Free to scan. €4.99 once, only if you decide to clean up. No account, no subscription.
Deep dive · 7 min read

Why “unsubscribe” doesn’t always mean unsubscribed

Click unsubscribe, and most people assume that’s the end of it. For a real share of senders, it isn’t, not because the click failed, but because the sender never built a working exit in the first place. Here’s what actually happens behind that click, and why regulators on both sides of the Atlantic are starting to pay attention.


What “unsubscribed” is supposed to mean

When a sender does this properly, unsubscribing is genuinely instant. Every legitimate marketing email can carry a List-Unsubscribe header (standardized in RFC 2369, extended with a one-click POST variant in RFC 8058), a piece of metadata your email client reads to send an opt-out request straight to the sender’s server. No login, no page to load, no form. The server responds, so the result is verifiable: the request was received.

This is the mechanism behind Gmail’s and Outlook’s own one-click unsubscribe buttons, and it’s what makes automatic, bulk unsubscribing possible at all. When it’s implemented correctly, “unsubscribed” means exactly what it sounds like.

Where it breaks down

Not every sender implements it, and nothing forces them to. Some publish a List-Unsubscribe header that only points to a login-gated preference center, so the “one click” is actually a multi-step form buried behind an account you have to find your way back into. Some publish nothing usable at all, no header, no working link in the footer, just a mailto address nobody reads. Some technically comply but bury the unsubscribe link below a wall of re-engagement copy asking you to reconsider first.

None of this shows up as an error. You click, a page loads or an email is sent, and there’s no way to tell from the outside whether anything actually happened on the sender’s end. That gap, between an action you took and a result nobody can confirm, is exactly where a lot of “I already unsubscribed from this, why am I still getting it” complaints come from.

Regulators are starting to notice

This isn’t just a UX complaint anymore. In the EU, Article 25 of the Digital Services Act explicitly bans dark patterns, deceptive interface designs that make an action like cancelling or opting out harder than it needs to be, and has applied to the very largest platforms since 2024. The broader Unfair Commercial Practices Directive, which covers misleading and aggressive practices generally, already applies to every business in the EU regardless of size. A dedicated Digital Fairness Act, meant to address dark patterns more broadly across all online services, is still in preparation at the European Commission. It isn’t law yet.

In the US, the FTC’s click-to-cancel rule has had a rockier path: a federal court vacated it in 2025 on procedural grounds, and the FTC has since signalled it’s renewing interest in similar rulemaking, in February and again in May 2026. That’s a direction regulators are moving in, not a rule currently in force, worth watching rather than relying on.

None of this changes what already applies to email specifically: under GDPR Article 21, a sender must act on an objection to marketing without undue delay, one month at the latest. Under CAN-SPAM, US senders have 10 business days. Those obligations exist today, dark-patterned interface or not.

What “accepted” should mean

Any tool that automates unsubscribing runs into the same honesty problem the senders create. When a request goes through a working List-Unsubscribe header, the sender’s server responds, so that result is genuinely confirmable: accepted. When the only option is a redirect to a preference center or a manually sent opt-out request, nobody on the receiving end can verify what happens next, so the honest label is something closer to sent or opened, not done.

A tool that shows the same green checkmark for both is making a promise it can’t keep. in-boxed, for what it’s worth, treats this distinction as a hard rule in its own interface: accepted only when a sender’s server actually confirmed it, a separate status for everything that could only be sent or opened, and a plainly stated reason whenever a request fails outright.

How to tell if you’re actually unsubscribed

There’s no shortcut around the underlying uncertainty, but there is a practical check: give it time before assuming success or failure. A confirmable opt-out through a working header tends to take effect within days. A preference-center or email-based request can legally take up to a month under GDPR, or 10 business days under CAN-SPAM, before you can fairly call it ignored. If mail from that specific sender is still arriving well past that window, that’s the point to treat the first attempt as failed and either escalate through the sender’s own site or file a complaint with your national data protection authority.

Related articles
What is a List-Unsubscribe header?Technical explainerHow to stop spam emails for goodInbox tipsGmail's Manage Subscriptions vs in-boxedComparisonFAQ, common questions about in-boxedFAQ

See which senders actually confirm it

in-boxed shows accepted, opened, and failed separately, per sender, so you know what you’re actually looking at.

Scan my inbox for free →