RFC 8058 compliance evidence

One-Click Unsubscribe Validator

Inspect final message headers for the HTTPS one-click target, List-Unsubscribe-Post signal and DKIM coverage required by RFC 8058.

one click unsubscribe checkerlist-unsubscribe-post checkerrfc 8058 validatorgmail unsubscribe requirements
Validate one-click unsubscribe signaling in the final messageInspects header structure, HTTPS target presence and DKIM header coverage. It does not call the unsubscribe endpoint.

What this analysis does

Paste final headers rather than template HTML. Mailybox parses List-Unsubscribe, List-Unsubscribe-Post and DKIM-Signature coverage, distinguishes structural readiness from receiver-verified DKIM validity, and shows exactly which one-click evidence is missing before a bulk campaign is released.

One-click unsubscribe is a message-header workflow, not a link found anywhere in the HTML body. The validator inspects the final delivered-header structure that receivers use to decide whether one-click handling is available.

Structure reviewed against RFC 8058 and current Gmail sender guidance

Validate the final message headers

Paste headers from a representative delivered marketing or subscribed message. The validator looks for an HTTPS URI in List-Unsubscribe and the exact one-click declaration in List-Unsubscribe-Post, then checks whether the DKIM signature declares coverage for those fields.

A visible unsubscribe link in the body remains important for recipients, but it does not replace the RFC 8058 header mechanism. Conversely, header syntax alone does not prove that the endpoint accepts a valid one-click POST request.

  • Use final headers after the ESP has signed the message.
  • Keep the body unsubscribe link available and easy to find.
  • Test every sending stream that uses a different template or signer.

Separate structural readiness from receiver verification

The tool can see which fields a DKIM-Signature says it covers, but it does not recompute the cryptographic signature. Use receiver-stamped Authentication-Results to confirm that DKIM passed for the delivered message.

Provider rules depend on message type, volume and recipient expectations. Transactional mail should not be mislabeled as subscribed marketing merely to satisfy a generic checklist.

Test endpoint behavior outside the header parser

A production release should verify that the HTTPS endpoint accepts the required POST form, does not require a login or confirmation page for the one-click action and records the suppression promptly. Protect the endpoint against abuse without adding user interaction that defeats the receiver workflow.

Retest after ESP, domain or DKIM changes because a template that looks identical can be signed by a different stream with different header coverage.

Evidence supplied
The message contains an Unsubscribe link in HTML and a List-Unsubscribe HTTPS URI, but List-Unsubscribe-Post is missing.

How to read the result
The validator reports that the visible link and header URI do not by themselves create the RFC 8058 one-click mechanism.

Known limits

  • The parser does not submit a request to the unsubscribe endpoint.
  • Declared DKIM header coverage is not the same as receiver-confirmed signature validity.
  • Provider eligibility and enforcement depend on the actual sending program and traffic.

Common questions

Is a mailto unsubscribe address enough?

No for RFC 8058 one-click. The mechanism uses an HTTPS URI and the required List-Unsubscribe-Post declaration.

Does the body unsubscribe link still matter?

Yes. Keep a clear recipient-facing link even when one-click headers are present.

Can this tool confirm that the endpoint works?

No. It validates message structure; endpoint POST behavior needs a controlled production test.

Primary references