Skip to main content
Compliance Last updated: September 2026 8 min read

Gmail and Yahoo one-click unsubscribe rules for venue email

C
CaptiFi Editorial Team
CaptiFi · September 2026
Gmail and Yahoo one-click unsubscribe rules for venue email
5,000
Messages a day to Gmail that make a domain a bulk sender (Google)
0.3%
The spam rate both Google and Yahoo tell senders to stay below
2 days
Yahoo's window for honouring an unsubscribe; Google's FAQ says 48 hours
p=none
The minimum DMARC policy both providers accept from a bulk sender

From 1 February 2024 Google began holding anyone who sends large volumes to Gmail to a published set of sender requirements, and Yahoo published a matching list for its own mailboxes. This guide is for venues and groups that email the guests they collect at WiFi sign-in, and every figure in it comes from Google's Email sender guidelines, its FAQ, or Yahoo's Sender Best Practices as they read on 29 September 2026.

The rules in plain English, and who counts as a bulk sender

Google splits its guidelines into two tiers. Requirements for all senders asks every sender to "Set up SPF or DKIM email authentication for your sending domains", to use a TLS connection, and to "Keep spam rates reported in Postmaster Tools below 0.3%". Nothing in that tier depends on list size; it applies to a venue emailing 40 regulars.

The second tier, Requirements for sending 5,000 or more messages per day, opens: "Starting February 1, 2024, email senders who send more than 5,000 messages per day to Gmail accounts must meet the requirements in this section." It asks for SPF and DKIM together, a DMARC record where "Your DMARC enforcement policy can be set to none", From: alignment with the SPF or DKIM domain, and this: "Marketing messages and subscribed messages must support one-click unsubscribe, and include a clearly visible unsubscribe link in the message body."

Yahoo's Sender Best Practices lists the same items under Requirements for Bulk Senders: "Implement both SPF & DKIM", "Publish a valid DMARC policy with at least p=none", "Implement a functioning list-unsubscribe header, which supports one-click unsubscribe", "Have a clearly visible unsubscribe link in the email body", "Honor unsubscribes within 2 days" and "Keep your spam rate below 0.3%". Yahoo attaches no daily figure to the words bulk sender.

Does a single venue hit the threshold, and when does a group?

Google's FAQ describes a bulk sender as one "that sends close to 5,000 messages or more to personal Gmail accounts within a 24-hour period". The count is messages to Gmail, in one day. A single-site restaurant sending one or two campaigns a month to a few thousand guests, only some of them on Gmail, stays under it.

Two things change the arithmetic. The FAQ counts "all messages sent from the same primary domain", its example being 2,500 messages from solarmora.com plus 2,500 from promotions.solarmora.com, so a group sending one campaign for six venues from one domain on the same morning adds every site together. And the status sticks: "Bulk sender status doesn't have an expiration date. Email senders that have been classified as bulk senders are permanently classified as such."

The practical answer is to meet the bulk list whether or not you expect to cross it. Yahoo publishes no number, Google's wording is "close to 5,000", and its FAQ says that "Starting November 2025, Gmail is ramping up its enforcement on non-compliant traffic", with failing messages facing "temporary and permanent rejections".

Authentication: SPF, DKIM and DMARC through your own sending domain

SPF is a DNS record naming the servers allowed to send for your domain. DKIM signs each message with a key published in your DNS, so the receiver can confirm it was not altered. DMARC tells receivers what to do when both fail; at p=none it tells them to do nothing, the minimum both providers accept. Alignment means the domain after the @ in your From address is the one that passed SPF or DKIM.

Alignment is why sending as hello@yourvenue.co.uk through a platform's shared domain fails the bulk requirement: the From address is on your domain and the signature is on theirs. The fix is to authenticate your own domain with the platform.

In CaptiFi that is the first step under Email Marketing, Settings, on the Sender & domain tab. Set a From name and From address, click Save sender identity, and a table of DNS records appears: type, host and value, each with a copy button. Add them at your domain provider; the How to add these records section under the table covers Cloudflare, GoDaddy, Namecheap, 123-reg, Squarespace Domains and IONOS.

Records usually propagate within minutes and can take up to 48 hours, then Verify now marks each record Pass and the domain Verified; campaigns cannot be sent until it is. If someone else manages your domain, Email these instructions sends them the exact records with registrar tips and needs no CaptiFi login.

One-click unsubscribe: the header, the button and what CaptiFi does

The unsubscribe rule has two halves. The visible half is the footer link, which both providers require in the message body. The technical half is a pair of headers defined in RFC 8058: List-Unsubscribe, carrying an HTTPS address, and List-Unsubscribe-Post with the value List-Unsubscribe=One-Click. Google's FAQ adds that "Including a mailto link in the body of your messages doesn't meet our one-click unsubscribe requirement."

When both headers are present, Gmail, Yahoo Mail, Apple Mail and Outlook show an Unsubscribe button beside the sender's name at the top of the message. The guest sees no form; the mailbox sends the request itself. Google's FAQ recommends fulfilling requests "within 48 hours", Yahoo says "Honor unsubscribes within 2 days", and the FAQ limits the rule to "marketing and promotional messages", with transactional mail excluded.

Every CaptiFi marketing email carries the footer link, and since August 2026 the one-click headers as well. Pressing Unsubscribe in Gmail, Yahoo Mail or any other mailbox that supports the standard opts the guest out at that moment, for every CaptiFi email that offers the button: venue campaigns, automations, review requests, and CaptiFi's own customer updates. The footer link keeps working alongside it.

The My Campaigns page on my.captifi.io listing three sent email campaigns with recipients, sent, opened and clicked counts and open and click rates
The campaigns list for a demo venue, each campaign sent from the venue's verified domain with the footer link and the one-click headers.

Suppressions that follow the address

An unsubscribe that removes an address from one list fails the next time a different list emails the same person, and that is how a venue group collects complaints. In CaptiFi the opt-out applies everywhere at once: every venue on the account and every campaign, automation and review request. The address moves to the Suppressions tab under Email Marketing, Settings, and nothing on the account emails it again.

Hard bounces land on the same list automatically. A bounced address is also marked Bounced on the Guest Visits page and rejected if anyone tries to sign in to the WiFi with it again, so a dead address costs one send. Imports respect the list too: anyone who previously unsubscribed or bounced stays suppressed whatever the uploaded file says.

Google's FAQ says the user-reported spam rate is calculated daily. A guest who asked to leave and then hears from a sister venue is the likeliest person to report you.

Keeping complaints under the line

Who you email decides the rest. Google's Postmaster Tools guidance is stricter than the headline figure: "Keep spam rates reported in Postmaster Tools below 0.10% and avoid ever reaching a spam rate of 0.30% or higher."

Consent at sign-in comes first. CaptiFi campaigns and automations email only guests who ticked the marketing box on your splash page. The box is separate from the WiFi terms, nothing is pre-ticked, and the consent is recorded against the guest, the setup our guest WiFi GDPR checklist walks through.

Imported lists are where complaints come from: an old booking export is full of people who do not remember you. CaptiFi's import asks you to confirm permission when the file has no opt-in column and fires no welcome emails. Send an imported list its first message on its own and watch the result.

Frequency matters as much. CaptiFi's own guidance is one or two emails a month, with a warning that weekly or more drives unsubscribes. Automations are timed by the guest's own visits, a welcome after the first connection or a win-back after a chosen number of days away, go only to opted-in guests, and can be held to a sending window in the venue's time zone.

A deliverability checklist for venues

  1. Send from your own domain and verify it in CaptiFi before the first campaign; Verify now shows Pass against each record.
  2. Publish a DMARC record at your registrar, at p=none as a minimum.
  3. Carry a visible unsubscribe link and the RFC 8058 headers on every marketing email and honour each request within two days; CaptiFi does both automatically.
  4. Email only guests who opted in at sign-in, with the marketing box unticked by default.
  5. Treat an imported list as its own audience and confirm permission before uploading it.
  6. Register the domain in Google Postmaster Tools and Yahoo's Complaint Feedback Loop, and read the spam rate after each send.
  7. Running a group from one domain? Add up every venue's send before a shared campaign day; Google counts the primary domain as a whole.

Requirement by requirement: Gmail, Yahoo and CaptiFi

Requirement What Gmail checks What Yahoo checks What CaptiFi does for you
SPF and DKIM SPF or DKIM for every sender; both above 5,000 messages a day "Implement both SPF & DKIM" DNS records generated when you save the sender identity; Verify now shows Pass per record
DMARC A record for the sending domain; the policy can be none "at least p=none", and it must pass You send from your own verified domain, so the record you publish there is the one checked
From alignment From: domain matches the SPF or DKIM domain Same wording Campaigns send from the From address on your verified domain
One-click unsubscribe RFC 8058 headers on marketing mail; a mailto link in the body does not count A functioning list-unsubscribe header; RFC 8058 POST recommended Headers on every marketing email; the Gmail and Yahoo Mail buttons opt the guest out at the click
Visible unsubscribe link Required in the message body "a clearly visible unsubscribe link in the email body" A footer link on every marketing email
Time to honour "within 48 hours" recommended in the FAQ "Honor unsubscribes within 2 days" Applied at the click, across every venue
Spam rate Below 0.3%; 0.10% advised, never 0.30% "Keep your spam rate below 0.3%" Only opted-in guests emailed; suppressions follow the address; bounced addresses rejected at sign-in

Two requirements sit with the platform: whose domain the mail leaves from, and whether a guest can leave in one click. CaptiFi handles both. The complaint rate sits with you and starts at the consent box on your splash page, where building an email list from guest WiFi begins; the compliance and guest data capture pages cover that side.

Sources: Google, "Email sender guidelines" (support.google.com/a/answer/81126) and "Email sender guidelines FAQ" (support.google.com/a/answer/14229414); Yahoo Sender Hub, "Sender Best Practices" (senders.yahooinc.com/best-practices), all as read on 29 September 2026. Both providers revise these pages, so check the live text before relying on a figure. CaptiFi behaviour is as described in its customer documentation and July to September 2026 release notes.

Frequently asked questions

Quick answers to the most common questions about this topic.

What is one-click unsubscribe, and how is it different from the link in the footer?
One-click unsubscribe is a pair of email headers defined in RFC 8058: List-Unsubscribe, carrying an HTTPS address, and List-Unsubscribe-Post with the value List-Unsubscribe=One-Click. When both are present, Gmail, Yahoo Mail, Apple Mail and Outlook show an Unsubscribe button at the top of the message, and pressing it opts the reader out without a form. The footer link is still required by Google and Yahoo, and Google's FAQ states that a mailto link in the body does not meet the one-click requirement on its own. CaptiFi marketing emails carry both the footer link and the headers.
Does a single restaurant or pub count as a bulk sender under Google's rules?
Usually not. Google's Email sender guidelines apply the bulk requirements to senders of more than 5,000 messages a day to Gmail accounts, and its FAQ describes the line as close to 5,000 messages to personal Gmail accounts in a 24-hour period. A single venue sending one or two campaigns a month to a few thousand guests, only some on Gmail, stays under that on any given day. Google's requirements for all senders, including SPF or DKIM and a spam rate below 0.3%, apply regardless of volume.
When does a venue group become a bulk sender?
Google's FAQ counts every message sent from the same primary domain, including subdomains, towards the 5,000-a-day figure. Its example is 2,500 messages from solarmora.com plus 2,500 from promotions.solarmora.com making one bulk sender. A group that sends the same campaign for several venues from one domain on the same morning adds every site together. The FAQ also says bulk sender status has no expiry, so one large send classifies the domain permanently. Meeting the bulk list from the start is the safer route.
Do I need DMARC to email my WiFi guests?
For bulk sending, yes. Google's guidelines require a DMARC record for the sending domain and say the enforcement policy can be set to none. Yahoo's Sender Best Practices asks bulk senders to publish a valid DMARC policy with at least p=none that passes. Both also require the domain in the From address to align with the domain that passed SPF or DKIM, which is why sending through your own verified domain matters. Publish the DMARC record at your domain registrar alongside the records CaptiFi generates for verification.
What happens in CaptiFi when a guest presses Unsubscribe in Gmail or Yahoo Mail?
The guest is opted out at that moment, with nothing to fill in. Since August 2026 every CaptiFi marketing email carries the one-click headers, and the September 2026 release extended the button to every CaptiFi email that offers it: venue campaigns and automations, review requests, and CaptiFi's own customer updates. The address moves to the Suppressions tab under Email Marketing, Settings, and the opt-out applies across every venue and every list on the account. The footer link keeps working alongside the button.
Does an unsubscribe at one of my venues apply to my other venues?
Yes. In CaptiFi an opt-out applies everywhere at once: every venue on the account and every campaign, automation and review request. The address is added to the account's Suppressions list and is never emailed again by any of them. Hard bounces land on the same list automatically, a bounced address is marked Bounced on the Guest Visits page and rejected at WiFi sign-in, and anyone who previously unsubscribed or bounced stays suppressed when a contact list is imported.
What spam rate do Gmail and Yahoo allow?
Google's Email sender guidelines tell every sender to keep spam rates reported in Postmaster Tools below 0.3%, and its Postmaster Tools guidance goes further: stay below 0.10% and never reach 0.30%. Google's FAQ says the user-reported spam rate is calculated daily. Yahoo's Sender Best Practices asks senders to keep the spam rate below 0.3% and offers a Complaint Feedback Loop for tracking complaints. Emailing only guests who opted in at sign-in, suppressing opt-outs across every venue and keeping to one or two campaigns a month are the practical ways a venue stays under the line.
How long does verifying a sending domain take in CaptiFi?
Saving your sender identity under Email Marketing, Settings, on the Sender and domain tab generates the DNS records immediately, with copy buttons and a How to add these records section covering Cloudflare, GoDaddy, Namecheap, 123-reg, Squarespace Domains and IONOS. Once you add them at your domain provider they usually propagate within minutes and can take up to 48 hours. Click Verify now and each record shows Pass and the domain shows Verified. Campaigns cannot be sent until the domain is verified. If someone else manages your domain, Email these instructions sends them the records with no CaptiFi login needed.
C
Written by
CaptiFi Editorial Team

The CaptiFi Editorial Team writes about guest WiFi marketing, captive portals, GDPR-compliant data capture, and local SEO for venue operators. We base our recommendations on real customer outcomes and verified third-party reviews from G2.com.

Ready to turn your guest WiFi into a marketing engine?

CaptiFi captures customer data from every WiFi login, automates Google reviews and email follow-ups, and plugs into the tools you already use. Hardware included (refundable deposit), transparent pricing, 30-day free trial.

Related reading