Across various sources, including email marketing experts, technical documentation (RFCs, CAN-SPAM), and real-world platform recommendations, the consensus is that relying solely on the 'From' address in mailto: unsubscribe requests is unreliable and a poor practice. Key issues include the potential for email spoofing, forwarding of emails to different recipients, and the existence of tagged/receive-only addresses. Modern best practices emphasize using web-based unsubscribe links with unique identifiers, one-click unsubscribe options (RFC 8058), and clear/accessible preference centers. Compliance with regulations (CAN-SPAM) and proactive list management (cleaning, re-engagement) are also vital.
13 marketer opinions
The consensus among email marketers and experts is that relying solely on the 'From' address in mailto: unsubscribe requests is unreliable and not recommended. This is primarily due to the ease of spoofing email addresses and the common practice of email forwarding, which can lead to unsubscribing the wrong address. Modern best practices emphasize using web-based unsubscribe links with unique identifiers or one-click unsubscribe options (RFC 8058). Clear unsubscribe processes, preference centers, and regular list cleaning are also crucial for compliance and maintaining a good sender reputation.
Marketer view
Email marketer from Sendinblue suggests providing a clear and easy unsubscribe process, preferably with a one-click unsubscribe option. They also emphasize the importance of immediately removing unsubscribed users from your mailing list to avoid compliance issues and maintain a good sender reputation.
28 Jan 2022 - Sendinblue
Marketer view
Email marketer from Litmus suggests that one-click unsubscribe options (List-Unsubscribe header) are ideal for user experience and compliance. These methods typically involve a web-based unsubscribe process initiated with a single click. It is recommended instead of a mailto unsubscribe.
11 Aug 2023 - Litmus
3 expert opinions
Experts agree that relying solely on the 'From' address when processing mailto: unsubscribe requests is problematic and should be avoided. Email forwarding, the use of tagged or receive-only addresses, and the potential for spoofing all contribute to the unreliability of the 'From' address. More robust unsubscribe mechanisms, such as encoding the recipient address in the unsubscribe link or utilizing web-based unsubscribe processes, are essential for accurate and effective unsubscribe management.
Expert view
Expert from Spamresource.com explains there are a number of different issues with managing your unsubscribes.
22 Jan 2023 - Spamresource.com
Expert view
Expert from Email Geeks explains that relying on the From address is not recommended because people forward mail, and unsubscribing would result in the wrong address being unsubscribed. Also, sometimes tagged addresses are receive-only. Instead, encode the recipient address in the unsubscribe link.
18 Jul 2024 - Email Geeks
3 technical articles
Technical documentation, including RFCs and the CAN-SPAM Act, suggests that relying solely on the 'From' address in mailto: unsubscribe requests is problematic. RFC 2369 highlights the challenges in verifying authenticity, recommending more robust mechanisms. RFC 8058 promotes one-click unsubscribe. The CAN-SPAM Act mandates a clear opt-out mechanism, which can include an email address, but reinforces the need for a straightforward process. Together, these documents advocate for moving beyond simple 'From' address reliance towards more secure and user-friendly unsubscribe methods.
Technical article
Documentation from RFC 8058 standardizes one-click unsubscribe functionality using the List-Unsubscribe header. It specifies that the unsubscribe process should not require additional information beyond the initial request and should be processed without forcing the user to log in or navigate multiple pages.
27 Jan 2025 - RFC Editor
Technical article
Documentation from RFC 2369 specifies that while mailto: unsubscribe links are technically valid, they present challenges in verifying the authenticity of the request. The 'From:' header can be unreliable, and it's recommended to implement more robust unsubscribe mechanisms, such as web-based forms with unique identifiers.
8 Apr 2024 - RFC Editor
Are mailto links compliant with Google and Yahoo's one-click unsubscribe requirements?
Does Google require List-Unsubscribe for one-click unsubscribe in emails?
How are Gmail and Yahoo enforcing unsubscribe requests, and what factors do they consider for compliance?
How can I avoid the unsubscribe link on Gmail when sending email campaigns?
How do email clients generate unsubscribe links, and what best practices should be followed?
How do Gmail and Yahoo's new one-click unsubscribe requirements work?
How do mailbox providers handle unsubscribe requests and multiple mailing lists from the same sender?
Should I process one-click unsubscribe requests faster than the CAN-SPAM 10-day requirement?
What are the Gmail sender requirements for one-click unsubscribe, and where should the links be placed?