IGSendMail
All articlesCompliance

Unsubscribe Link Requirements by Law

What the law actually requires from your unsubscribe link under CAN-SPAM, CASL, and GDPR, plus the one-click List-Unsubscribe headers major mailbox providers now require from bulk senders. Includes a comparison table of deadlines, the friction you cannot add, footer requirements, and preference-center best practice.

Unsubscribe Link Requirements by Law
Erin Moore
Erin Moore
September 24, 20269 min read
Share:

Every commercial email must include a clear, working way to opt out. Under CAN-SPAM in the US you must honor requests within 10 business days; under CASL in Canada it is 10 business days from an unsubscribe mechanism valid for at least 60 days; under GDPR in the EU withdrawal must be as easy as consent was to give. Major mailbox providers now also require one-click list-unsubscribe headers for bulk senders.

This article explains the requirements plainly for marketers. It is not legal advice — regulations change and your obligations depend on where your recipients live. Consult qualified counsel before finalizing your compliance approach.

The four regimes most senders touch

LawApplies toConsent modelOpt-out deadlineMechanism must stay live
CAN-SPAM (US)Commercial email to US recipientsOpt-out10 business daysAt least 30 days after sending
CASL (Canada)Commercial electronic messages to Canadian recipientsOpt-in (express or implied)10 business daysAt least 60 days after sending
GDPR / ePrivacy (EU & UK)Marketing to individuals in the EU/UKOpt-in, with narrow soft opt-inWithout undue delayIn every message
Provider bulk sender rulesSenders of roughly 5,000+/day to major providersN/AWithin 2 daysOne-click header in every message

Notice the pattern: the deadlines are converging downward and the friction allowed is shrinking. The practical answer for almost every sender is to process unsubscribes instantly and automatically. Building your process around the longest legal deadline is a strategy that expires.

What "clear and conspicuous" actually means

Every one of these regimes uses some version of the phrase, and enforcement tends to focus on the same handful of failures:

  • Visible without hunting. The link belongs in the footer of every commercial message, not buried in a paragraph of legal text.
  • Legible. 6-point light gray on white is the classic bad-faith pattern. Use at least 12px and adequate contrast.
  • Honestly labeled. "Unsubscribe" or "Manage your preferences." Not "click here if you never want to hear from us again," and never disguised as something else.
  • Present in every commercial email, including one-off announcements and the last email in a sequence.
  • Working. Broken unsubscribe links are among the most common compliance failures, and they are entirely self-inflicted. Test yours after every template change.

Friction you cannot add

The heart of the requirement is that opting out must be at least as easy as opting in was. That rules out several practices that remain surprisingly common:

  • Requiring a login. A recipient may have signed up without ever creating an account, or may not remember the password. Forcing authentication to unsubscribe is not an acceptable mechanism.
  • Charging a fee or requiring any payment, for any reason.
  • Demanding extra personal data beyond the email address being removed.
  • Requiring a reason. You may ask, optionally, on the confirmation page. You may not gate the removal behind an answer.
  • Multi-step confirmation chains. One click to a page, one confirmation click at most. Three screens is a problem.
  • Only offering "pause for 30 days." Snooze options are a fine addition, but a full opt-out must always be available on the same screen.
  • Requiring a reply email as the sole method. A working link is expected.

The one-click List-Unsubscribe header

Beyond statute, the major mailbox providers now enforce their own bulk-sender rules, and these bite faster than any regulator. Since 2024, senders of significant daily volume to the largest providers must support one-click unsubscribe via email headers and process those requests within two days.

Technically this means two headers on each message: List-Unsubscribe containing an HTTPS URL (and optionally a mailto address), and List-Unsubscribe-Post: List-Unsubscribe=One-Click. The provider then renders a native "Unsubscribe" control next to your sender name, and clicking it sends a POST to your URL. Your endpoint must remove the subscriber without any further interaction — no landing page, no confirmation.

This is genuinely good for you. When a native unsubscribe control is easy to find, annoyed recipients use it instead of the spam button, and complaint rate is a far more damaging signal than an unsubscribe. Most reputable sending platforms add these headers automatically; if yours does not, that is worth fixing this week.

What else the footer needs

  1. A valid physical postal address. Required under CAN-SPAM and expected under CASL. A registered PO box or a commercial mail-receiving agency address is acceptable in the US.
  2. Accurate sender identification. The From name, From address, and Reply-To must not mislead about who is sending.
  3. A truthful subject line. Deceptive subject lines are a separate violation from anything unsubscribe-related.
  4. A permission reminder. One line — "You're receiving this because you signed up at example.com on March 3, 2026" — measurably reduces spam complaints from people who forgot.
  5. Contact details for the sender, which CASL requires explicitly.

Preference centers: the better alternative to a hard opt-out

You cannot make unsubscribing harder, but you can offer better options alongside it. A preference center presented on the unsubscribe page often retains a meaningful share of people who were reacting to frequency rather than to you.

Offer, on one screen: reduce to monthly, choose specific topics, pause for 60 days, and — clearly, at equal prominence — unsubscribe from everything. The mistake to avoid is hiding the full opt-out below the fold or styling it as a faint text link while the "reduce frequency" option is a large button. That asymmetry is exactly the kind of dark pattern regulators have begun naming explicitly.

Also distinguish transactional from marketing streams. A customer who opts out of your newsletter should still receive their receipts and shipping notifications; a preference center makes that distinction explicit rather than leaving you guessing.

Operational rules that keep you clean

  • Process instantly. Automate it. Manual suppression lists are how deadlines get missed.
  • Suppress globally, not per-list. Someone who unsubscribes should not reappear because a colleague uploaded a CSV that included them.
  • Never delete unsubscribes — suppress them. You need the record to prove you honored the request and to block future re-imports. Keep it as a suppression entry, not an active contact.
  • Log the timestamp and method of every opt-out and every original opt-in. Consent records are your evidence if a complaint arrives.
  • Never sell or transfer a list of people who opted out. Under CAN-SPAM this is specifically prohibited.
  • Apply the strictest applicable standard. If your list spans the US, Canada, and the EU, running everything to a GDPR-style opt-in standard is simpler than segmenting your compliance by geography — and it produces a better-performing list anyway. Our guide to GDPR email marketing compliance covers the consent and records side in more depth.
  • Audit quarterly. Click your own unsubscribe link from a real inbox, complete the flow, and confirm the address is actually suppressed on the next send.

Frequently asked questions

Is an unsubscribe link legally required in every email?

It is required in every commercial or marketing message. Purely transactional messages — receipts, password resets, shipping notices — generally do not require one, but adding promotional content to them can reclassify the message as commercial. Consult counsel for your specific situation.

How quickly must I honor an unsubscribe request?

CAN-SPAM and CASL both allow up to 10 business days, and GDPR requires action without undue delay. Major mailbox providers require bulk senders to process one-click unsubscribes within two days, so automatic instant processing is the only practical standard.

Can I ask why someone is unsubscribing?

You can ask, but only optionally and only after the removal is already guaranteed. Requiring a reason, a login, or any additional information before honoring the request is not permitted.

What is List-Unsubscribe one-click?

It is an email header pair that lets mailbox providers show a native unsubscribe button next to your sender name and remove the recipient with a single click. Bulk senders to major providers are required to support it and to process those requests within two days.

Should I delete unsubscribed contacts from my database?

No — move them to a suppression list instead. Deleting the record removes your proof that you honored the request and creates the risk of re-adding the same person through a future import.

Want compliance handled automatically, with one-click unsubscribe headers, global suppression, and GDPR/CAN-SPAM/CASL-ready footers built in? Start free with IGSendMail.

Enjoyed this article?

Get email marketing tips delivered to your inbox every week.