hxxp://example.com/unsubscribe?id=abcd1234
A couple years ago I noticed that MSFT IPs hitting my unsubscribe links with invalid identifiers on the quest string. Anybody ever seen that?
hxxp://example.com/unsubscribe?id=abcd1234
A couple years ago I noticed that MSFT IPs hitting my unsubscribe links with invalid identifiers on the quest string. Anybody ever seen that?
This allows everything to be "one click" (which honestly is a good thing) but prevents crawlers from accidentally triggering the unsubscribe.
Not sure this still works today and obviously this is not legal advice.
---
Okay, HN. Go ahead and explain what's offensive here.
The question that was asked: "I noticed that MSFT IPs hitting my unsubscribe links with invalid identifiers on the [query] string. Anybody ever seen that?"
The question the parent commenter seems to have hallucinated: "Does anyone know how we can keep mail services from unsubscribing folks in error when these mail services scan our subscribers' emails, but also still offer our subscribers 1-click unsubscribe?"
You can use captcha or similar, one workaround I've seen has a submit that is hidden so never clicked by real people then a visible submit that sets a hidden input and clicks the other one which requires the hidden input... not foolproof but avoids some accidents.
https://techcommunity.microsoft.com/t5/security-compliance-a...
Please report back if you try it :-)
If I get another email from that org, I click "report spam".
That was my understanding at least.
I don't read clicking a "confirm" button as a second action. The attorney didn't either. He also said CAN SPAN doesn't apply to a 501(c)3. I still try to comply to be a good citizen.
What you can't do is take them to a page that says "to unsubscribe, send a certified letter to our headquarters and wait 90 business days". The entire transaction must be completed at the page you link to.
Bonus points when contacting support requires me to log in to "my account" too.
I've seen this pattern of unsubscribe link, then click button approved as CAN-SPAM compliant more than once so I don't think there's a legal concern. The CAN-SPAM rule seems more targeted at the systems you used to see a lot that required the user to log into their account, type in their email address, or figure out a complicated "communications preferences" list to use the unsubscribe form.
check out https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C...
It's a little fuzzy to me how exactly to interpret this but I think you could reasonably read it as allowing even unsubscribe pages that require you to type your email address in again (even though I detest these and don't think the problem they're intended to solve is a meaningful one).
These are fine for me if the email is prepopulated.
Details: https://support.google.com/mail/answer/81126#zippy=%2Crequir...
(I work for Google, but on something totally unrelated, and don't speak for them or have any inside knowledge. I was just curious and looked it up.)
Turns out, dealing with Unicode beyond 2 bytes (i.e. anything above ASCII and the common Latin characters) is still a problem in 2023.
Weirdly, if google thinks you're a dodgy sender they won't display the button, which seems counterproductive to me.
If it's in the querystring then they essentially fuzz it by changing some part(s) of the value. I noticed this because I use signed tokens and it raised an exception in Sentry when the signed token was invalid.
I ended up moving the signed token into the URL itself and the problem went away. eg. /unsubscribe/abcd1234/
Please try to make the world a better place instead of doing the legal minimum.
One click unsubscription is presumably what they want.
My experience is that every unsubscribe goes to a form w/ a submit button. Shitty ones make you type your email address. (Mine doesn't.)
Just did a bit of unsubscribing and sydneytools.com.au, abc.net.au, squabblr.co, bundlehunt.com, and healingstreams.tv all one click unsubscribe.
No idea if this holds if/when the email crawler bots start executing JS on crawl.