Set up one-click List-Unsubscribe
For promotional or subscription mail, publish an HTTPS List-Unsubscribe URI plus List-Unsubscribe-Post and make the endpoint suppress the recipient on one POST. A footer link or mailto address alone does not meet Gmail's RFC 8058 one-click requirement.
Gmail requires one-click unsubscribe for marketing and subscribed mail from senders above its bulk threshold, while Yahoo requires an easy unsubscribe path for bulk senders and highly recommends the RFC 8058 POST method. Correct unsubscribe reduces the chance that an unwanted message becomes a complaint. Missing one-click does not by itself prove why a message went to spam, and Google says it does not automatically reject or spam-folder a message solely for that omission.
Primary sources for this guidance
- RFC 8058 — Signaling One-Click Functionality for List Email Headers
- Gmail email sender guidelines
- Gmail sender guidelines FAQ
- Yahoo Sender Hub best practices
How to fix it
- Confirm the message class first. Gmail's one-click requirement applies to marketing and subscribed messages from bulk senders, not password resets, receipts or other transactional messages.
- Create an HTTPS unsubscribe URI with an opaque, hard-to-forge token that identifies the list and recipient without exposing their address in the URL.
- Add List-Unsubscribe with that HTTPS URI and add List-Unsubscribe-Post: List-Unsubscribe=One-Click. You may also include a mailto URI, but it does not replace Gmail's HTTPS one-click path.
- Apply a valid DKIM signature that covers both List-Unsubscribe headers. RFC 8058 tells receivers not to offer one-click when that authenticated coverage is absent.
- Accept the provider's POST without login, confirmation or a redirect. Do not depend on browser cookies; the opaque URI must carry the bounded unsubscribe context.
- Honor the request within 48 hours and suppress the address from the relevant subscription stream before the next eligible send.
- Keep a clearly visible unsubscribe link in the body. It can lead to preferences, but it complements rather than replaces the header-based one-click action.
- Test with a synthetic subscriber through the production ESP: inspect the received headers and DKIM signature, issue the one-click POST, and confirm suppression without exposing a real recipient.
Limitations
Flash can show whether the tested message contains unsubscribe headers and whether message authentication passes. It does not execute the unsubscribe endpoint, classify every message under provider policy, or guarantee that a provider displays its unsubscribe UI.