Hijacking the thread: I do some "bulk" sending for a 501(c)3 I volunteer for. I include unsubscribe links that go to a form with a submit button (because I want the unsubscribe to be a POST request). Each link has a random opaque identifier in the query string. Something like: hxxp://example.com/unsubscribe?id=abcd1234 A couple years ago I noticed that MSFT IPs hitting my unsubscribe links with invalid identifiers on…
I thought it was part of CAN SPAM that you can’t require a second action and that was why the big email sending providers moved to that.
Details: https://support.google.com/mail/answer/81126#zippy=%2Crequir...
(I work for Google, but on something totally unrelated, and don't speak for them or have any inside knowledge. I was just curious and looked it up.)