- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Regardless of what google and yahoo say, I need to be able to verify that when user@domain wants to unsubscribe they MUST verify their account ownership first.
Simply embedding a long per-person (email address) token in CLEAR text in an email is liable to interception?
If any bad actor has the email they can simply curl the URL for the unsubscribe and that person will be unsubscribed.
Does your platform offer "validated owner account unsubscribe" i.e. password or 2FA protected?
Thanks
PS part of my organisation is a customer and I specialize in security.
Solved! Go to Solution.
- Labels:
-
Contact Management
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @Ivanb09 ,
No, since we're an external email service provider, any emails coming from our system would not be affected by the internal mechanisms for specific email programs. Therefore, it would not be possible to "vet" contacts' unsubscriptions via two-factor or password entry for one-click unsubscribe, as contacts do not have their own MFA and passwords for your particular Constant Contact (or any ESP for that matter) account.
One-click unsubscribe is a requirement we must comply with in order to still operate globally, as well as have emails accepted by the largest and most popular email programs. Unsubscription in general has to be as deliberately clear and unburdened of a process as possible, in order to comply with industry standards and anti-spam laws. At this time, the current one-click unsubscribe process cannot be changed or removed. There are currently no plans to change this, unless there are significant changes to anti-spam laws and industry standards.
Contacts unsubscribing via the links provided in Compliance blocks / footers are still redirected to a confirmation page. On this page, they can pick-and-choose other lists you've made available as an alternative to wholly unsubscribing, or make the final confirmation of the email address they're unsubscribing for. If they change the email address that auto-populates from clicking the coded unsub link, they will see an error message. There are currently no plans to change this, unless there are significant changes to anti-spam laws and industry standards.
See also:
Understanding unsubscribed contacts
Manually resubscribe a contact
Update your email and sign-up form footer settings
Constant Contact's email permission policy
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
William A
Community & Social Media Support
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @Ivanb09 ,
No, since we're an external email service provider, any emails coming from our system would not be affected by the internal mechanisms for specific email programs. Therefore, it would not be possible to "vet" contacts' unsubscriptions via two-factor or password entry for one-click unsubscribe, as contacts do not have their own MFA and passwords for your particular Constant Contact (or any ESP for that matter) account.
One-click unsubscribe is a requirement we must comply with in order to still operate globally, as well as have emails accepted by the largest and most popular email programs. Unsubscription in general has to be as deliberately clear and unburdened of a process as possible, in order to comply with industry standards and anti-spam laws. At this time, the current one-click unsubscribe process cannot be changed or removed. There are currently no plans to change this, unless there are significant changes to anti-spam laws and industry standards.
Contacts unsubscribing via the links provided in Compliance blocks / footers are still redirected to a confirmation page. On this page, they can pick-and-choose other lists you've made available as an alternative to wholly unsubscribing, or make the final confirmation of the email address they're unsubscribing for. If they change the email address that auto-populates from clicking the coded unsub link, they will see an error message. There are currently no plans to change this, unless there are significant changes to anti-spam laws and industry standards.
See also:
Understanding unsubscribed contacts
Manually resubscribe a contact
Update your email and sign-up form footer settings
Constant Contact's email permission policy
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
William A
Community & Social Media Support
