Why one-click can only be checked on a real message

The unsubscribe button Gmail, Yahoo and others show beside the sender name does not depend on DNS but on the individual message: on two headers and on the DKIM signature covering them. None of that lives in a DNS record. Whether a message meets the conditions therefore only shows on a message actually sent — exactly as it arrives at the receiver.

How the headers are built and what the unsubscribe endpoint has to do is covered in the guide Set Up List-Unsubscribe. This page is about what the report checks.

What AnalyzeMy.Email checks

  • List-Unsubscribe present — and whether it contains addresses in angle brackets, as RFC 2369 requires. If the message carries several of these headers, all of them are evaluated.
  • Type of address — every address found is classified as https:, http: or mailto: and listed in the report.
  • List-Unsubscribe-Post — present and carrying the value List-Unsubscribe=One-Click per RFC 8058? Whitespace and letter case do not matter; any other value does.
  • DKIM coverage — is there a valid DKIM signature whose h= tag names both List-Unsubscribe and List-Unsubscribe-Post (RFC 8058 §4)? A signature that does not verify does not count. The signing domain is shown as d= in the result.
  • One-click — only holds when all three conditions come together: an HTTPS address, the correct Post header and the DKIM coverage.

The report also notes whether the message looks like bulk mail — recognisable by List-Unsubscribe, List-Id, Feedback-ID or Precedence: bulk or list. Unsubscribe handling does not affect the Security Score.

The findings and their weight

  • info — no List-Unsubscribe header. Exactly right for personal mail. Newsletters and marketing mail need it.
  • high — header without a valid address. The header is there but contains nothing in angle brackets. No receiver can do anything with it.
  • medium — unsubscribe address over http://. Only HTTPS counts for one-click.
  • medium — no HTTPS address. A mailto:-only unsubscribe does not satisfy Gmail and Yahoo for one-click.
  • medium — List-Unsubscribe-Post missing or with the wrong value. Without it you have a classic RFC 2369 unsubscribe, but not one-click.
  • high — DKIM does not cover the unsubscribe headers. This finding appears when the HTTPS address and the Post header are already right — it is then the last missing piece. Without it one-click is ignored, even though the headers themselves are correct.
  • pass — one-click unsubscribe correct. All three conditions are met.

The most common finding: everything there, but unsigned

Many sending systems set both headers correctly but do not sign them. DKIM signers put a fixed list of headers into h=, and the unsubscribe headers are often not on it. The result is deceptive: in the source the message looks complete, yet the button never appears.

The fix is almost always a setting in the signer or at the sending service: add List-Unsubscribe and List-Unsubscribe-Post to the list of signed headers. Order matters too — the headers have to be in place before signing. If a downstream system only adds them afterwards, no signature can cover them. After the change, send a new test message; one already sent stays as it was signed.

What the report does not see

This check reads only the headers and the signature. It does not call the unsubscribe address — neither by GET nor by POST. Whether your endpoint processes a POST request without a login and applies the unsubscribe within two days can only be tested on your own server. The same goes for the most consequential server-side mistake: an address that already unsubscribes on a plain GET and is therefore triggered by link scanners. How to avoid it is in the guide.

When a missing header is correct

Transactional mail — invoices, password messages, order confirmations — needs no List-Unsubscribe, and personal correspondence even less so. The report therefore lists the missing header only as information. It becomes mandatory once you send newsletters or marketing mail at volume: Gmail and Yahoo then require one-click unsubscribe, see the bulk sender checklist.

Test your own configuration

Send any email to hello@analyzemy.email and within seconds you get back a complete report with over 20 checks — including this one.

Analyze your email now

Last updated: · All checks at a glance