Just generate a unsubscribe url for each user and send the same link on every email. Something like http://www.example.com/newsletter/unsubscribe?id=6e85d15bdbd...
A simple newsletter registration doesn't require that much security anyways.
Previously I have just created a filter to archive the email rather than hitting spam, but flagging it would do more damage to the sender. I guess I'll consider next time if its bad enough that their poor admin needs to deal with his domains being blacklisted. It's almost certainly not his fault after all, but all the misery will be dumped on him when "THE EMAILS ARENT GETTING THROUGH!"
Are you saying that they should be able to know you via link hash? For single actions like 'confirm' or yes/no I would agree that it would be easier to not need to be logged in.
Can I ask you this, have you never not logged in and left the action not done? Or do you log in begrudgingly anyway?
If the unsubscribe action chain is longer than setting up a new email filter - you're doing it wrong. Not the OP, but I do leave and add the address to auto-spam as soon as I need to log in / do something else.
1) Click the unsubscribe link
2) Uncheck a bunch of never seen before mailing lists subcategories
3) Enter e-mail address
4) Enter captcha
5) Check Are you sure? box
6) Click Save
BAD BAD BAD user experience.Theirs is the worst I've ever experienced.
Think I eventually had to close my ebay account entirely to get rid of all mail (which was after 4 support tickets).
I don't know how typical she is, but you do wonder whether eBay's mercenary attitude towards spam isn't a detriment to their public reputation.
Or perhaps the text was written by someone who had no idea of how subscribe/unsubscribe worked and took a 'reasonable' guess.