14 ms·
Removing email registration improved retention
- justingreet 6y agoThat's really interesting and definitely something worth trying. I wonder how the effectiveness of email changes with the goals for the user (play solitaire vs pay for a subscription, etc).
- ghaff 6y agoHe does mention, somewhat off-handedly, that the lack of email makes password recovery harder. (Presumably impossible without some other communications channel like a phone number.) And you really need to be able to recover account access for a paid subscription. It's probably also reasonable to assume that if someone is going to give you a credit card number and address, they're probably OK with giving you an email.
- londons_explore 6y agoI run a site that takes payments for a subscription, but then just stores a cookie on the users machine proving they've paid. It will give them the cookie again if they re-visit from any IP they've previously used. It also re-gives them the cookie if they try to pay again with the same credit card. Support just tells people to try to resubscribe if their subscription has 'vanished' - but it seems to happen to very few customers.
- c22 6y agoThis is pretty clever, but people might get double billed if they accidentally try to confirm their account with a different card than they used to sign up.
- ohyeshedid 6y agoPublic IP as an auth token seems like a horrible idea. You're giving anyone on CGNat or even the same coffee shop access to your customers account.
- londons_explore 6y agoIn my case, customers don't have any data on the account - it's simply a bit saying 'has paid for premium?'. And if I end up giving premium to a few people who didn't pay it isn't an issue. The sign-up friction of needing an email address is greater.
- MakeUsersWant 6y agoHow about you put the recovery code onto the invoice / credit card line?
- smoe 6y agoI think age plays also a role. I have met various young people who have't entered the "working world" yet, that only have an email address because they needed one for registration and to recieve some school related information. But it is percieved as something completely arcaic and they never use it for anything else nor check it regularly. All communication is via messangers or social media. On the other hand also elderly are or could be moving in this directions. E.g. my mother getting an iPad and apps like Whatsapp have completly changed "computers" for her. From, being mostly a chore that you have to use, to something really useful for getting information and to stay in touch with relatives in other countries
- tapneal 6y agoI would suspect brand too makes a difference in whether people will give away their email address.
- foxhop 6y agoI'm fairly certain I would rather collect the emails even if it means less retention. Not for marketing purposes but for support purposes. With MakePostSell [1] a customer may add products to their shopping cart and interact with a shop as if they are logged in, but at the point of sale / checkout, we ask them to verify their email. [1] https://www.makepostsell.com https://www.makepostsell.com
- dsr_ 6y agoDon't bother. If you collect email addresses, it's PII and someday you will have to account for that. Instead, give them a searchable FAQ or a wiki and an email address to write to for support. Connect it to a ticket system that autoresponds with a ticket number. (then you added your second paragraph while I was writing this.)
- londons_explore 6y agoI get users to email a personalized support email address. Eg. help3a2fg@company.com The support team can figure out which account or anonymous cookie saw that email address. It's a handy way to still communicate directly with users while holding as little PII data as possible about them.
- thomascgalvin 6y agoEven the article says this creates "issues for password recovery."
- Apreche 6y agoHave you considered that without email verification that a lot of those sign-ups were just bots?
- ackbar03 6y agoYes. I run a web service that provides a free trial period, and I can't see anyway around it other than forcing a sign up. I'd love to know if there are more friendly ways to do it.
- tapneal 6y agoWe use some tools to understand traffic and fortunately most of the traffic is clean. One downside with asking for usernames alone is that people (not too surprisingly), come up with creative but very profane usernames!
- megous 6y agoOr users creating another account due to lost password (which is easier if you don't have to get another email address).
- s3r3nity 6y agoGreat idea, but all these posts deserve the same qualifier: this should be considered an experiment / hypothesis, and not a recommendation that every other site / business / experience should apply without question. There are times when removing email is best, and others where data or business vertical necessitates something different. You still need to verify with your users and do the appropriate testing / analysis / user research.
- tapneal 6y ago100% agree. This worked for us, but is likely to vary by business and this is not a silver bullet. I do think though people who register with email and convert tend to be people who would convert already (i.e., there is a bias already). Product managers can test opening up the funnel more by asking for emails later in the funnel.
- davnicwil 6y agoThe article mentions the tradeoff of username Vs email of increased willingness for people to sign up Vs losing the simple channel for password reset, but does not propose a solution outside of non-expiring cookies, which to me isn't really a satisfactory solution (though perhaps it works OK enough in practice for some types of use cases). In my view, for most applications, the upside is not really worth that downside. It got me thinking though, are there any clever solutions to do password reset without an email / social media account login / etc? Does anyone know of any good ones?
- londons_explore 6y agoThe Reddit model of "email address is optional, but if you don't provide it you can't ever reset your password" works well.
- ipnon 6y agoOld Reddit is the epitome of user friendly web design.
- petercooper 6y agoPhone number, I guess. Sending SMS messages en masse is expensive or heavily regulated in much of the world and it doesn't particularly suit frequent "spamming" so people of a younger generation may be more willing to hand it over(?)
- chrisco255 6y agoThat hasn't been true lately. Lately I'm getting spammed at least a dozen times a day by SMS.
- c22 6y agoYeah, I have a number that I "hand over" and another number I don't. The public number is inundated with spam SMS to the point that I don't even bother checking them anymore. And this is with pretty conservative behavior: even though I have a dedicated number for this purpose I still avoid entering it unless I absolutely have to.
- ve55 6y agoThis is pretty far from what would be needed to say 'Email registration is dead'. Users may be annoyed by it and it may help in niche cases to exclude email requirements, but for most webapps this will not be possible as users will not even be able to reset their password then.
- tapneal 6y agoTotally agree. This will depend by business. We're were just pointing out that it makes sense to challenge the norm, because people are so reluctant to give their email addresses.
- GoblinSlayer 6y ago> most of us also hate emails from commercial sites This genius, my ass.
- gwbas1c 6y agoHonestly, I hate managing accounts and passwords so much that I'll walk away when a "create an account" is thrown in my face. Login via Google / Facebook / Whatever is sometimes helpful, but it usually results in SPAM. For example, I logged into Redfin through Google and they immediately started spamming me. Other times, when I login through Facebook and disable sharing my email, the site that I'm trying to log into has a "mystery error" because the concept of not sharing my email address never occurred to whoever wrote the integration. Most of the time, I just use a unique email address with each site. My domain has a catch-all email address, so when someone starts spamming it, I know who did it.
- christophilus 6y agoSame. Catch all aliases are the way to go.
- throwayws 6y agoHow do you avoid getting spam to random addresses using catchall?
- techsupporter 6y agoI use a subdomain; making your main domain a catch-all will eventually result in a deluge of spam. Instead of [everything]@example.com, I set up [everything]@yo.example.com. Discovering subdomains is much harder and the one time I encountered a form that didn't like a subdomain, I just made a forwarding address on my main domain. Using Fastmail's rules, I have a setup where every message arriving to @yo.example.com gets shunted into a folder unless there's a different rule putting it somewhere else.
- newscracker 6y ago> Discovering subdomains is much harder... Is this because you don’t publish MX records in DNS for the subdomains and the default setting on the main domain is to accept only specific addresses (and reject catch-all addresses)?
- 6y ago
- deleted 6y ago[deleted]
- WilTimSon 6y agoAnecdotal, of course, but in my experience many people won't sign-up using their email because they're tired of getting added to mailing lists and receiving spam. Now, you could use fake emails when you sign up for these, partially as a way of avoiding spam and partially to find out which services are the most annoying with their mailing. However, this gets tiresome and if I can find an alternative service that doesn't require me to give as many personal details, I'll choose it over that one.
- jpalomaki 6y agoAsk me email, but don't force me to verify it before letting me in. While I'm browsing, show me a prominent warning that my email is not yet verified. Include my email address in the warning so that I can catch possible typos.
- abstrct 6y agoThis scares me a bit. A part of email validation is ensuring they actually own that account. It depends on the sensitivity of the service to an extent but I don't think it's appropriate to let somebody interact as if they were a specific email account until they've proven it's theirs. Edit: I do like the recommendation of showing them the email they're waiting to validate so that they can see typos.
- threeseed 6y agoOne option and something I am using for my startup is to use Clearbit Risk (https://clearbit.com/risk https://clearbit.com/risk). It's an API where you give it the user's email address and they tell you if they think it's real or not. I have it such that if it's not risky I bypass the "verify email" step. Not sure how long the API will be around and it's pretty slow but for now at least it's free.
- chrisdbanks 6y agoEmail registration is the gateway drug to conversion. We AB tested this. Requiring users to sign up meant we got fewer sign ups but a higher conversion rate to premium. So although we had fewer users, more paid. Giving your email is a committment. Maybe once you've made a small committment it's easier to make a bigger committment. If you're running a commercial product, especially freemium, it's not just about number of signups.
- franga2000 6y ago> Maybe once you've made a small committment it's easier to make a bigger committment. It's definitely not the whole story, but this is a pretty well-studied thing in psychology. A similar trick in social engineering is to ask your mark for a small favor, which will make them more likely to do you a bigger favor later. I've read about it many times, but can't for the life of me remember what it was called...
- amatecha 6y agoYou're just trying to get someone to do you a favor by looking up what that phenomenon is called! We're onto you! heheh ;)
- rygine 6y agoperhaps this? https://en.wikipedia.org/wiki/Ben_Franklin_effect#:~:text=The%20Ben%20Franklin%20effect%20is,for%20this%20is%20cognitive%20dissonance https://en.wikipedia.org/wiki/Ben_Franklin_effect#:~:text=Th....
- Beldin 6y agoPerhaps one of the 6 principles of persuasion? From a google search: Theses 6 principles are reciprocity, consistency, social proof, liking, authority, and scarcity.
- electricviolet 6y agoI've heard it called the foot-in-the-door phenomenon. https://www.simplypsychology.org/compliance.html https://www.simplypsychology.org/compliance.html
- InfiniteRand 6y agoI like the idea of starting registration with no email but with the option to add a recovery email later on, once I am sold on the idea that this account is worth recovering.
- tapneal 6y agoThat's something we're hoping to explore further. I think email for those with early interest often is a non-starter.
- macrael 6y ago10 years ago (!) Instapaper changed its tune and started requiring emails for new accounts. Before it had not required emails (just usernames) and even didn't require passwords, and after living with that for years Marco decided to switch back to the more traditional form. https://blog.instapaper.com/post/2318776738 https://blog.instapaper.com/post/2318776738 It's interesting to think that times may have changed and that people are hesitant to give out their email addresses anymore, but you are giving up some real benefits by leaving it out.
- franga2000 6y agoHopefully a lot of the remaining resons to collect emails start going away as WebAuthn gets adopted and better integrated into browser sync and/or password managers.
- cblconfederate 6y agoIn the end, it's all about time. People are rational creatures (despite rumours) and quickly decide whether they are willing to spend time to do the email activation thingie, and so they bail. Someone should do a survey of conversion rates vs time it takes to sign up somewhere, i bet there will be a strong correlation. Anecdotally, i ve observed the opposite too. I don't require email to sign up, but there is an email field further down in the form, and yet 95% people DO enter an email that looks valid, and not just garbage. That said, only 5% clicked on the email verification link , presumably because they don't have to
- PostThisTooFast 6y agoIt's also about tolerance for stupidity. The use of E-mail addresses as user IDs is not just inconvenient and annoying, but it's a piss-poor practice from a security standpoint. You can assume that a large portion of the public does not understand that they don't have to use their E-mail password on sites that force them to use their E-mail address to sign up. This puts the security of their entire E-mail account in the hands of dozens or hundreds of random Web sites' administrators and employees, which means it puts the security of their identities in those hands. Not to mention that everyone's E-mail address is on thousands of spammers' lists. When you test the top 100 passwords against millions of E-mail addresses, you're going to get a shitload of compromised accounts. Nobody should be forcing people to use an E-mail address as a user ID.
- oxfordmale 6y agoI have a fake email address I use to sign up when I am forced to. I login to that email account once every month not to lose access, but other than that it is a huge swamp of unread emails.
- encom 6y agoI use 10minutemail.com for this. Sadly though, it appears all these temporary mail domains are in some central list, that data harvesters use to deny access. It's almost impossible to sign up for forum accounts with these. So it's impossible to download files from vinylengine.com unless you allow them to spam you.
- jen729w 6y agoI run 2 addresses, both at my own domain (using Midagu for hosting). One is my actual address that human people who I know have. The other – referred to as “the sluice” – is everything else. I don’t really care what goes in it. A rule marks it as read as soon as it hits my inbox. Simple but massively effective. I used to get stressed about spam but now I don’t give a crap. Edit: also, the sluice mailbox is 2020@mydomain. When it does finally become too much of a cesspit, I'll just kill it and create 2023@...
- bborud 6y agoI am not surprised. The list of services I no longer use because they constantly email me to generate "engagement" is quite long. And if I get too annoyed (about once or twice per quarter), I make the effort to not only de-register my account, but I often add the domain to my spam filter so I never see email from that domain again. I just checked and I have a bit over 110 domains in my spam list that look like they were added over the years because of this. So I may have under-estimated how often I "blacklist" businesses like this.
- threeseed 6y agoThis is not advice any startup should ever listen to. The most successful and lucrative form of marketing, by far, is re-marketing. That is where you take someone who signed up but is not currently a customer and you target Facebook/Google ads specifically at that email address. I've seen conversion rates as high as 30% and it's typically pretty affordable. It's such a critical part of marketing that many companies will take a loss on the initial "here is our product, please join" ads just so they can follow up with re-marketing in the weeks/months to come. And because people re-use their email addresses across websites you can target them on Quora, Reddit etc as well. You can't do any of this without their email.
- Nextgrid 6y ago> you target Facebook/Google ads specifically at that email address That is scummy as hell and might even get you in trouble when it comes to the GDPR if you're operating in the EU. If I sign up for your web service the last thing I want is Facebook/Google knowing that fact.
- threeseed 6y agoThis is a core feature of every ad platform I've seen and is absolutely not a violation of the GPDR since users are giving consent when they signup. You've signed up for a web service and never seen ads on other sites for it ? Very strange.
- Nextgrid 6y agoI agree that this is a core feature. However, the GDPR mandates that consent should be opt-in, granular (you can provide consent for your data to be used for one purpose but not another) and you can't refuse service because a user is refusing to consent to non-essential data processing (ads would fall into that). So yes, technically you can ask the user for consent, but it has to be explicit ("we'd like to share your e-mail/phone number with our advertising partners such as Facebook, accept/decline?") and I can't imagine anyone in their right mind consenting to that. > You've signed up for a web service and never seen ads on other sites for it ? Very strange. I sign up for stuff only when I have no other choice for exactly this reason, and often provide fake details. Reminds me of an ex-client where they had an issue with their potential customers not providing the right contact details because they're afraid we're going to spam them. "But do we actually spam them? -Yes."
- zargon 6y agoReddit has regressed in this area. It now appears like an email is required for signup (even though you can leave it empty and click next). It probably deters people from creating accounts.
- anderspitman 6y agoI've started uses separate email addresses on my personal domain for each account I create, and so far I like this approach. I hope some company solves the problem of making domain registration as accessible as phone numbers are today so the average person can reap the benefits
- spsful 6y ago>you can target them on Quora, Reddit etc as well. This is one of the reasons I stopped giving out my primary email address for user signups. I use a service called Blur which allows for unlimited "masked" emails to be created, allowing me to give companies read-only email addresses. In the four years I've had it I have created 378 email addresses. If I'm including the email addresses that I've already deleted, the list gets to 400. Marketing and the 3000 spam messages I get per month made me do this. It does not have to be this way, but as long as corporations can play fast and loose with my email address I will make sure they never get a real one to begin with. Edit: Want to add here that I am not in any way sponsored by that company, I've just been using them for years now and think their prices are reasonable.
- elorant 6y agoCare to provide a link for the service you're using?
- feistypharit 6y agoHe means https://www.abine.com/ https://www.abine.com/. personally, I use https://33mail.com/ https://33mail.com/. If you want to go full fake, check out https://mysudo.com/ https://mysudo.com/.
- Shorn 6y agoI run https://kopi.cloud https://kopi.cloud - let's you give out burner addresses you can just make up on the fly. SSO through Google, Facebook, Twitter. One touch blocking of burner addresses. Supports replying and attachments. Mail 2 RSS - read Facebook / StackOverflow, newsletters, etc. as RSS feeds. And you can use your own domain if you want, so no lock-in.
- matheusmoreira 6y agoOnce the marketers discover people are doing this, they'll ban email addresses from this service as if they were fraudulent. Wouldn't be surprised if companies started disallowing everything except gmail.
- jakub_g 6y ago1) Everyone and their dog wants your email those days, which is bad due to engagement spam as mentioned in article, and privacy (those email addresses are probably flying around adtech servers which allow building up extremely detailed user profiles by those adtech companies). Your website should allow "demo mode" to make me see what's the value it provides. No way I will go through registration on random pages that fail to immediately make me crave to use them. I ain't got time or will for that. 2) If you want to follow advice of the article, I'd rather not remove email field, but as I wrote before, allow demo mode, and at next step when actually registering the user, put a clear one paragraph sentence saying that you'll not be spamming me with your engagement stuff. 3) If you ask for email, absolutely verify it. There are way too many people who subscribe to all kinds of services using someone else's email. See this thread: https://news.ycombinator.com/item?id=24359980 https://news.ycombinator.com/item?id=24359980
- tester756 6y agoI'm strongly avoiding shops with want you to create acccount If you need me to register in order to purchase boots, then something is not ok.
- awinder 6y agoIs anyone else here concerned / wondering if these numbers could be noise and loosely correlated? The leaderboard addition lead to a 22% user signup but there’s a 3-5% jump in number of sessions (games?) and it’s as a decimal position of 4. This feels like maybe there’s something more fundamentally wrong going on here...
- m3kw9 6y agoLooks like noise
- kull 6y agoHN does the same. Just username and password. No email. Very interesting concept.
- lookmanoemail 6y agoTrue, I just registered.
- BMSmnqXAE4yfe1 6y agoHN users are much less likely to forget their password.
- nuker 6y agoIf you disable loading remote images/content in your email client, spam dies off eventually. Without read receipts address gets marked as dead.
- jerzyt 6y agoMy pet peeve is with retailers which force you to register before even being able to browse their virtual store. They will never get my business. I wonder if the CEOs of these companies have any idea how much business they're driving away.
- BMSmnqXAE4yfe1 6y agoThat might work for casual gaming site where it's not a big deal to create a new account after forgetting your password.