Unsubscribe
opt out of email / list-unsubscribe / one-click unsubscribe / CAN-SPAM opt-out
Unsubscribing has a legal shape and a technical one. The law allows a reply or a single web page, with no fee and no information beyond the address, honored within 10 business days. The one-click standard exists because automated scanners were unsubscribing people by accident.
The statute sets two clocks. Once a recipient asks not to receive further commercial email, it is unlawful for the sender to transmit a covered message more than 10 business days after receiving that request. Separately, the mechanism you offered has to keep working: the address or page must remain capable of receiving those requests for no less than 30 days after the original message went out.
The Federal Trade Commission's rule then governs what you may ask of someone on the way out, and it is stricter than most unsubscribe flows. Under 16 CFR 316.5 a sender may not require the recipient to pay any fee, to provide any information other than their email address and opt-out preferences, or to take any steps except sending a reply email or visiting a single web page. No account login, no survey, no reason required, and nothing beyond one page.
That last constraint collided with a practical problem, which is where the technical half comes in. RFC 8058 explains it plainly: anti-spam software often fetches all resources in mail header fields automatically, without any action by the user, and there is no mechanical way for a sender to tell whether a request came from software or from a person. Senders responded by adding a confirmation step, which protected them from accidental unsubscribes and made the experience worse for everyone.
The one-click standard resolves that. It defines a signal a sender places in the header so a mail provider can offer a genuine one-press unsubscribe that automated scanners will not trigger by accident. The result is the outcome the law wanted and the safety senders needed, in the same mechanism.
In practice
Two checks settle whether your setup is defensible. Does the link land somewhere that completes the request without a login, a form or a reason, and does the request take effect well inside 10 business days. A flow that asks somebody to sign in to leave a list is asking for information beyond an email address and opt-out preferences.
Not the same as
- Consent
- That is whether you were allowed to send in the first place. This is the exit, and it has its own separate rules and deadlines.
- Deleting the record
- Honoring an opt-out means not sending, and the address is normally kept precisely so it stays suppressed.
Why it matters to you
An unsubscribe flow is usually built by whoever set up the email tool, using whatever that tool offered, and nobody checks it against the rule. It is also the single most visible part of your email practice to a recipient who has decided to leave, and the cheapest thing in marketing to get right. The rules here are short, specific and old, which means there is no interpretive question to resolve.
What to ask or check
- 01Click our own unsubscribe link: does it complete in one page, with no login and no questions?
- 02How quickly does a request take effect, and who would notice if it stopped working?
- 03Does our email carry the one-click header, so providers can offer the button that does not misfire?
What people get wrong
That an unsubscribe page may ask why somebody is leaving or require them to sign in. The rule permits a reply email or a single web page and forbids requiring any information beyond the address and opt-out preferences.
Red flags
- An unsubscribe link that opens a login screen.
- A required reason, survey or preference form before the request completes.
- An unsubscribe page that stopped working, when the mechanism has to stay live for at least 30 days after the message.
Who owns it
The sender, and explicitly anyone acting on their behalf, which is language the statute uses so an agency or a platform cannot absorb the duty.
Where you will see it
At the foot of every marketing email you send, and in the header your sending tool does or does not set.