2026 Email Exit Gap Index: Evidence Protocol
This is the evidence protocol for Flick’s 2026 Email Exit Gap Index, not a results report. Federal law gives a sender 10 business days to honor an opt-out, while Gmail and Yahoo require covered bulk senders to process it within two days. The index will compare those rules with real mailbox observations; until those observations exist, every sender remains ungraded and no compliance-rate claim is published.
Verification note: This is a documentary research protocol checked against current sources on August 3, 2026. It contains no observations or results; those require the stated collection protocol. Interfaces can vary by account, region, rollout, and app version.
One definition before we start. Unsubscribe compliance is the measurable gap between a sender receiving your opt-out request and that sender actually stopping the email. Everything in this report — statutes, mailbox-provider mandates, header standards, grades — is an attempt to shrink or expose that gap.
This protocol is intentionally excluded from search indexing until the first evidence-backed results edition exists. External rules link to primary sources; future sender observations require preserved headers, request timestamps, and follow-up mailbox evidence. The full governance standard lives in our research methodology. The house rule is simple: ungraded, not guessed.
What does the law require after you click unsubscribe?
The CAN-SPAM Act sets the floor for every commercial email sent to US recipients, regardless of sender size. The opt-out obligations are specific:
| Requirement | Rule | Source |
|---|---|---|
| Honor the opt-out | Within 10 business days of receipt | 15 U.S.C. § 7704 |
| Keep the mechanism alive | The opt-out path must work for at least 30 days after the message is sent | 15 U.S.C. § 7704 |
| No fee | A sender may not "require that any recipient pay any fee" to opt out | 16 CFR § 316.5 |
| No interrogation | A sender may not demand "any information other than the recipient's electronic mail address and opt-out preferences" | 16 CFR § 316.5 |
| One page, maximum | Opting out may require nothing beyond "sending a reply electronic mail message or visiting a single Internet Web page" | 16 CFR § 316.5 |
| Transfer restriction | After you opt out, a sender generally may not sell, lease, exchange, transfer, or release the address; the statute permits transfer to an entity engaged to help the sender comply | 15 U.S.C. § 7704 |
Civil-penalty ceilings are adjusted over time, so this protocol does not freeze a dollar figure into its method. Before citing a maximum, consult the current FTC penalty-adjustment table in 16 CFR § 1.98.
Read that table again and notice what the law does not require. It does not mandate RFC 8058 one-click headers. But “one page” is not permission for a login maze: the rule also bars fees, identifying information beyond the email address and opt-out preferences, and steps beyond a reply message or one page. A mandatory login that adds credentials or another step is difficult to reconcile with the text; a live compliance decision belongs with counsel.
What did the Gmail and Yahoo one-click mandate change in 2024?
The mailbox providers added separate delivery rules. On October 3, 2023, Google announced that senders of more than 5,000 messages a day to personal Gmail accounts would need RFC 8058 one-click unsubscribe for covered marketing/subscribed mail and to process those requests within two days, with enforcement beginning in 2024. Yahoo does not publish that numeric threshold: it requires bulk senders to provide a functioning List-Unsubscribe header, calls RFC 8058 POST highly recommended, accepts mailto:, and requires requests to be honored within two days. Both publish a 0.3% complaint-rate ceiling, though their denominators and enforcement are provider-specific. Microsoft's high-volume Outlook announcement focuses on SPF, DKIM, and DMARC and recommends a visible unsubscribe path; it is not evidence of a matching RFC 8058 mandate.
That produced a strange two-tier world, which is the defining feature of unsubscribe compliance in 2026:
| CAN-SPAM (law) | Gmail | Yahoo | |
|---|---|---|---|
| Who it covers | Covered U.S. commercial messages | Covered marketing/subscribed mail from senders of more than 5,000 messages a day to personal Gmail accounts | Bulk senders; no numeric threshold published |
| Deadline to honor opt-out | 10 business days | Two days | Two days |
| Header requirement | No RFC 8058 mandate | HTTPS RFC 8058 one-click for covered mail | Functioning List-Unsubscribe; POST highly recommended, mailto: accepted |
| Possible consequence | Fact-specific enforcement and remedies | Provider-specific filtering, deferral, or rejection | Mail may be routed to spam or rejected |
For covered bulk marketing mail, the provider deadlines are faster and their header requirements are more technical than CAN-SPAM. The mechanisms differ: Google requires RFC 8058, while Yahoo's current page accepts mailto: and highly recommends POST. Neither provider promises an immediate, identical delivery outcome for every defect.
Why does one-click unsubscribe (RFC 8058) matter so much?
RFC 8058, "Signaling One-Click Functionality for List Email Headers," published in January 2017, is the technical spine of the whole mandate. It defines the List-Unsubscribe-Post: List-Unsubscribe=One-Click header: when present, a mail client can unsubscribe you by sending a single HTTPS POST to the sender's unsubscribe URI — no browser, no confirmation page, no "are you sure." The spec is blunt about why: "the unsubscription process has to work without manual intervention, and in particular without requiring that software attempt to interpret the contents of a confirmation page."
This matters because it splits every sender's unsubscribe into two separate paths that can behave differently:
- The machine path. The RFC 8058 POST. It sends a deterministic request without a sender page; it does not prove immediate suppression or that later mail stops. This is the route Gmail can surface and the header mechanism Flick parses.
- The human path. The visible "unsubscribe" link in the footer. This is where the preference-center mazes, the login walls, and the "processing your request" pages live — the territory 16 CFR § 316.5's single-page rule was written for.
A sender can be a model citizen on one path and a maze on the other. Any honest compliance measurement has to test both. For the full mechanics of the header standard, see our explainer on one-click unsubscribe.
Do companies actually honor unsubscribe requests?
Here is the measurement gap this protocol addresses: we did not find a maintained public, sender-by-sender unsubscribe compliance dataset during the July 20, 2026 source review.
Every enforcement signal in the ecosystem is either aggregate or private. The FTC litigates individual cases but publishes no ongoing compliance census. Gmail and Yahoo enforce their 0.3% spam-rate thresholds sender by sender — but that data lives in private postmaster dashboards, and a spam rate measures complaints, not whether an opt-out was honored. Deliverability vendors audit their own clients under NDA. The result is an accountability vacuum: a recipient who suspects a sender ignored their unsubscribe has no public record to check, and a sender who honors every request within hours gets no public credit for it.
What we do know from published behavioral research is indirect: how often people unsubscribe, why, and how badly broken flows erode trust — we keep a maintained roundup in our email unsubscribe statistics. And we know the individual-level answer to "is it safe, does it work" is more nuanced than folklore suggests — covered in does unsubscribing actually work?. But neither of those answers the per-sender question. "Unsubscribe not working" remains one of the most common complaints about commercial email precisely because no scoreboard exists on which a sender could be caught.
That absence is the exit gap: the space between what senders are required to do when you leave and what they actually do. It is measurable. Someone just has to measure it in public.
How does the Exit Gap Index measure unsubscribe compliance?
The Exit Gap Index is our instrument for exactly that, and this section is its methodology disclosure. We are naming ourselves as the measurer on purpose — a report that hides its instrument is not one worth citing.
What it is. A public 150-sender worklist and a protocol designed to produce A–F unsubscribe-honor grades only after the evidence gate is met. The worklist is published at flicked.email/graded; as of August 3, 2026, it contains four capability-only observations and zero honor grades. Capability is not honor, and there is no per-sender result to look up yet.
What it measures. Each sender is graded on the machine path against the human path — the two routes described above. Does the sender publish RFC 8058 headers at all? Does the one-click POST actually stop the mail? What does a human face on the visible link: one page, or a maze? And does the mail actually stop within the clocks the law and the mailbox providers set?
Where it stands today. The baseline worklist covers 150 senders across categories — devtools, entertainment, fashion, news, and more — and, as of August 3, 2026, no sender carries a published exit grade. The four current observations establish technical capability only. No founder burner-mailbox observation cycle has run. A future honor grade requires at least three probes across at least 48 hours, with raw headers, request logs, screenshots, timestamps, and follow-up mailbox evidence preserved. We will publish grades as they clear that bar rather than infer letters from reputation.
Limitations, stated plainly. The worklist is our selection, not a census of commercial email. A grade is a point-in-time measurement of an unsubscribe flow, and senders change their flows — so grades can and should change on re-measurement. And Flick is a commercial product; the index is credible only as long as its method is inspectable, which is why the grading rule is public: we never guess a letter. Ungraded, not guessed.
Future editions of this report will open with the grade distribution. This one opens with the honest version: the scoreboard is built, the worklist is public, and the first letters land as they are measured.
What should a compliant sender do in 2026?
The legal and provider controls can be reviewed together, but passing this table is not a guarantee of compliance or delivery:
| Do this | Because |
|---|---|
Ship RFC 8058 List-Unsubscribe and List-Unsubscribe-Post on marketing mail covered by Google's rule |
Required by Google; defined by RFC 8058. Yahoo requires List-Unsubscribe but accepts mailto: and highly recommends POST |
| Honor opt-outs within two days when the applicable Gmail/Yahoo rule covers the message; always meet CAN-SPAM's 10-business-day deadline | Provider and legal clocks have different scopes |
| Make the visible exit free and direct: no identifying information beyond email and preferences, and no step beyond a reply or single page | 16 CFR § 316.5 |
| Keep the mechanism working for at least 30 days post-send | 15 U.S.C. § 7704 |
| Do not transfer an opted-out address except to an entity engaged to help comply | 15 U.S.C. § 7704; consult the current penalty schedule |
| Watch your spam rate against the 0.3% ceiling | A broken unsubscribe converts quiet leavers into complainers |
The last row is an operational risk signal, not a causal guarantee. A broken exit may prompt some recipients to report spam, but complaint aggregation, denominator, and delivery effects are provider-specific. Fast, tested suppression reduces that avoidable path.
Turn the next inbox decision into a finite deck.
Open Flick with an account you control, or practice first with fabricated sample mail. Provider results remain limited to the accounts, messages, and actions Flick actually confirms.
Open Flick with your inbox →FAQ
How long does a company legally have to honor an unsubscribe request?
Under CAN-SPAM, a sender must stop covered commercial mail within 10 business days of receiving your opt-out. Separately, Gmail and Yahoo require covered senders to process subscription opt-outs within two days. Those clocks have different scopes, and neither source establishes which deadline governs every message from a particular sender.
Is one-click unsubscribe legally required?
CAN-SPAM does not mandate RFC 8058; it requires a working opt-out honored within its deadline. Google requires RFC 8058 for covered marketing/subscribed mail from senders of more than 5,000 messages a day to personal Gmail accounts. Yahoo publishes no matching numeric threshold and currently accepts a functioning mailto: List-Unsubscribe method while highly recommending RFC 8058 POST (Yahoo). This protocol does not estimate what share of consumer mail those rules cover.
Can a company make me log in or fill out a form to unsubscribe?
No. Under 16 CFR § 316.5, a sender may not require a fee, may not demand any information beyond your email address and opt-out preferences, and may not require any step beyond a reply email or visiting a single web page. A mandatory login or survey before the opt-out is honored sits outside that rule.
What is the penalty for ignoring an unsubscribe request?
CAN-SPAM violations can trigger civil penalties, and the maximum is inflation-adjusted; consult the current 16 CFR § 1.98 schedule rather than relying on a copied number. The faster operational consequence is deliverability: mailbox providers monitor complaint rates, with Google telling bulk senders to stay below 0.3%.
What is the exit gap?
The exit gap is the distance between what a sender is required to do when you unsubscribe and what it actually does. It is the thing unsubscribe compliance rules exist to close and the thing this protocol is designed to measure per sender. No sender has a published Flick honor grade yet; the first letter will appear only after the repeated-probe evidence gate is met.