Folderly Flash Send-readiness test

Set up one-click List-Unsubscribe

For promotional or subscription mail, publish an HTTPS List-Unsubscribe URI plus List-Unsubscribe-Post and make the endpoint suppress the recipient on one POST. A footer link or mailto address alone does not meet Gmail's RFC 8058 one-click requirement.

Why mailbox providers enforce this

Gmail requires one-click unsubscribe for marketing and subscribed mail from senders above its bulk threshold, while Yahoo requires an easy unsubscribe path for bulk senders and highly recommends the RFC 8058 POST method. Correct unsubscribe reduces the chance that an unwanted message becomes a complaint. Missing one-click does not by itself prove why a message went to spam, and Google says it does not automatically reject or spam-folder a message solely for that omission.

Primary sources for this guidance

How to fix it

  1. Confirm the message class first. Gmail's one-click requirement applies to marketing and subscribed messages from bulk senders, not password resets, receipts or other transactional messages.
  2. Create an HTTPS unsubscribe URI with an opaque, hard-to-forge token that identifies the list and recipient without exposing their address in the URL.
  3. Add List-Unsubscribe with that HTTPS URI and add List-Unsubscribe-Post: List-Unsubscribe=One-Click. You may also include a mailto URI, but it does not replace Gmail's HTTPS one-click path.
  4. Apply a valid DKIM signature that covers both List-Unsubscribe headers. RFC 8058 tells receivers not to offer one-click when that authenticated coverage is absent.
  5. Accept the provider's POST without login, confirmation or a redirect. Do not depend on browser cookies; the opaque URI must carry the bounded unsubscribe context.
  6. Honor the request within 48 hours and suppress the address from the relevant subscription stream before the next eligible send.
  7. Keep a clearly visible unsubscribe link in the body. It can lead to preferences, but it complements rather than replaces the header-based one-click action.
  8. Test with a synthetic subscriber through the production ESP: inspect the received headers and DKIM signature, issue the one-click POST, and confirm suppression without exposing a real recipient.

Limitations

Flash can show whether the tested message contains unsubscribe headers and whether message authentication passes. It does not execute the unsubscribe endpoint, classify every message under provider policy, or guarantee that a provider displays its unsubscribe UI.

Next action Send one representative promotional message through the production ESP to verify its received headers. Then use a synthetic subscriber to POST the HTTPS URI and confirm suppression within the required window.
Run a free test →

FAQ

Do transactional emails need one-click unsubscribe?
Gmail excludes transactional messages such as password resets, receipts and reservation confirmations from its one-click requirement. Classify mixed-purpose mail carefully and follow any legal requirements that also apply.
Does adding the headers guarantee an inbox unsubscribe button?
No. Providers apply their own eligibility and reputation checks before showing the UI. The headers and endpoint are required implementation evidence, not a display or placement guarantee.

Related

Content record Owner: Folderly Flash content operations Reviewed: 2026-08-11 Maintenance trigger: Review when RFC 8058 changes, Gmail or Yahoo changes unsubscribe requirements, or Flash changes the list_unsubscribe subcheck.
Want a deliverability engineer to fix this for you? Hand it to Folderly →