Skip to content
Claim your free business email
Deliverability

How to set up one-click unsubscribe (RFC 8058)

By Rasket TeamLast updated 13 min read

The short answer

One-click unsubscribe (RFC 8058) is two email headers: List-Unsubscribe, carrying an HTTPS URL that identifies the recipient and list, and List-Unsubscribe-Post: List-Unsubscribe=One-Click. A DKIM signature must cover both. The mail app sends a POST to that URL, and your server removes the address at once, with no login, confirmation page or redirect.

What one-click unsubscribe is

One-click unsubscribe is a way for a mail app to take someone off your list without sending them to your website. It is defined by RFC 8058, published by the IETF in January 2017, and it builds on a much older header: List-Unsubscribe, from RFC 2369 (1998), which lets a message say where to send an unsubscribe request.[1][2]

The older header had a problem the new one exists to fix. RFC 8058 explains that “anti-spam software often fetches all resources in mail header fields automatically”, so a sender cannot tell a real click from a scanner, and senders protected themselves with a confirmation page — which makes the process “more complex than a single click”. One-click replaces that with an HTTPS POST that only a mail app sends, and only with the reader’s consent.[1]

A marketing email carries List-Unsubscribe and List-Unsubscribe-Post headers signed by DKIM. When the reader presses the mail app’s unsubscribe button, the mailbox provider sends an HTTPS POST with the body List-Unsubscribe=One-Click to the URL in the header, and the sender’s server removes the address and answers 200 without a redirect.Your emailList-UnsubscribeList-Unsubscribe-PostDKIM covers bothMail appReader pressesUnsubscribe(with their consent)Your serverVerifies the tokenRemoves the addressAnswers 200, no redirectPOST List-Unsubscribe=One-ClickRFC 8058, in three steps
The headers travel with the message; the unsubscribe itself is one HTTPS POST from the mailbox provider to your server. Nothing in it needs the reader to visit your site.

The standard is also frank about why senders should want this. Mailbox providers know “their users do not make a clear distinction between unsubscription and junk”, and if unsubscribing is too difficult, “the recipient’s alternative is to report mail from the sender as junk”.[1] Every unsubscribe that one click makes easy is, very often, a spam complaint that never happens. The companion guide on lowering your spam complaint rate picks up from there.

Who requires one-click unsubscribe

Gmail requires anyone sending 5,000 or more messages a day to personal Gmail accounts to support one-click unsubscribe on marketing and subscribed messages, and to include “a clearly visible unsubscribe link in the message body”.[3] The bulk-sender rules took effect in February 2024; senders who already had an unsubscribe link were given until June 1, 2024 for one-click.[4] Yahoo requires a working list-unsubscribe header with one-click for the same kinds of mail.[5] Microsoft’s rules for Outlook.com recommend a functional, clearly visible unsubscribe link and do not name RFC 8058.[6]

What each mailbox provider documents about unsubscribing
GmailYahooOutlook.com
Who it applies to5,000+ a day to GmailBulk senders5,000+ a day (recommended)
RFC 8058 POSTRequired“Highly recommended”Not named
mailto: aloneDoes not meet the requirement“Acceptable”Not named
Visible link in the bodyRequiredRequired; may go to a preference pageRecommended
Time to honourWithin 48 hoursWithin 2 daysNot stated
Transactional mailExcludedMarketing and subscribed onlyNot stated

Gmail’s FAQ settles the questions senders ask most. One-click is required “only for marketing and promotional messages” — password resets, reservation confirmations and form confirmations are excluded — and mailto or plain unsubscribe links “don’t meet our one-click unsubscribe requirement”. You must “include one HTTPS URL in the List-unsubscribe: header”.[4] The line between the two kinds of mail is drawn in transactional vs marketing email, and the rest of the bulk-sender rules in the Gmail and Yahoo sender requirements.

48 hours

is how quickly Google recommends you fulfil an unsubscribe request. Google lists unsubscribes not honoured within 48 hours, and marketing mail missing one-click unsubscribe, among the failures that make a bulk sender ineligible for its delivery support and mitigations.
Source: Gmail Help, Google, “Email sender guidelines FAQ” [4]

Missing the requirement does not bounce your mail. Google says it does not automatically reject or spam-folder messages for it — but “unwanted messages that don’t use one-click unsubscribe are more likely to be reported as spam by recipients”, and reports decide where your future mail goes.[4]

The List-Unsubscribe and List-Unsubscribe-Post headers

RFC 8058 asks for exactly two header fields. List-Unsubscribe “MUST contain one HTTPS URI” and may also carry a non-HTTP one such as mailto:; List-Unsubscribe-Post “MUST contain the single key/value pair ‘List-Unsubscribe=One-Click’”.[1]

The two headers on a marketing email
List-Unsubscribe: <https://example.com/u/eyJsIjoibmV3cyIsInMiOjQyfQ.k3Jz9Q>,
 <mailto:unsubscribe@example.com?subject=unsubscribe>
List-Unsubscribe-Post: List-Unsubscribe=One-Click

List-Unsubscribe

  • Angle brackets, comma-separated. Each URL sits inside < and >; several are separated by commas, in order of preference from left to right.[2]
  • One HTTPS URL that identifies the person and the list. There is no way to pass extra fields with the POST, so the URL “MUST contain enough information to identify the mail recipient and the list”.[1]
  • An opaque, hard-to-forge token. The URL “SHOULD include an opaque identifier or another hard-to-forge component”, and your server should check it. The point is to stop someone who knows your URL pattern from unsubscribing other people.[1] A signed token (an HMAC over the list and subscriber ids) does this without a database lookup to reject a forgery.
  • A mailto is optional. Keep one if you can process it: Yahoo accepts mailto,[5] and some older clients only speak mail. It does not satisfy Gmail on its own.[4]

List-Unsubscribe-Post

The value is fixed. The standard limits it to one known key and value on purpose, so a malicious message cannot use it to make a mail app fill in an arbitrary form on someone else’s website.[1] Copy it byte for byte: List-Unsubscribe=One-Click.

Sign both headers with DKIM

This is the requirement most often missed. The message “MUST have a valid DomainKeys Identified Mail (DKIM) signature that covers at least the List-Unsubscribe and List-Unsubscribe-Post headers”, which means both names appear in the h= tag of the DKIM-Signature. Without it, the mail receiver “SHOULD NOT offer a one-click unsubscribe for that message”.[1]

What to look for in the received message
DKIM-Signature: v=1; a=rsa-sha256; d=example.com; s=mail;
 h=from:to:subject:date:message-id:list-unsubscribe:list-unsubscribe-post;
 bh=...; b=...

Two practical consequences. First, the headers have to exist before the message is signed: a tool that adds them afterwards produces headers the signature does not cover. Second, the signing domain should be yours and aligned with your From domain, which is what Gmail’s bulk-sender rules ask for anyway.[3] The background is in DKIM, SPF and DMARC explained and the DKIM glossary entry.

Handling the one-click POST request

When a reader presses unsubscribe, the mailbox provider sends your URL a POST whose body is the header’s value. Gmail’s guidelines show the request you receive:[3]

The request a one-click unsubscribe sends
POST /u/eyJsIjoibmV3cyIsInMiOjQyfQ.k3Jz9Q HTTP/1.1
Host: example.com
Content-Type: application/x-www-form-urlencoded
Content-Length: 26

List-Unsubscribe=One-Click

RFC 8058 says the body “SHOULD” be sent as multipart/form-data and “MAY” be sent urlencoded, so parse both. The POST goes to the same URL a person would open by hand, which is deliberate: one route can serve the confirmation page on GET and the one-click on POST. And the rules for the response are strict:[1]

  1. No redirect. “The mail sender MUST NOT return an HTTPS redirect,” because redirected POSTs have historically not worked reliably.[1] Answer with a 200 directly.
  2. No login, no cookies, no confirmation. The request “MUST NOT include cookies, HTTP authorization, or any other context information”.[1] Anything that waits for a person to click a button never completes, because no person is looking.
  3. Never unsubscribe on GET. Link scanners fetch URLs in headers automatically;[1] a GET that unsubscribes will take people off your list who never asked.
  4. Make it idempotent. A provider may retry, and a reader may press twice. Unsubscribing an address that is already off the list should still answer 200.

A minimal handler, written against the standard Request and Response:

app/u/[token]/route.ts — a minimal one-click endpoint
import { createHmac, timingSafeEqual } from "node:crypto";

const SECRET = process.env.UNSUBSCRIBE_SECRET!; // a long random key

// token = base64url(JSON [listId, subscriberId]) + "." + HMAC of that part
function verify(token: string): { listId: string; subscriberId: string } | null {
  const [payload, mac] = token.split(".");
  if (!payload || !mac) return null;
  const expected = createHmac("sha256", SECRET).update(payload).digest();
  const given = Buffer.from(mac, "base64url");
  if (given.length !== expected.length || !timingSafeEqual(given, expected)) return null;
  const [listId, subscriberId] = JSON.parse(Buffer.from(payload, "base64url").toString());
  return { listId, subscriberId };
}

export async function POST(request: Request, ctx: { params: Promise<{ token: string }> }) {
  const who = verify((await ctx.params).token);
  if (who === null) return new Response(null, { status: 404 });

  const form = await request.formData(); // urlencoded or multipart/form-data
  if (form.get("List-Unsubscribe") !== "One-Click") return new Response(null, { status: 400 });

  await unsubscribe(who.listId, who.subscriberId); // idempotent; records when and how
  return new Response(null, { status: 200 }); // no page, no redirect
}

// GET shows a page with a button that POSTs back here. It never unsubscribes by itself.

Keep the endpoint working for as long as the mail is in someone’s inbox. In the US, CAN-SPAM sets a legal floor for that:[8]

30 days

is the minimum time an opt-out mechanism must keep working after you send, under the FTC’s CAN-SPAM rules, which also require honouring an opt-out within 10 business days. Tokens that expire sooner than that break the law as well as the button.
Source: U.S. Federal Trade Commission, “CAN-SPAM Act: A Compliance Guide for Business” [8]

Step by step: set up one-click unsubscribe

The order matters: the headers are useless without the signature, and the signature is useless without an endpoint that answers.

  1. Decide which mail gets the headers

    Add one-click unsubscribe to marketing and subscribed mail: newsletters, promotions, digests. Leave it off transactional mail such as receipts, password resets and account alerts, which Gmail excludes from the requirement.

  2. Mint a signed unsubscribe URL per recipient and list

    Build an HTTPS URL that carries an opaque, hard-to-forge token identifying the subscriber and the list, such as an HMAC over their ids. Never put a bare email address in it, and keep it valid for at least 30 days.

  3. Add both headers before signing

    Write List-Unsubscribe with the HTTPS URL in angle brackets (optionally followed by a mailto) and List-Unsubscribe-Post: List-Unsubscribe=One-Click, then DKIM-sign the message so both header names appear in the signature's h= tag.

  4. Handle the POST at that URL

    Accept urlencoded and multipart bodies, verify the token, check for List-Unsubscribe=One-Click, remove the subscriber from that list and answer 200. No redirect, no login, no confirmation step, and never unsubscribe on a GET.

  5. Keep a visible link in the body

    Add an unsubscribe link people can see in every marketing email. It may lead to a preference page where readers choose fewer topics or leave everything, as long as the headers still offer one click.

  6. Test it and watch Postmaster Tools

    Read the raw headers of a test send, replay the POST with curl, tamper with the token to confirm it fails, and check the compliance dashboard in Postmaster Tools for one-click unsubscribe and honouring unsubscribes.

Before your next campaign

  • Every marketing message carries List-Unsubscribe with one HTTPS URL, and List-Unsubscribe-Post: List-Unsubscribe=One-Click.
  • Transactional messages (receipts, resets, alerts) carry neither.
  • The DKIM-Signature h= tag lists both headers.
  • The URL carries a signed token for the person and the list, not a bare address.
  • POST answers 200 with no redirect, no login and no confirmation step.
  • GET never unsubscribes; it shows a page.
  • The unsubscribe takes effect at once — well inside 48 hours.
  • The body also has a visible unsubscribe link.
  • The endpoint is exempt from bot challenges and keeps working for old messages.

The headers do not replace the link in the email. Gmail requires a visible unsubscribe link in the body for bulk marketing mail,[3] and Yahoo says that link “may direct to a preference page”.[5] The body link does not have to be one-click itself; Google says it “can link to a preferences web page that you specify”.[4]

That split is what lets you offer choice without breaking the rule. The header removes someone from “the mailing list associated with the message”, not from everything you send,[4] and the preference page lets a reader who only wants less mail pick fewer topics instead of leaving entirely. Google’s guidelines suggest exactly this — let people unsubscribe from lists individually or all at once — alongside one-click, never instead of it.[3]

How to test your List-Unsubscribe-Post setup

  1. Read the raw headers. Send a campaign to yourself and open the original message (in Gmail, “Show original”). Confirm both headers are present, the URL is HTTPS, DKIM passes, and both names are in the signature’s h= list.
  2. Replay the POST yourself. Send exactly what a mailbox provider sends and check you get a 200 with no Location header, then that the subscriber is actually off the list.
  3. Tamper with the token. Change one character and send it again. It should fail, and it should not unsubscribe anyone.
  4. Watch Postmaster Tools. Its compliance dashboard reports one-click unsubscribe and honouring unsubscribes for your domain.[7]
Replay a one-click unsubscribe
curl -i -X POST 'https://example.com/u/eyJsIjoibmV3cyIsInMiOjQyfQ.k3Jz9Q' \
  -H 'Content-Type: application/x-www-form-urlencoded' \
  --data 'List-Unsubscribe=One-Click'

# expect: HTTP/2 200, no Location header, and the subscriber gone

Do not use the button’s appearance as your test. Gmail shows its unsubscribe link next to the sender name “only for messages that pass Google’s automated eligibility checks”, which include meeting the sender requirements and building volume gradually — so a correct setup can still show no button on a new domain.[4]

Common one-click unsubscribe mistakes

What goes wrong, and what the standard or provider says instead
MistakeWhy it failsFix
Headers added after signingThe DKIM signature does not cover them, so no one-click is offered.Add the headers first, then sign.
Redirect to a “you’re unsubscribed” pageRFC 8058 forbids redirects on the POST.Answer 200 directly.
A confirmation step on POSTNobody is there to confirm; the request never completes.Unsubscribe on the POST itself.
Unsubscribing on GETScanners fetch header URLs and unsubscribe people who never asked.GET shows a page; only POST changes anything.
mailto onlyDoes not meet Gmail’s requirement.Add one HTTPS URL; keep the mailto as a second choice.
Plain email address in the URLAnyone can unsubscribe anyone.Use a signed, opaque token.
Headers on receipts and resetsInvites people to unsubscribe from mail they need.Marketing and subscribed mail only.

Myths about one-click unsubscribe

  • Documented by Google “A mailto: in List-Unsubscribe is enough for Gmail.” False: Gmail supports mailto links but says they do not meet its one-click requirement.[4]
  • Documented by Google “Missing one-click gets your mail rejected.” Not directly: Google says it does not reject or spam-folder mail for this alone. It costs you through complaints and through losing eligibility for mitigation.[4]
  • Documented by Google “The unsubscribe link in the body must be one-click too.” False, when the headers are in place; the body link can go to a preference page.[4]
  • Documented by Google “One-click removes people from everything you send.” Not by itself: the header unsubscribes from the list the message belongs to.[4] Gmail’s own subscription manager does remove people from every list of a sender, though.[10]
  • Documented by Google “Keep sending after an unsubscribe until the list syncs.” Costly: when someone who unsubscribed receives more mail from you, Gmail sends it straight to Spam.[11]
  • Unproven “Making it easy to leave shrinks your list for nothing.” The people leaving were not going to read. RFC 8058 notes their alternative is the spam button,[1] and a 2008 survey by Q Interactive and MarketingSherpa found many people reached for it on purpose (below).

43%

of respondents to the 2008 Spam Complainers Survey by Q Interactive and MarketingSherpa said they skip unsubscribe links and press Report Spam instead, believing it removes them from the list. The published summary gives no sample size, and the survey predates one-click; read it as a direction, not a current measurement.
Source: Daily Research News Online, MrWeb (26 March 2008), “Survey Reveals Spam Misconceptions” [12]

What the law adds to one-click unsubscribe

Mailbox providers set the technical rules; the law sets its own, and one-click does not replace them. In the US, CAN-SPAM requires a clear and conspicuous way to opt out of all marketing mail from you, honoured within 10 business days, and forbids charging a fee or asking for anything beyond an email address and a single page visit or reply.[8] In the UK, PECR requires a valid contact address for opting out in every marketing message, solicited or not.[13] Record every opt-out with when and how it happened; you may need to prove you honoured it.

One-click unsubscribe in Rasket

If you send marketing mail with Rasket’s Campaigns (the API resource is broadcasts), none of the above is yours to build. Every campaign message carries List-Unsubscribe with a signed HTTPS URL and List-Unsubscribe-Post: List-Unsubscribe=One-Click, both written before the message is DKIM-signed with your verified domain. Transactional sends never carry the headers.

The URL points at a preference page we host. It needs no login; a GET only shows the page, a one-click POST unsubscribes the contact at once and answers 200 with no redirect, and the page lets a contact opt out of everything or change individual topics. A campaign body without an unsubscribe link gets a footer with one and your postal address, and every change is written to a consent record. See marketing email for the rest of the picture, and the Gmail Promotions tab guide for what these headers do and do not do for placement.

Frequently asked questions

What is one-click unsubscribe?

It is a standard, RFC 8058, that lets a mail app unsubscribe someone for you. The email carries a List-Unsubscribe header with an HTTPS URL and a List-Unsubscribe-Post header; when the reader presses the app's unsubscribe button, the mailbox provider sends a POST to that URL and the sender removes the address without any page or login.

What does the List-Unsubscribe-Post header do?

It tells mail apps that the HTTPS URL in List-Unsubscribe accepts a one-click POST. Its value is fixed: List-Unsubscribe=One-Click, which is also the body the POST sends. RFC 8058 limits it to that single key and value so it cannot be used to submit arbitrary forms.

Is one-click unsubscribe required?

For marketing and subscribed mail to Gmail, yes, if you send about 5,000 or more messages a day to personal Gmail accounts. Yahoo requires it for bulk senders too. Microsoft recommends a clearly visible unsubscribe link for Outlook.com but does not name RFC 8058. Smaller senders gain the same benefit: fewer spam complaints.

Do transactional emails need a List-Unsubscribe header?

No. Google's FAQ says one-click unsubscribe is required only for marketing and promotional messages, and gives password resets, reservation confirmations and form submission confirmations as examples of excluded transactional mail. Adding the header to receipts invites people to unsubscribe from mail they need.

Is a mailto link in List-Unsubscribe enough for Gmail?

No. Gmail still supports mailto links, but says they do not meet its one-click unsubscribe requirement: you need one HTTPS URL in the List-Unsubscribe header plus List-Unsubscribe-Post. Yahoo calls mailto acceptable and the POST method highly recommended, so offer both, HTTPS first.

Why doesn't Gmail show an unsubscribe button next to my sender name?

Gmail shows it only for messages that pass its automated eligibility checks, which include meeting the sender requirements, correct one-click headers covered by DKIM, and building volume gradually. Check the raw headers and the DKIM h= tag first; on a new domain, the button can take time to appear.

How quickly do I have to process an unsubscribe?

Google recommends within 48 hours and Yahoo within 2 days; missing that makes a bulk sender ineligible for Gmail's delivery mitigation. CAN-SPAM's legal limit in the US is 10 business days. Doing it at once is best, because Gmail sends mail to people who unsubscribed straight to Spam.

Does Rasket add one-click unsubscribe headers?

Yes, on every Campaigns message. Each carries List-Unsubscribe with a signed HTTPS URL and List-Unsubscribe-Post, written before the message is DKIM-signed, and the URL serves a hosted preference page that honours a one-click POST at once. Transactional sends never carry the headers.

Sources

13 primary sources, each read on the date shown.

See all sources
  1. 1.RFC 8058: Signaling One-Click Functionality for List Email Headers — IETF (January 2017),
  2. 2.RFC 2369: The Use of URLs as Meta-Syntax for Core Mail List Commands and their Transport through Message Header Fields — IETF (July 1998),
  3. 3.Email sender guidelines — Gmail Help, Google,
  4. 4.Email sender guidelines FAQ — Gmail Help, Google,
  5. 5.Sender Requirements & Recommendations — Yahoo Sender Hub,
  6. 6.Strengthening Email Ecosystem: Outlook’s New Requirements for High‐Volume Senders — Microsoft Defender for Office 365 Blog (2 April 2025),
  7. 7.Postmaster Tools dashboards — Gmail Help, Google,
  8. 8.CAN-SPAM Act: A Compliance Guide for Business — U.S. Federal Trade Commission,
  9. 9.Manage email subscriptions from a single location in Gmail — Google Workspace Updates (8 July 2025),
  10. 10.Manage your subscriptions in Gmail — Gmail Help, Google,
  11. 11.Report spam in Gmail — Gmail Help, Google,
  12. 12.Survey Reveals Spam Misconceptions — Daily Research News Online, MrWeb (26 March 2008),
  13. 13.How do we comply with the PECR electronic mail marketing rules? — UK Information Commissioner’s Office,

Keep reading

Written by the Rasket Team. First published ; last checked against its sources . See something out of date? How we correct guides.

Send email that earns its place

Authenticated mail, one-click unsubscribe and separate reputations for campaigns and transactional mail, set up in minutes.