Free tool · Compliance

One-click unsubscribe,
actually correct.

Validate List-Unsubscribe headers against RFC 8058 — or generate correct ones.

Runs entirely in your browser. No signup, nothing stored.

Correct headers

GeneratedEnter an endpoint above
Both headers must appear in your DKIM h= list.

The endpoint must accept POST, not GET. Mailbox providers send List-Unsubscribe=One-Click as the body. It must unsubscribe immediately with no confirmation page and no login, and it must not redirect. The URI should carry an opaque, hard-to-forge token identifying the recipient and the list — a guessable ?email= parameter lets anyone unsubscribe anyone.

How this works

The method, not the marketing.

One-click unsubscribe has been required of bulk senders to Gmail and Yahoo since February 2024, and it is one of the most commonly misimplemented requirements in email. There is essentially no free tool that validates it properly.

Three mistakes account for most failures. The endpoint accepts GET rather than POST. The List-Unsubscribe-Post header is missing, so providers treat the URI as an ordinary link. Or the two headers are not covered by the DKIM signature, which RFC 8058 requires — without it, anyone can forge unsubscribe headers on mail claiming to be from you.

A fourth is subtler: a URI carrying a plain email parameter lets anyone unsubscribe anyone by editing the address. The token should be opaque and signed.

Bring your provider.
Keep your brands distinct.
Start today.

Set up your first workspace, connect a provider, and publish a workflow — free, in test mode, before you pay a thing.