Skip to Main Content
Back to Learning CenterDeliverability

One-click unsubscribe law: RFC 8058 vs CAN-SPAM

Johanie DupontBy Johanie DupontAugust 12, 2026Updated September 17, 202610 min read

In brief

One-click unsubscribe law: RFC 8058 is a standard Gmail and Yahoo enforce, not a statute. What CAN-SPAM actually requires, and what it does not.

One-click unsubscribe law: RFC 8058 vs CAN-SPAM

There is no statute called the "one-click unsubscribe law." The term people search for usually points to RFC 8058, an IETF technical standard, which Gmail and Yahoo have each turned into a bulk-sender requirement. The actual law on unsubscribing, in the United States, is the CAN-SPAM Act, which requires a working opt-out on every commercial email and says nothing about RFC 8058.

At a glance

Quick takeaways

  • One-click unsubscribe is a protocol standard, RFC 8058, not a law passed by a legislature.
  • Gmail and Yahoo each require it from their bulk senders; the thresholds, covered message types and effective dates are on the Google and Yahoo requirements page.
  • The law that does apply in the United States is CAN-SPAM: a clear opt-out notice on every commercial email, a mechanism that keeps working for at least 30 days after sending, and requests honored within 10 business days, per the FTC's compliance guide.
  • Consumer subscription-cancellation rules, sometimes called "click to cancel," are a separate legal subject from email one-click unsubscribe. Confirm those with counsel or the relevant regulator.

Who is affected?

Who is affected by the one-click unsubscribe requirement depends on the mailbox provider, not on the RFC. RFC 8058 itself does not name a sending volume or a specific mailbox provider. It defines a signal that any list sender can add to outgoing mail, and a behavior any mail receiver can implement when it sees that signal.

Mailbox providers decide who has to use it. Google's Email sender guidelines require it of bulk senders to personal Gmail accounts on "Marketing messages and subscribed messages", and Yahoo's Sender Best Practices require bulk senders to "Implement a functioning list-unsubscribe header, which supports one-click unsubscribe". The thresholds, covered message types, honor windows and effective dates for both are on the Google and Yahoo requirements page; this page does not restate them.

Transactional-only senders with no marketing or subscribed mail are outside the scope both providers describe. Whether they are also outside CAN-SPAM is a separate question, answered by the primary-purpose test below.

What is actually law, and what is provider policy?

The one-click unsubscribe mechanism itself comes from a technical standard, not a statute. It is RFC 8058, an IETF Standards Track document from January 2017, and the obligation to use it comes from Gmail's and Yahoo's own sender requirements. The legal layer sits underneath that and is older and broader: in the United States the CAN-SPAM Act sets the rules for commercial email, and the FTC's compliance guide is the plain-language statement of them.

LayerWho sets itWhat it requires of an unsubscribeWho it applies to
RFC 8058IETFThe List-Unsubscribe and List-Unsubscribe-Post header pair, covered by DKIM, answered by an HTTPS POST with no cookies, login or redirectNobody by itself; it defines a mechanism
Gmail and Yahoo sender requirementsThe mailbox providersOne-click support on marketing and subscribed mail from bulk senders, plus a visible body link at GmailBulk senders to those providers' mailboxes
CAN-SPAM ActUnited States Congress, enforced by the FTCA clear and conspicuous opt-out notice, an opt-out mechanism that works for at least 30 days, and opt-outs honored within 10 business daysEvery commercial email, at any volume, including business-to-business

The technical mechanics of the header pair, the DKIM h= coverage and the POST are on one-click unsubscribe and the RFC 8058 header pair. The provider applicability matrix, thresholds and dates are on Google and Yahoo one-click unsubscribe requirements. This page stays on the legal question.

What does CAN-SPAM require for opting out?

The FTC's CAN-SPAM compliance guide sets out the opt-out duties for any commercial email, which it defines as "any electronic mail message the primary purpose of which is the commercial advertisement or promotion of a commercial product or service". The guide notes the law "makes no exception for business-to-business email" and that CAN-SPAM "doesn't apply just to bulk email".

  • Tell recipients how to opt out. The message "must include a clear and conspicuous explanation of how the recipient can opt out of getting marketing email from you in the future", with "a return email address or another easy Internet-based way" to communicate the choice.
  • Keep the mechanism working. "Any opt-out mechanism you offer must be able to process opt-out requests for at least 30 days after you send your message."
  • Honor requests within ten business days. "You must honor a recipient's opt-out request within 10 business days." The sender "can't charge a fee, require the recipient to give you any personally identifying information beyond an email address, or make the recipient take any step other than sending a reply email or visiting a single page on an Internet website".
  • Subscribers and members keep the right. Recipients of a subscription or membership program "still have the right to opt out of marketing messages from you".
  • Penalties are per message. "Each separate email in violation of the CAN-SPAM Act is subject to penalties of up to $53,088", and more than one party can be held responsible.
None of that names RFC 8058. A message can satisfy CAN-SPAM with a compliant opt-out link and still fail Gmail's or Yahoo's one-click requirement, and a message can carry a perfect RFC 8058 header pair and still break CAN-SPAM by taking longer than ten business days to act on it. Meet both.

Which messages are commercial under CAN-SPAM?

The guide's test is the message's "primary purpose". Content is commercial, transactional or relationship, or other. A message that only "Facilitates, completes, or confirms a commercial transaction that the recipient already has agreed to", or notifies a change to an ongoing account, is transactional or relationship and "is otherwise exempt from most provisions of the CAN-SPAM Act" apart from truthful routing information.

When a message mixes both, the FTC says the primary purpose is commercial "If a recipient reasonably interpreting the subject line would likely conclude that the message contains an advertisement or promotion" or "if the message's transactional or relationship content does not appear mainly at the beginning of the message". The guide warns that the transactional categories are read narrowly, so a receipt with a promotion at the top is commercial mail and needs the opt-out.

This is close to, but not the same as, the provider line. Google and Yahoo exclude transactional messages from the one-click rule, and Google's sender-guidelines FAQ says recipients, not Google, decide what they regard as promotional. CAN-SPAM decides by primary purpose and subject line. Classify each message stream against both tests.

When does each rule take effect?

Each rule takes effect differently: RFC 8058 has no enforcement date of its own, CAN-SPAM's opt-out duties already apply to every commercial email, and the only rollout dates are the mailbox providers'. RFC 8058 itself was published as an IETF Standards Track document in January 2017. Publication of the RFC did not create an enforcement date on its own; that came later, from individual mailbox providers.

Provider effective dates and thresholds are on the provider requirements page. CAN-SPAM's civil penalty maximum is adjusted for inflation; the FTC's guide notes it was edited in January 2024 to reflect the current figure.

How do I know which rule applies to me?

Which rule applies to a message comes down to three questions, asked in order. Is the message commercial by CAN-SPAM's primary-purpose test? If yes, it needs the CAN-SPAM opt-out regardless of volume or provider. Is it a marketing or subscribed message sent to Gmail or Yahoo mailboxes by a bulk sender, as those providers define both? If yes, it needs the one-click mechanism whatever the CAN-SPAM answer was, with a visible body link for Gmail; transactional messages are outside both providers' rules. Does it go to recipients outside the United States? Then a different statute may apply, and the FTC guide does not cover it; confirm with counsel or the relevant regulator.

Checking compliance is two separate tests. For the legal layer, confirm the opt-out notice is in the message, the mechanism keeps working for at least 30 days after the send, and suppression completes within ten business days across every system that can send to that recipient. For the provider layer, inspect a delivered message's raw headers for the RFC 8058 pair and its DKIM coverage; one-click unsubscribe and the RFC 8058 header pair walks through that check.

Check your domain's authentication posture

A correctly signed one-click header pair depends on working DKIM in the first place. If you have not confirmed your domain's SPF, DKIM, and DMARC records are published correctly, that is worth checking before troubleshooting header coverage.

Check your domain's authentication setup

This check reads public DNS records. It cannot confirm that a specific delivered message carries the RFC 8058 headers, that DKIM covers them, or that an opt-out was honored within the legal window; those need the delivered message and your suppression records. For what Gmail and Yahoo require on unsubscribe, see Google and Yahoo one-click unsubscribe requirements; for the rest of Google's bulk-sender rules, see the Gmail bulk sender guidelines.

Evidence

Sources and further reading

Where email deliverability and unsubscribe handling fit into a broader sender program, the deliverability hub covers the surrounding practices. Subscription-cancellation rules are a separate legal subject from email opt-outs; confirm current requirements with counsel or the relevant regulator.

Questions readers ask

Frequently asked questions

Is one-click unsubscribe a law?

No. One-click unsubscribe is RFC 8058, a technical standard published by the IETF in January 2017. Gmail and Yahoo each require it as part of their own bulk-sender rules, which is a mailbox-provider policy, not legislation. Separately, the FTC's CAN-SPAM guide requires commercial email to tell recipients how to opt out and to honor opt-out requests promptly, but that requirement does not itself specify the RFC 8058 header mechanism.

Is "click to cancel" the same as one-click unsubscribe?

No. "Click to cancel" and "one click cancel" refer to consumer subscription-cancellation rules, a separate legal subject from email unsubscribe. Those rules come from consumer-protection law, not from RFC 8058 or mailbox-provider policy, so confirm what applies to your subscriptions with the FTC, your state attorney general's office, or counsel.

Does CAN-SPAM require the RFC 8058 header pair?

Not directly. The FTC's CAN-SPAM compliance guide requires commercial email to tell recipients how to opt out and to honor those requests promptly, but the guide does not itself mandate List-Unsubscribe or List-Unsubscribe-Post. The RFC 8058 header pair is a mailbox-provider requirement from Gmail and Yahoo, layered on top of, not substituting for, general CAN-SPAM opt-out obligations.

How quickly does the law require an opt-out to be honored?

The law requires an opt-out to be honored within 10 business days under CAN-SPAM, and the opt-out mechanism must keep working for at least 30 days after the message is sent, according to the FTC's compliance guide. That is the legal deadline. Yahoo also publishes its own, shorter honor window for bulk senders, stated on the provider requirements page, so the tightest deadline you face may be a provider's, not the statute's.

Does CAN-SPAM apply to business-to-business email?

Yes. The FTC's guide states that the law "makes no exception for business-to-business email" and that it "doesn't apply just to bulk email". Any message whose primary purpose is commercial needs the opt-out notice, the working mechanism and the ten-business-day honor window, whether it goes to one prospect or a list.

Find the authentication issues behind your delivery problem

Start in Palisade.

Get started

Share this article

Johanie Dupont

Written by

Johanie Dupont

Brand & Ecommerce Email

Johanie Dupont works on brand and ecommerce email at Palisade: BIMI and verified marks, sender requirements, and getting marketing mail into the inbox.

More from Johanie →

Related articles and tools