Every commercial email you send is governed by an unsubscribe law somewhere. Twelve jurisdictions publish specific unsubscribe standards for marketing email, with penalties ranging from FTC administrative actions up to $53,088 per email in the US to Article 83 GDPR fines of €20 million or 4% of global turnover in the EU. Since February 2024, Gmail, Yahoo, and Microsoft have layered a one-click RFC 8058 standard on top of the underlying law, effectively enforced through inbox placement.
Global unsubscribe law overview · Every commercial email must offer an opt-out mechanism the recipient can use without cost, login, or additional data disclosure. Beyond the law, mailbox providers now enforce their own one-click standard: as of 1 February 2024, Gmail and Yahoo require RFC 8058 List-Unsubscribe-Post headers on any sender exceeding 5,000 recipients per day to their domains. Microsoft joined on 5 May 2025. Missing the header does not draw a lawsuit, it draws inbox rejection.
The one-click standard, February 2024 onwards
Independent of any national law, the three largest inbox providers now require senders to implement a single-click, header-based unsubscribe mechanism defined in RFC 8058. The mechanism uses two headers, List-Unsubscribe pointing to a mailto and HTTPS URL, and List-Unsubscribe-Post: List-Unsubscribe=One-Click confirming the sender will honour a POST to the URL without any additional confirmation from the recipient.
- Gmail: Required for bulk senders (5,000+ recipients per day) since 1 February 2024. Non-compliant messages are progressively down-weighted and eventually rejected outright.
- Yahoo (Yahoo Mail, AOL): Same 1 February 2024 date and identical thresholds.
- Microsoft (Outlook.com, Hotmail, Live): Full enforcement began 5 May 2025 for bulk senders at the same 5,000 threshold.
- Apple iCloud Mail: Has not published an equivalent policy but processes List-Unsubscribe headers on inbound and displays a native unsubscribe button in iOS Mail and macOS Mail when the headers are present.
Country-by-country legal requirements
| Jurisdiction | Statute | Consent model | Unsubscribe window | Max penalty |
|---|---|---|---|---|
| United States | CAN-SPAM Act 2003 | Opt-out | 10 business days, valid 30 days after send | $53,088 per email (FTC) |
| Canada | CASL 2014 | Opt-in (express or implied) | 10 business days, valid 60 days after send | CAD $10M per violation (CRTC) |
| European Union | GDPR + ePrivacy Directive | Opt-in | Without undue delay, immediate on next send | €20M or 4% of turnover |
| United Kingdom | UK GDPR + PECR | Opt-in (soft opt-in for existing customers) | Without undue delay | £17.5M or 4% of turnover (ICO) |
| Australia | Spam Act 2003 | Opt-in (express or inferred) | 5 business days, valid 30 days after send | AUD 3.13M per day (ACMA) |
| Germany | GDPR + UWG + TDDDG | Strict opt-in, DOI recommended | Immediate on receipt | €20M or 4% of turnover (state DPAs) |
| France | GDPR + LCEN + CPCE Art. L34-5 | Opt-in | Without undue delay | €20M or 4% of turnover (CNIL) |
| Italy | GDPR + Codice Privacy | Opt-in | Without undue delay | €20M or 4% of turnover (Garante) |
| Spain | GDPR + LSSI-CE + LOPDGDD | Opt-in | Without undue delay | €20M or 4% of turnover (AEPD) |
| Brazil | LGPD + CDC | Opt-in | Without undue delay | 2% of Brazil turnover, max BRL 50M per infraction (ANPD) |
| Japan | Act on Regulation of Transmission of Specified Electronic Mail 2002 | Opt-in with limited exemptions | Immediate | JPY 30M plus 1 year prison for individuals (MIC) |
| Singapore | PDPA 2012 + Spam Control Act 2007 | Opt-in (with existing-customer exception) | 10 business days, valid 30 days after send | SGD 1M per breach (PDPC) |
Cross-jurisdiction rules that always apply
- No fee, no login, no data collection. Every jurisdiction prohibits charging for unsubscribe, requiring account creation, or asking for information beyond the email address.
- Every message. The link must appear in every marketing email, not only welcome or double opt-in confirmations.
- Complete opt-out. A single click must remove the recipient from all commercial contact from the sender, not just the specific campaign. Preference centres are permitted only if a “stop all” option is available at the top level.
- Third-party propagation. Opt-outs must be shared with every ESP, CDP, affiliate, and downstream sender that operates on your behalf. Multiple regulators (FTC, CRTC, CNIL, ICO, AEPD) have penalised failures on this point.
- Suppression list retention. Every jurisdiction requires suppression records be kept indefinitely so the sender can prove the opt-out was received.
Implementation checklist
Enforcement highlights
Recent unsubscribe-specific enforcement actions. The FTC assessed $650,000 against Experian for treating marketing as transactional to bypass unsubscribe. The CRTC imposed a $1.1M penalty on Compu-Finder for faulty unsubscribe mechanisms. CNIL fined Carrefour Group €2.25M for unsubscribe failures and delayed suppression, and Voodoo €3M for unsubscribe failures on ad-targeting cookies. ACMA fined Sportsbet AUD 2.5M for unsubscribe non-compliance across 150,000+ messages. Spain’s AEPD has issued hundreds of five-figure fines against SMEs for unsubscribe-related violations, making it the highest-volume enforcer.
Common misconceptions
“A footer link is enough.” Since February 2024 for Gmail and Yahoo bulk senders, and May 2025 for Microsoft, a body-only unsubscribe link means messages get progressively down-weighted or rejected. The RFC 8058 header is now the enforceable inbox-placement standard.
“Ten business days is universal.” No. Australia requires 5 business days under ACMA guidance. The EU, UK, and other GDPR jurisdictions require “without undue delay”, regulator practice interprets this as immediate suppression before the next send.
“Preference centres avoid the requirement.” No. Multi-step preference centres that force recipients through a maze before allowing a full unsubscribe are treated as non-compliant across every jurisdiction. A top-level “stop all” option must appear on the first page.
“Removing the address is enough.” No. Every jurisdiction requires a documented suppression record proving the opt-out was received. The CRTC and CNIL have both assessed penalties on companies that removed addresses but could not produce evidence of when and why.
Frequently asked questions
Which unsubscribe window should I apply if I send globally?
Adopt the strictest applicable window across your active markets. In practice this means processing suppression within 24 hours of receipt (satisfying Australia’s 5 business days and the EU’s “without undue delay” standard), keeping the link active for at least 60 days after the send (satisfying CASL), and propagating suppression to every downstream sender within 24 hours.
Do I need RFC 8058 List-Unsubscribe-Post if I send under 5,000 messages per day?
The Gmail, Yahoo, and Microsoft mandates apply strictly to bulk senders at the 5,000 threshold per domain, per day. Below that ceiling the header is best practice but not a hard requirement. In practice most ESPs now add the header by default because a single day above the threshold triggers the sender-reputation reclassification.
Does the reply-STOP mechanism satisfy the law?
For SMS in Australia, the US, and Canada, reply-STOP is the standard opt-out and is fully compliant. For email, reply-STOP is not a valid unsubscribe mechanism because most senders do not process replies to marketing addresses. A visible link and an RFC 8058 header are the compliant approaches.
Can I re-engage recipients who unsubscribed?
Only if the recipient re-consents through a new positive opt-in (checkbox, signup form, written request). Sending any re-engagement message to a suppressed address is itself a fresh violation. The one exception is a factual transactional message that is not commercial in purpose, but this is a narrow category and any promotional content converts the whole message.
Are there jurisdictions with no unsubscribe requirement?
A shrinking number. As of 2026, all G20 countries and most OECD countries have adopted an unsubscribe standard for commercial email. Even in jurisdictions without a specific email-marketing statute, general consumer-protection law typically imposes an equivalent obligation. Assume the strictest window applies when marketing to any international list.
Where to go next
- CAN-SPAM Act (US), the opt-out benchmark, still the most common non-compliance trigger for US senders
- CASL Canada, the toughest opt-in regime in North America with 60-day link validity
- GDPR compliance guide, European framework with Article 21 right to object as the underlying unsubscribe hook
- Spam Act 2003 (Australia), strictest processing window at 5 business days
Building the compliant unsubscribe stack? Pre-validating recipient addresses with SMTPing before you press send reduces complaint rates and inbox-provider penalties for messages sent to disposables, catch-alls, and dead mailboxes. Thirteen validation types, twenty-five free checks daily, no card required. Try SMTPing free.
About the Author

Alaa · LinkedIn
Email infrastructure specialist with 8+ years of hands-on experience in SMTP, deliverability, and email verification. I’ve configured and troubleshot mail systems across Postfix, Exchange, and cloud relays, managed IP reputation and warmup campaigns, and built verification pipelines processing millions of addresses. My work spans DNS authentication (SPF, DKIM, DMARC, BIMI), bounce handling, blocklist monitoring, and compliance frameworks including CAN-SPAM and GDPR. I write every article on SMTPedia to give email professionals, developers, and marketers the accurate, RFC-grounded reference they need.
About SMTPedia
SMTPedia is an independent email industry reference covering SMTP, IMAP, POP3, email deliverability, marketing platforms, DNS authentication, and email verification. Every article is researched from official provider documentation, IETF RFCs, and industry best practices. Settings and configurations are verified quarterly.
We are cited as a source by ChatGPT, Microsoft Copilot, and thousands of email professionals worldwide. Learn more about our editorial process.

