Skip to content
Inbox Distiller
All conclusions

RFC 8058 uses a consented HTTPS POST for one-click unsubscribe, separating that request from automated link fetching.

Updated · Version 2 · 1 source domain

Email scanners can fetch links before a reader acts. A distinct unsubscribe request lets receiving mail software act on consent without requiring another visit to the sender's website. For an implementation, test that fetching a link leaves subscription status unchanged and the authorized POST performs the unsubscribe.

What supports and challenges it

  • Supporting evidence
    “The mail receiver MUST NOT perform a POST on the HTTPS URI without user consent.”

    IETF RFC 8058 — One-click email unsubscribe · RFC 8058, section 3.2 (Mail Receivers), page 5

    Added
    View source versionSHA-256 d591a283fbf4cdd4553e7689110239fdc945a29682393649e35ecff4cac8c3fc
  • Context
    “software often fetches all resources in mail header fields automatically”

    IETF RFC 8058 — One-click email unsubscribe · RFC 8058, section 1 (Introduction and Motivation), page 2

    Added
    View source versionSHA-256 d591a283fbf4cdd4553e7689110239fdc945a29682393649e35ecff4cac8c3fc

What could change this conclusion

This specification does not measure reductions in spam complaints or improvements in inbox placement. It leaves when and how consent is obtained outside its scope, and warns that someone with access to a message can unsubscribe its recipient. Correct behavior still needs testing in the actual mail system.

What changed

First editorial publication, checked against RFC 8058 sections 1, 3.2 and 6. January 2017 source; newly reviewed here.

Several sites may repeat the same original source. The source count does not tell you how strong the evidence is.