Guide
RFC 8058 explained: one-click unsubscribe in plain English
Two email headers and one HTTPS request. Here is what the standard says, line by line, and who now requires it.
Short answer
RFC 8058 is the standard behind one-click unsubscribe. An email carries a List-Unsubscribe header with one HTTPS address and a List-Unsubscribe-Post: List-Unsubscribe=One-Click header; the mail client unsubscribes the reader by sending an HTTPS POST to that address [1]. Gmail requires it for marketing email from bulk senders [2].
The problem it solves
Unsubscribe links used to be ordinary links. The trouble is that security scanners open links by themselves. As the RFC puts it, "anti-spam software often fetches all resources in mail header fields automatically, without any action by the user" [3]. A link that unsubscribed on a simple visit could be triggered by a scanner, so senders added a confirmation page, and unsubscribing stopped being one click. RFC 8058 fixes this with a different kind of request, a POST, that the mail client sends only when the person asks.
The two headers
List-Unsubscribe: <https://example.com/u/7f3a9c>
List-Unsubscribe-Post: List-Unsubscribe=One-Click
- List-Unsubscribe must contain one HTTPS address [4]. The older standard, RFC 2369, defined this header for mailing lists [5]; RFC 8058 adds the one-click part.
- List-Unsubscribe-Post must contain exactly
List-Unsubscribe=One-Click[1].
The address should identify both the person and the list, so the unsubscribe can complete with no further step. In practice that means a signed token in the URL, not an email address in plain text.
What your server has to do
- Accept an HTTPS POST to the address, whose body is
List-Unsubscribe=One-Click[1]. - Unsubscribe the person straight away. The request carries no cookies and no login: "The POST request MUST NOT include cookies, HTTP authorization, or any other context information" [6]. Everything you need must be in the URL.
- Answer the request itself. Do not redirect it to a confirmation page.
- Keep a page for people who click the link in a browser (a GET), with a button that confirms. Scanners load that page too, so loading it must not unsubscribe anyone.
The DKIM rule
Both headers must be covered by the message's DKIM signature, listed in its h= tag
[7]. Otherwise anyone could add an unsubscribe header to your mail. If you send through a provider,
check that its signature includes these two headers.
Who requires it
| Who | What they require |
|---|---|
| Google (Gmail) | Marketing and subscribed messages must support one-click unsubscribe and show a visible unsubscribe link [2]. The requirements in that section apply to senders of more than 5,000 messages a day to Gmail accounts [8]. Google recommends honouring unsubscribes within 48 hours [9]. |
| Yahoo | Bulk senders need a working one-click list-unsubscribe header and must honour unsubscribes within 2 days [10]. |
| The law | Laws ask for a working way to opt out and set deadlines, but do not name RFC 8058. In the US, "You must honor a recipient's opt-out request within 10 business days" [11]. See the law by country. |
Does a low-volume cold email need it?
If you send a few dozen emails a day from your own mailbox, Google's bulk sender rules do not apply to you, and the law only asks for a working opt-out. One-click unsubscribe is still worth having: it is the easiest way for someone to say no without marking you as spam, and a spam report costs you far more than an unsubscribe.
A checklist
- One HTTPS address in
List-Unsubscribe, with a token that identifies the person. List-Unsubscribe-Post: List-Unsubscribe=One-Click, exactly.- A POST endpoint that unsubscribes with no cookies, no login and no redirect.
- A GET page that asks for confirmation and changes nothing by itself.
- Both headers inside the DKIM signature.
- Unsubscribes honoured within 48 hours at most.
How Honest Intros does it
Every email Honest Intros sends carries both headers, with a signed token that names the recipient. A POST to that address stops all further email to the person straight away, with no login; opening the link in a browser shows a button and changes nothing until it is pressed.
Questions
Is RFC 8058 required by law?
No. It is a technical standard. The law asks for a working opt-out; Gmail and Yahoo require one-click unsubscribe from bulk senders.
Why does one-click unsubscribe use POST and not a normal link?
Because security scanners open normal links by themselves. A POST is only sent by the mail client when the reader asks to unsubscribe, so a scanner cannot unsubscribe anyone by accident.
Is a mailto unsubscribe address enough?
Not for one-click. RFC 8058 requires one HTTPS address in the List-Unsubscribe header. A mailto address can sit alongside it for older mail clients.
How fast must I honour an unsubscribe?
Google recommends within 48 hours and Yahoo asks for within 2 days. Laws set their own limits, such as 10 business days under the US CAN-SPAM Act.
See what it would write for you
Type your website. Honest Intros reads it and shows the kind of first email it writes, quoting your own pages.
Free to start. Nothing is sent until you approve it.