September 30, 2026 · LegalBriefsUSA
Do I Need an Unsubscribe Link in a Cold Email? Not Under CAN-SPAM, and Yes Under 3 Other Rules
No, not under US law, and yes under 3 other rules. CAN-SPAM requires a clear opt-out mechanism rather than a link, and the FTC accepts a return email address or one easy internet-based way to say stop.
Four separate rule sets decide this question and they do not agree with each other. US federal law, the Gmail and Yahoo bulk sender requirements, Canada’s CASL, and the European ePrivacy Directive each set a different bar. Three of the four are satisfied by a line of plain text. One of them prohibits sending at all without a working route to opt out, with no business-to-business exemption available anywhere in the European Union. This post sits in our outbound compliance hub and works through all four, then covers what the opt-out has to do once someone uses it. Every requirement below is quoted from the regulator, the mailbox provider or the RFC, and every source is linked and dated at the end.
Does CAN-SPAM require an unsubscribe link?
No. It requires an opt-out mechanism, and the FTC names two acceptable forms. The compliance guide asks for a “clear and conspicuous explanation of how the recipient can opt out” and then says to “give a return email address or another easy Internet-based way to allow people to communicate their choice to you.” A return email address is a reply. If the recipient can hit reply and type the word stop, the requirement is met.
Three constraints come attached, and they are where programs actually fail. You have 10 business days to honor the request. The mechanism has to keep working for at least 30 days after the message went out. And you cannot charge a fee, cannot require any personally identifying information beyond an email address, and cannot make the recipient take any step other than sending a reply email or visiting a single page. A preference center behind a login breaks the third one. So does a form that asks why they are leaving before it will accept the answer.
The FTC is also explicit that none of this is consumer-only: “The law makes no exception for business-to-business email.” Each separate violating email carries penalties of up to $53,088. The practical exposure for a B2B sender is smaller than that figure implies, and the mechanics of who counts as the sender are covered in whether cold email is legal in the US. The opt-out rule itself is not the part anyone argues about.
Do Gmail and Yahoo require one-click unsubscribe on cold email?
Only above 5,000 messages a day to personal Gmail accounts, and Google states the rule does not reach Google Workspace inboxes. Google defines a bulk sender as “any email sender that sends close to 5,000 messages or more to personal Gmail accounts within a 24-hour period,” and its sender guidelines FAQ says one-click unsubscribe “is required only for marketing and promotional messages,” excluding transactional mail and one-to-one communications.
That distinction matters more in B2B than anywhere else, because a B2B prospect list is mostly Workspace and Microsoft 365 addresses at company domains, not gmail.com addresses. A program spread across a dozen sending inboxes at a few hundred sends a day is not a bulk sender under Google’s own definition, and most of its volume is not going to personal Gmail at all. The one-click requirement, read literally, rarely binds it.
What binds it always is the complaint rate. Google asks senders to keep spam rates in Postmaster Tools below 0.30% and recommends staying under 0.10%. Yahoo sets the same 0.3% ceiling, tells senders to “honor unsubscribes within 2 days,” and asks for both a functioning List-Unsubscribe header and a “clearly visible unsubscribe link in the email body.” At 0.30%, three complaints in a thousand sends is the line. That is the number an opt-out route exists to protect.
If you do implement the header version, the standard is RFC 8058. The List-Unsubscribe header must contain one HTTPS URI, the List-Unsubscribe-Post header must contain the single key and value pair List-Unsubscribe=One-Click, and the mailbox provider unsubscribes by sending an HTTPS POST to that URI. It is a two-header change plus an endpoint, not a redesign.
What do Canada and Europe require?
Both make an opt-out route mandatory in every message, and Europe makes it mandatory in the first one. CASL requires an unsubscribe mechanism in every commercial electronic message. The link has to stay valid for at least 60 days after the message is sent, and requests must be processed “without delay, and no later than 10 business days after receiving it.” The maximum administrative monetary penalty per violation is $1 million for an individual and $10 million for a business.
Europe is stricter in a way most cold email advice never mentions. Article 13(4) of the ePrivacy Directive prohibits, in any event, sending marketing email “without a valid address to which the recipient may send a request that such communications cease.” That clause carries no business-to-business carve-out in any member state, which is the point: the country-by-country disagreement covered in whether cold email is legal under GDPR is about consent, not about the opt-out. On the opt-out, the 27 implementations agree.
GDPR then sets the timing. Article 21(2) gives the recipient the right to object at any time to processing for direct marketing. Article 21(4) says that right must be surfaced “at the latest at the time of the first communication with the data subject” and “presented clearly and separately from any other information.” Read those two together and a European cold email cannot hold the opt-out back for the follow-up. It goes in message one, visibly, not folded into a signature block.
| Rule set | Is an opt-out required? | Does it have to be a link? | Deadline to honor | How long it must work |
|---|---|---|---|---|
| CAN-SPAM, United States | Yes, in every commercial message, B2B included | No. A return email address is accepted | 10 business days | At least 30 days after sending |
| Gmail bulk sender requirements | Only at close to 5,000 messages a day or more to personal Gmail accounts | Yes at that volume: one-click plus a visible link in the body | Google recommends 48 hours | Not specified |
| Yahoo sender requirements | Yes for marketing and subscribed mail to Yahoo accounts | Yes: working List-Unsubscribe header plus a visible link | 2 days | Not specified |
| CASL, Canada | Yes, in every commercial electronic message | A mechanism is required; CRTC guidance describes a link | Without delay, no later than 10 business days | At least 60 days after sending |
| ePrivacy Article 13(4), European Union | Yes. Sending without one is prohibited outright, with no B2B exemption | No. A valid address to send a cease request is the stated minimum | GDPR Article 21(3): stop, with no balancing test | Not specified; the address has to work |
Does an unsubscribe link hurt cold email deliverability?
Nobody has published a controlled test either way, and the claim circulates on all sides without one. What is published is the metric the mailbox providers grade you on, and it points in the other direction. Gmail wants spam rates under 0.30% and ideally under 0.10%. Yahoo wants under 0.3%. Those are complaint rates, and a complaint is what a recipient files when they want the mail to stop and cannot see a faster way to make that happen. An opt-out route is the cheapest available substitute for the spam button.
The version of the deliverability argument that does hold up is narrower than the version that gets repeated. A clickable unsubscribe on a young sending domain adds a link and a redirect to a message whose reputation profile is still being established, which is a reason to prefer a plain-text reply instruction during warmup and stops mattering once the domain is established. It is not a reason to ship a sequence with no opt-out route at all. Inbox failure is almost always authentication and reputation rather than message content, which is the subject of why cold emails go to spam.
There is also a contract layer that sits above all of this. Sending platforms impose their own rule regardless of what the statute says. lemlist’s published sending policy requires that “all campaigns must include a clear and concise link for recipients to easily opt-out of receiving future communication,” checked 30 September 2026. If you run on a platform with that term, the legal analysis is academic: the platform’s terms are the binding constraint, and breaching them risks the account rather than a fine.
What does the opt-out actually have to do once someone uses it?
Suppress that address across every sending domain and every inbox in the program, permanently, and keep the endpoint alive after the campaign ends. This is the part that gets built wrong, and it fails in a way the recipient notices: a second email from a different domain you also own, two weeks after they said stop.
Four specifics follow from the rules above. Suppression has to be global rather than per sequence, because the recipient objected to you and not to one campaign. The endpoint has to outlive the send, because CAN-SPAM requires 30 days and CASL requires 60, and a link that dies when a campaign is archived fails both. The opt-out cannot demand anything, because CAN-SPAM caps the recipient’s effort at a reply or a single page with no fee and no personal information beyond the email address. And a reply-based opt-out has to be monitored by something, because an unread inbox is not a mechanism. The most common real-world failure in a reply-only setup is that nobody was reading the mailbox the instruction pointed at.
| Opt-out format | Satisfies CAN-SPAM | Satisfies ePrivacy 13(4) | Satisfies Gmail and Yahoo bulk rules | Best use |
|---|---|---|---|---|
| Reply instruction in plain text, for example “reply stop and I will close the file” | Yes | Yes | No | Low-volume B2B sends from company domains, and domain warmup |
| Plain-text opt-out plus a mailto link that files the suppression automatically | Yes | Yes | No | The practical default for a distributed B2B program |
| Visible unsubscribe link in the body | Yes | Yes | Partly; the header is also required | Any sequence touching consumer mailboxes |
| RFC 8058 one-click headers plus a visible link | Yes | Yes | Yes | Mandatory above roughly 5,000 daily sends to personal Gmail accounts |
So what should a B2B cold email actually say?
One line, in the body, above or immediately below the signature, in the same typeface as the rest of the message. Something the recipient can act on in a single step, that names you, and that does not read as a marketing footer. A reply instruction plus a physical or postal address covers CAN-SPAM, covers ePrivacy Article 13(4), and covers the GDPR Article 21(4) timing requirement if it is in the first message and set apart from the pitch rather than buried in it.
Three things not to do. Do not hide it behind a single grey pixel of 8-point text, because “clear and conspicuous” is the actual statutory language and a regulator gets to decide whether you cleared it. Do not route it to an unmonitored mailbox. And do not use the opt-out as a last engagement attempt, because a page that asks the recipient to reconsider before it will accept the request is the extra step CAN-SPAM specifically prohibits.
If any part of the list sits in Canada, build for the 60-day endpoint, since a campaign-scoped link is the standard way that rule gets broken. If any part sits in the European Union, put the opt-out in message one, visually separate from the offer.
How LeadButton handles this
Every sequence ships with a one-step opt-out in the first message, written as plain text rather than as a marketing footer, and the address behind it is monitored rather than decorative. Suppression is global across every sending domain and every inbox in the program and it is permanent, so a prospect who opts out of one campaign is out of all of them. Lists are segmented by recipient country before launch, which is what makes the European timing requirement and the Canadian 60-day rule buildable instead of retrofitted. Sequences that touch consumer mailboxes in volume get the RFC 8058 headers as well.
Launch is $1,500 a month for managed email outreach, Growth is $3,500 a month for email plus LinkedIn, and Scale is custom. Nothing in the opt-out architecture changes the price at either tier; it is the same build at both. Pricing is on the LeadButton pricing page. We are not lawyers and this is not legal advice. What we can tell you is exactly which of the controls above run as standard and which stay with you.
Sources
- FTC, CAN-SPAM Act: A Compliance Guide for Business, checked 30 September 2026. Source for the “clear and conspicuous explanation of how the recipient can opt out,” the acceptance of a return email address or another easy internet-based way, the 10 business day deadline, the 30 day minimum lifetime of the mechanism, the prohibition on fees, extra personal information and any step beyond a reply or a single page, the statement that the law makes no exception for business-to-business email, and the $53,088 per email figure.
- Google, Email sender guidelines, checked 30 September 2026. Source for the requirement that marketing and subscribed messages support one-click unsubscribe and include a clearly visible unsubscribe link in the message body, the references to RFC 2369 and RFC 8058, and the instruction to keep spam rates in Postmaster Tools below 0.30% with 0.10% as the working target.
- Google, Email sender guidelines FAQ, checked 30 September 2026. Source for the definition of a bulk sender as close to 5,000 messages or more to personal Gmail accounts within a 24-hour period, the statement that one-click unsubscribe is required only for marketing and promotional messages, the exclusion of Google Workspace inbound and one-to-one mail, and the recommendation to fulfill unsubscribe requests within 48 hours.
- Yahoo, Sender best practices, checked 30 September 2026. Source for the one-click unsubscribe and functioning List-Unsubscribe header requirements for marketing and subscribed messages, the instruction to honor unsubscribes within 2 days, the clearly visible unsubscribe link in the body, and the 0.3% spam rate ceiling.
- RFC 8058, Signaling One-Click Functionality for List Email Headers, checked 30 September 2026. Source for the requirement that List-Unsubscribe contain one HTTPS URI, that List-Unsubscribe-Post contain the single key and value pair List-Unsubscribe=One-Click, and that the mailbox provider unsubscribe by HTTPS POST to that URI.
- CRTC, Frequently Asked Questions about Canada’s Anti-Spam Legislation, checked 30 September 2026. Source for the requirement to include an unsubscribe mechanism in commercial electronic messages, the minimum 60 day validity of the link, the obligation to process a request without delay and no later than 10 business days, and the $1 million and $10 million maximum administrative monetary penalties.
- Directive 2002/58/EC of 12 July 2002 (ePrivacy Directive), Article 13, EUR-Lex, checked 30 September 2026. Source for the Article 13(4) prohibition on sending direct marketing email without a valid address to which the recipient may send a request that such communications cease.
- GDPR Article 21, checked 30 September 2026. Source for the Article 21(2) right to object at any time to direct marketing, the Article 21(3) obligation to stop processing, and the Article 21(4) requirement that the right be brought to the recipient’s attention at the latest at the time of the first communication and presented clearly and separately from any other information.
- lemlist, Sending Policy, checked 30 September 2026. Source for the platform term that all campaigns must include a clear and concise link for recipients to easily opt out of receiving future communication. Quoted as an example of a platform-level requirement that sits above the statutory one.
Leave a Reply