This guide assumes email unsubscribe compliance is already deployed and passing. It covers what breaks at scale and how mature teams operate it.
Edge cases that break a working setup#
- Unsubscribe pages that ask 'are you sure' with a hidden confirm button.
- Continuing sequences from a different tool after an opt-out in another.
- Mail forwarded through mailing lists or personal forwarders, which alters headers and content.
- Acquisitions and rebrands that introduce domains nobody audited.
- Vendors silently changing their sending infrastructure.
Operating it as infrastructure#
- Assign an owner for each sending domain and each vendor relationship.
- Put DNS records under version control or a change-review process.
- Alert on authentication pass rate drops and reputation changes, not just outages.
- Run a quarterly audit against the setup steps below.
- Document runbooks for the three most common failures.
Reference: the baseline setup#
- Include a visible unsubscribe link in every marketing message.
- Add List-Unsubscribe and List-Unsubscribe-Post headers so providers show a native unsubscribe button.
- Process opt-outs immediately; the legal maximum is 10 business days in the US, but providers expect 2 days.
- Never require login or more than one click to unsubscribe.
List-Unsubscribe: <https://example.com/u/abc123>, <mailto:unsub+abc123@example.com>
List-Unsubscribe-Post: List-Unsubscribe=One-ClickFrequently asked questions#
What is one-click unsubscribe?
An RFC 8058 header pair that lets the mailbox provider send a POST to your endpoint when a user clicks Unsubscribe in the client, with no landing page.