Why one-click can only be checked on a real message
The unsubscribe button Gmail, Yahoo and others show beside the sender name does not depend on DNS but on the individual message: on two headers and on the DKIM signature covering them. None of that lives in a DNS record. Whether a message meets the conditions therefore only shows on a message actually sent — exactly as it arrives at the receiver.
How the headers are built and what the unsubscribe endpoint has to do is covered in the guide Set Up List-Unsubscribe. This page is about what the report checks.
What AnalyzeMy.Email checks
- List-Unsubscribe present — and whether it contains addresses in angle brackets, as RFC 2369 requires. If the message carries several of these headers, all of them are evaluated.
- Type of address — every address found is classified as
https:,http:ormailto:and listed in the report. - List-Unsubscribe-Post — present and carrying the value
List-Unsubscribe=One-Clickper RFC 8058? Whitespace and letter case do not matter; any other value does. - DKIM coverage — is there a valid DKIM signature whose
h=tag names bothList-UnsubscribeandList-Unsubscribe-Post(RFC 8058 §4)? A signature that does not verify does not count. The signing domain is shown asd=in the result. - One-click — only holds when all three conditions come together: an HTTPS address, the correct Post header and the DKIM coverage.
The report also notes whether the message looks like bulk mail — recognisable by List-Unsubscribe, List-Id, Feedback-ID or Precedence: bulk or list. Unsubscribe handling does not affect the Security Score.
The findings and their weight
- info — no List-Unsubscribe header. Exactly right for personal mail. Newsletters and marketing mail need it.
- high — header without a valid address. The header is there but contains nothing in angle brackets. No receiver can do anything with it.
- medium — unsubscribe address over http://. Only HTTPS counts for one-click.
- medium — no HTTPS address. A
mailto:-only unsubscribe does not satisfy Gmail and Yahoo for one-click. - medium — List-Unsubscribe-Post missing or with the wrong value. Without it you have a classic RFC 2369 unsubscribe, but not one-click.
- high — DKIM does not cover the unsubscribe headers. This finding appears when the HTTPS address and the Post header are already right — it is then the last missing piece. Without it one-click is ignored, even though the headers themselves are correct.
- pass — one-click unsubscribe correct. All three conditions are met.
The most common finding: everything there, but unsigned
Many sending systems set both headers correctly but do not sign them. DKIM signers put a fixed list of headers into h=, and the unsubscribe headers are often not on it. The result is deceptive: in the source the message looks complete, yet the button never appears.
The fix is almost always a setting in the signer or at the sending service: add List-Unsubscribe and List-Unsubscribe-Post to the list of signed headers. Order matters too — the headers have to be in place before signing. If a downstream system only adds them afterwards, no signature can cover them. After the change, send a new test message; one already sent stays as it was signed.
What the report does not see
This check reads only the headers and the signature. It does not call the unsubscribe address — neither by GET nor by POST. Whether your endpoint processes a POST request without a login and applies the unsubscribe within two days can only be tested on your own server. The same goes for the most consequential server-side mistake: an address that already unsubscribes on a plain GET and is therefore triggered by link scanners. How to avoid it is in the guide.
When a missing header is correct
Transactional mail — invoices, password messages, order confirmations — needs no List-Unsubscribe, and personal correspondence even less so. The report therefore lists the missing header only as information. It becomes mandatory once you send newsletters or marketing mail at volume: Gmail and Yahoo then require one-click unsubscribe, see the bulk sender checklist.