2026 Email Exit Gap Index: Evidence Protocol
This is the evidence protocol for Flick’s 2026 Email Exit Gap Index, not a results report. Federal law gives a sender 10 business days to honor an opt-out, while Gmail and Yahoo require covered bulk senders to process it within two days. The index will compare those rules with real mailbox observations; until those observations exist, every sender remains ungraded and no compliance-rate claim is published.
One definition before we start. Unsubscribe compliance is the measurable gap between a sender receiving your opt-out request and that sender actually stopping the email. Everything in this report — statutes, mailbox-provider mandates, header standards, grades — is an attempt to shrink or expose that gap.
This protocol is intentionally excluded from search indexing until the first evidence-backed results edition exists. External rules link to primary sources; future sender observations require preserved headers, request timestamps, and follow-up mailbox evidence. The full governance standard lives in our research methodology. The house rule is simple: ungraded, not guessed.
What does the law require after you click unsubscribe?
The CAN-SPAM Act sets the floor for every commercial email sent to US recipients, regardless of sender size. The opt-out obligations are specific:
| Requirement | Rule | Source |
|---|---|---|
| Honor the opt-out | Within 10 business days of receipt | 15 U.S.C. § 7704 |
| Keep the mechanism alive | The opt-out path must work for at least 30 days after the message is sent | 15 U.S.C. § 7704 |
| No fee | A sender may not "require that any recipient pay any fee" to opt out | 16 CFR § 316.5 |
| No interrogation | A sender may not demand "any information other than the recipient's electronic mail address and opt-out preferences" | 16 CFR § 316.5 |
| One page, maximum | Opting out may require nothing beyond "sending a reply electronic mail message or visiting a single Internet Web page" | 16 CFR § 316.5 |
| No reselling the address | After you opt out, a sender may not "sell, lease, exchange, or otherwise transfer or release" your address | 15 U.S.C. § 7704 |
Civil-penalty ceilings are adjusted over time, so this protocol does not freeze a dollar figure into its method. Before citing a maximum, consult the current FTC penalty-adjustment table in 16 CFR § 1.98.
Read that table again and notice what the law does not require. It does not require one-click unsubscribe. It does not require the machine-readable headers that let your mail client unsubscribe for you. It tolerates a login wall in spirit-violating gray zones, as long as the wall technically counts as "a single Internet Web page." The statutory floor is low, and it was set before smartphones existed.
What did the Gmail and Yahoo one-click mandate change in 2024?
The mailbox providers raised the floor themselves. On October 3, 2023, Google announced that senders of more than 5,000 messages per day to Gmail accounts would have to "give Gmail recipients the ability to unsubscribe from commercial email in one click" and "process unsubscription requests within two days," with enforcement starting February 2024. Yahoo shipped matching requirements on the same schedule: a functioning one-click unsubscribe per RFC 8058, unsubscribes honored within 2 days, and spam complaint rates kept below 0.3%. Google's sender guidelines hold bulk senders to the same 0.3% spam-rate ceiling. Microsoft has since published its own requirements for high-volume Outlook senders, as of July 2026 completing the sweep of major consumer mailbox providers.
That produced a strange two-tier world, which is the defining feature of unsubscribe compliance in 2026:
| CAN-SPAM (law) | Gmail/Yahoo mandate (market) | |
|---|---|---|
| Who it covers | Every commercial sender | Bulk senders: 5,000+ messages/day |
| Deadline to honor opt-out | 10 business days | 2 days |
| One-click required? | No | Yes — RFC 8058 headers |
| Enforced by | FTC; consult the current inflation-adjusted schedule | Deliverability controls and spam-rate thresholds, including 0.3% |
| Enforcement style | Occasional, litigated | Continuous, automated |
The market standard is now stricter than the statutory one on every axis that matters to an inbox owner. The law asks for ten business days and a working link. The mailbox providers ask for two days and a machine-readable header. In practice, the second regime is the one senders fear, because its enforcement is not a lawsuit that may never come — it is a spam folder that arrives immediately.
Why does one-click unsubscribe (RFC 8058) matter so much?
RFC 8058, "Signaling One-Click Functionality for List Email Headers," published in January 2017, is the technical spine of the whole mandate. It defines the List-Unsubscribe-Post: List-Unsubscribe=One-Click header: when present, a mail client can unsubscribe you by sending a single HTTPS POST to the sender's unsubscribe URI — no browser, no confirmation page, no "are you sure." The spec is blunt about why: "the unsubscription process has to work without manual intervention, and in particular without requiring that software attempt to interpret the contents of a confirmation page."
This matters because it splits every sender's unsubscribe into two separate paths that can behave differently:
- The machine path. The RFC 8058 POST. Silent, instant, no human involved. This is what Gmail's native unsubscribe button uses, and it is what we parse at Flick — we build List-Unsubscribe parsing for a living, and one-swipe unsubscribe in our client rides these exact headers.
- The human path. The visible "unsubscribe" link in the footer. This is where the preference-center mazes, the login walls, and the "processing your request" pages live — the territory 16 CFR § 316.5's single-page rule was written for.
A sender can be a model citizen on one path and a maze on the other. Any honest compliance measurement has to test both. For the full mechanics of the header standard, see our explainer on one-click unsubscribe.
Do companies actually honor unsubscribe requests?
Here is the measurement gap this protocol addresses: we did not find a maintained public, sender-by-sender unsubscribe compliance dataset during the July 20, 2026 source review.
Every enforcement signal in the ecosystem is either aggregate or private. The FTC litigates individual cases but publishes no ongoing compliance census. Gmail and Yahoo enforce their 0.3% spam-rate thresholds sender by sender — but that data lives in private postmaster dashboards, and a spam rate measures complaints, not whether an opt-out was honored. Deliverability vendors audit their own clients under NDA. The result is an accountability vacuum: a recipient who suspects a sender ignored their unsubscribe has no public record to check, and a sender who honors every request within hours gets no public credit for it.
What we do know from published behavioral research is indirect: how often people unsubscribe, why, and how badly broken flows erode trust — we keep a maintained roundup in our email unsubscribe statistics. And we know the individual-level answer to "is it safe, does it work" is more nuanced than folklore suggests — covered in does unsubscribing actually work?. But neither of those answers the per-sender question. "Unsubscribe not working" remains one of the most common complaints about commercial email precisely because no scoreboard exists on which a sender could be caught.
That absence is the exit gap: the space between what senders are required to do when you leave and what they actually do. It is measurable. Someone just has to measure it in public.
How does the Exit Gap Index measure unsubscribe compliance?
The Exit Gap Index is our instrument for exactly that, and this section is its methodology disclosure. We are naming ourselves as the measurer on purpose — a report that hides its instrument is not one worth citing.
What it is. A crawler-seeded public index that grades real senders A–F on whether they honor unsubscribes, published at flicked.email/graded, with a per-sender page for each graded domain at flicked.email/s/<domain>.
What it measures. Each sender is graded on the machine path against the human path — the two routes described above. Does the sender publish RFC 8058 headers at all? Does the one-click POST actually stop the mail? What does a human face on the visible link: one page, or a maze? And does the mail actually stop within the clocks the law and the mailbox providers set?
Where it stands today. The baseline worklist covers 150 senders across categories — devtools, entertainment, fashion, news, and more — and, as of this July 2026 baseline edition, no sender carries a published exit grade yet; every grade reads "—" until the index has measured that sender. We publish grades as they are measured rather than launching with estimates, because the alternative — inferring a letter from a sender's reputation — would make this report exactly the kind of unsourced scoreboard it exists to replace.
Limitations, stated plainly. The worklist is our selection, not a census of commercial email. A grade is a point-in-time measurement of an unsubscribe flow, and senders change their flows — so grades can and should change on re-measurement. And Flick is a commercial product; the index is credible only as long as its method is inspectable, which is why the grading rule is public: we never guess a letter. Ungraded, not guessed.
Future editions of this report will open with the grade distribution. This one opens with the honest version: the scoreboard is built, the worklist is public, and the first letters land as they are measured.
What should a compliant sender do in 2026?
The two regimes compose into one checklist. A sender who meets the stricter line of each requirement is safe under both:
| Do this | Because |
|---|---|
Ship List-Unsubscribe and List-Unsubscribe-Post headers on all marketing mail |
Required for bulk senders by Google and Yahoo; defined by RFC 8058 |
| Honor every opt-out within 2 days, not 10 business days | The mailbox-provider clock is the binding one |
| Make the visible link a single page, no login, no fee, no forms | 16 CFR § 316.5 |
| Keep the mechanism working for at least 30 days post-send | 15 U.S.C. § 7704 |
| Never transfer an opted-out address | 15 U.S.C. § 7704; consult the current penalty schedule |
| Watch your spam rate against the 0.3% ceiling | A broken unsubscribe converts quiet leavers into complainers |
The last row is the strategic one. When the unsubscribe path fails, recipients do not give up — they hit "report spam" instead, and that feeds the one metric that gets a bulk sender's entire mail stream throttled. Honoring unsubscribes quickly is not a courtesy. In 2026 it is self-preservation.
Stop reading your inbox. Start flicking it.
Flick turns every inbox into a finite swipe deck — archive, "no reply needed," or AI-draft → approve, one card at a time. Inbox flicked.
Try the live demo — no signup →FAQ
How long does a company legally have to honor an unsubscribe request?
Under CAN-SPAM, a sender must stop mailing you within 10 business days of receiving your opt-out. For bulk senders, Gmail and Yahoo impose a stricter de facto standard of two days. The legal clock and the market clock disagree; the market clock is the one most large senders actually run on.
Is one-click unsubscribe legally required?
No US law requires one-click unsubscribe — CAN-SPAM only requires a working opt-out honored within its deadline. One-click per RFC 8058 is mandated by Gmail and Yahoo for senders above 5,000 messages per day, enforced through deliverability rather than courts. In practice that mandate covers most of the commercial email in a consumer inbox.
Can a company make me log in or fill out a form to unsubscribe?
No. Under 16 CFR § 316.5, a sender may not require a fee, may not demand any information beyond your email address and opt-out preferences, and may not require any step beyond a reply email or visiting a single web page. A mandatory login or survey before the opt-out is honored sits outside that rule.
What is the penalty for ignoring an unsubscribe request?
CAN-SPAM violations can trigger civil penalties, and the maximum is inflation-adjusted; consult the current 16 CFR § 1.98 schedule rather than relying on a copied number. The faster operational consequence is deliverability: mailbox providers monitor complaint rates, with Google telling bulk senders to stay below 0.3%.
What is the exit gap?
The exit gap is the distance between what a sender is required to do when you unsubscribe and what it actually does. It is the thing unsubscribe compliance rules exist to close and the thing no public dataset currently measures per sender — which is why we are grading it, one measured letter at a time.