# One-Click Unsubscribe (RFC 8058) for Exim, Postfix, WordPress

Source: https://srvscripts.com/guides/one-click-unsubscribe-rfc-8058/
Updated: 2026-10-06
Publisher: srvScripts (https://srvscripts.com/)

**Short answer:** One-click unsubscribe needs two headers in every marketing message: `List-Unsubscribe: <https://...>` with an HTTPS URL that identifies the recipient and list, and `List-Unsubscribe-Post: List-Unsubscribe=One-Click`. Both must be covered by a valid DKIM signature, and the URL must accept a POST and answer 200 without redirects. The sending application adds the headers; Exim or Postfix only has to sign them. Gmail and Yahoo require it for bulk senders and expect unsubscribes to be honoured within two days.

We ran the Exim DKIM checks on our lab servers (AlmaLinux 9.8 with cPanel & WHM 11.138 and DirectAdmin 1.712, Exim 4.100.1) and tested the example endpoint below with PHP 8.2 and `curl` on the cPanel lab on 6 October 2026. The Postfix/OpenDKIM part was checked against the OpenDKIM documentation and source, not run on a lab server.

## What RFC 8058 requires

The headers look like this (the `mailto:` part is optional):

```
List-Unsubscribe: ,

List-Unsubscribe-Post: List-Unsubscribe=One-Click
```

When a user clicks the unsubscribe button in their mailbox, the provider sends an HTTPS POST to that URL with the body `List-Unsubscribe=One-Click`. The rules from RFC 8058:

- `List-Unsubscribe` must contain one HTTPS URI. It may also contain a `mailto:`.

- `List-Unsubscribe-Post` must contain exactly `List-Unsubscribe=One-Click`.

- The URI must carry enough information to remove the right recipient from the right list, because the POST has no other parameters. It should include an opaque or hard-to-forge token.

- The message must have a valid DKIM signature whose `h=` tag includes both headers. Without it, receivers should not offer one-click.

- The server must not answer the POST with a redirect, and the request carries no cookies or login.

Gmail adds that a mailto link or a plain “unsubscribe” link in the body does not meet its one-click rule. Yahoo calls the POST method “highly recommended” and accepts mailto. Both want unsubscribes honoured within 48 hours / 2 days, and both require it only for marketing and subscribed mail, not for receipts or password resets.

## Who adds the headers

Exim and Postfix do not know which messages are newsletters or who the recipient is on a list, so they cannot create correct per-recipient unsubscribe URLs. The headers must come from the software that builds the message: the newsletter plugin, CRM, mailing list manager or your own code. The server admin’s jobs are to make sure DKIM signs those headers, and that the unsubscribe URL works through the web stack.

## Exim on cPanel and DirectAdmin: check DKIM covers the headers

Exim signs the headers listed in `dkim_sign_headers`. When that option is not set, it uses a built-in default. Check what your build uses:

```
exim -bP macro _DKIM_SIGN_HEADERS | tr ':' '\n' | grep -i list
grep -c dkim_sign_headers /etc/exim.conf
```

Output on our cPanel lab (the DirectAdmin lab showed the same list):

```
List-Id
List-Help
List-Unsubscribe
List-Unsubscribe-Post
List-Subscribe
List-Post
List-Owner
List-Archive
0
```

The `0` means neither panel’s Exim configuration overrides the option, so Exim 4.100.1 signs `List-Unsubscribe-Post` whenever the message contains it. cPanel signs with selector `default` and DirectAdmin with `x`; DKIM must be enabled for the sending domain. If you added your own `dkim_sign_headers` line in a custom Exim configuration, make sure it still includes both list headers.

## Postfix with OpenDKIM

OpenDKIM’s documented default for `SignHeaders` is the “common examples” list from RFC 6376 section 5.4.1, which includes `List-Unsubscribe` but predates and does not name `List-Unsubscribe-Post`. Check a signed message first (see the verification section). If `list-unsubscribe-post` is missing from `h=`, set the list explicitly in `/etc/opendkim.conf`:

```
SignHeaders From,Reply-To,Subject,Date,To,Cc,Message-ID,MIME-Version,Content-Type,Content-Transfer-Encoding,In-Reply-To,References,List-Id,List-Help,List-Unsubscribe,List-Unsubscribe-Post,List-Subscribe,List-Post,List-Owner,List-Archive
```

Specifying a list replaces the default entirely, so include everything you want signed. Then restart OpenDKIM (`systemctl restart opendkim`) and send a new test message. If you sign with Rspamd or another milter instead, check its signed-headers setting the same way.

## WordPress and PHP senders

Newsletter plugins and mailing services usually have a setting for List-Unsubscribe; check the plugin’s documentation for “List-Unsubscribe-Post” or “one-click” specifically, since older versions often add only the first header. If you send from your own code, `wp_mail()` accepts extra headers and passes unknown ones through to PHPMailer:

```
