Ignorance is not anyone’s friend.

On your website, you don’t appear to have the legal opt in wordings when folk subscribe which could cause you concern. That said Ghost themselves are many many theme designers are not hard coding in the required opt in conformation and agreement to privacy policies and terms of business on their themes. It’s the first thing I edit on any theme purchase, if not there by default, which in 2026 it should be. Unsure why Ghost are not addressing this. It’s only been in GDPR since 2018.

If the individual who signed up to your email list, does not then check the ‘what to next instructions’, then are they really worth having on your list if they are that distracted?

Just leaving this here, because I was confused myself:

There are no new GDPR or other EU regulations coming into play on 19th June. However, a UK Data Act that regulates data‑protection complaints‑handling duty: The Data Use and Access Act 2025 (DUAA) - what does it mean for organisations? | ICO

(which, as far as I understand, mainly stripped charities from the option of not requiring consent up to this date + penalties raised)

Because data privacy laws are different worldwide. GDPR is mainly enforceable in the EU (and to some extent in the UK, since post-Brexit it was basically just copied & renamed). Other legislations might need other wording.

Ghost’s portal has the option of adding a legal text with a checkbox.

As with all legal requirements for a website: it’s the publisher that needs to make sure they comply, not the software.

Anyway, I do think that isn’t what @adventuretoawaken wants to raise here − just wanted to clarify, since the 19th June date might raise alarms for others (as it did for me).

Yes, ONLY the portal, not buttons in the hero eg Source theme - but 115 in well short for what’s needed legally. I had to shave mine to 114 and I have a short business name. It’s not long enough.

Further, when people subscribe to email marketing, you’d want them to select three checkboxes, not just one.

I’m no legal expert but have that under good advisement from someone who is. Folk need to do their own research.

The boxes should not be pre-checked and they should check ALL THREE boxes to submit their email and subscribe.

Even if you have no physical presence in UK/Europe, the GDPR applies based on the location of the data subjects* (users), not the location of your business. If your analytics show traffic from the UK/EU and you collect personal data from those users, you should be complying.

Having the ability to add 3 checkboxes would be a start. Why offer FREE themes when we have to pay a developer to add code to make our website compliant. Doesn’t make sense.

I brought this up with Ghost more than once then get the usual standard response, which was not useful and still not implimented.

From what I believe, and I’m no legal expert, and feel free to correct me, full GDPR Compliance =

Subscribe Button +

Checkbox. I agree to the Privacy Policy (with the policy linked);

Checkbox. I agree to the Terms of Service (with the policy linked);

Checkbox. I agree to receiving marketing emails from name of business (or something similar).

Combing all in one checkbox = non-compliance.

Can a code script overwrite this on Ghost, until they do their own legal due diligence on GDPR subscription form updates and concur with a platform update?

I’ve DM’d John about this either way …

Ghost support suggested I post in the forum, as one sole voice isn’t being heard. I’ll start a new thread for clarity and close this conversation off here please.

Would be nice if this conversation could stay open to reflect the fact that my actual question got no airtime. Thanks.

The main difference between Substack and Ghost here is, all subscribers has an account on Substack. So, no need to validate if there is an email like that and if subscription request really came from the owner of that email. Because Substack users log in to Substack, and subscribe accounts like in any other social media.

But in Ghost, we don’t know anything about this subscription “attempt”. Is this email address real? Is the subscription request really came from the owner of that email, or someone else just randomly (or accidentally, or intentionally) wrote that email?

These are the tricky parts of accepting newsletter subscriptions in a decentralized world. But there are advantages of “not having” mediators between subscriber and publisher as well, like avoiding prioritization of your post in a timeline, or pushing your subscribers to install a mobile app to read your newsletter “better”, instead of reading in email.

Maybe a second “remembering” email would be helpful, but in case of spam requests, that would make the situation worse. Signing up with a Social login (like Facebook/Google login) would solve 2 step verification, if you don’t mind allowing those platforms to track your subscribers with this integration.

Not so … this was my experience this afternoon.

Screenshot 2026-06-16 at 15.51.48|690x299

If you don’t already have a substack account with that email and subscribe to a Substack without creating a Substack account first, yeah, then you are creating a Substack account now. But when you want to “Sign in” to that substack, you actually signin to Substack platform. When you are signed in, if you click “Subscribe” to any other publishers, you don’t get an email anymore, you just get “Subscribed!” message.

This is the difference that I was trying to highlight.

I do have a Substack account. I did subscribe to a new publisher and I got that message.

Ah, interesting. It doesn’t work like that for me. Maybe I’m wrong. Sorry.

It may an optional individual publisher setting?

LOL. this is my account setup … ;)

Snort! Seriously? Substack knows you have an account, but you have to opt in to someone not typing your email somewhere random?

:shaking my head:

Granted it’s easily done to not check for that email. Folk are busy. What would be good, and I’m not sure if this is possible, is for Ghost to ping a reminder email 24 hours later if no action is taken. A bit like you get when you leave something in your cart and you get an automated ‘abandoned cart’ email. Just a passing thought. But you seeing that email address, however, is a no no.