How Long Must a Link Keep Working? The Legal Minimums
You turned on link expiry because it felt tidy. Then someone tried to unsubscribe six weeks after the send and hit a dead page. Here is the minimum time each rule actually requires a link to keep answering, and which links you must never put behind an expiry date.

Why a dead link can be a legal event, not just a broken one
A short link that stops resolving is usually a support ticket. Occasionally it is a breach. The difference is entirely about what the link was carrying. If the dead URL was the only route a recipient had to get off your list, to read the terms of a promotion, or to find the ingredients on a bottle they are holding in a shop, the link was not decoration. It was the compliance mechanism, and the rule it satisfied did not stop applying on the day your campaign calendar closed.
Almost nobody writes this down. Link expiry is a standard feature on every shortener, Flyn included, and the copy around it talks about scarcity, security and tidy dashboards. None of it mentions that several rules put a floor under how long particular links have to answer, measured from the moment you pressed send rather than the moment the offer ended.
What actually dies when a link expires
Three things break at once, and only the first generates a complaint you will hear about. The visitor experience dies: someone taps and gets an expired page. The measurement dies: every click after expiry is one you never attribute. And the obligation dies, because the rule that required a working route does not care that your link had a TTL. For the mechanics of expiry itself, the companion guide on link security, passwords and expiry covers the controls; this post is about the floor underneath them.
The minimum lifetimes, rule by rule
No single law says "a link must work for N days". Several rules each demand a working route, and two attach an explicit number. Everything in this section was verified at the primary source on 2026-09-10.
CAN-SPAM: thirty days, counted from each send
The FTC's own CAN-SPAM Act compliance guide for business is unambiguous: "Any opt-out mechanism you offer must be able to process opt-out requests for at least 30 days after you send your message." It also requires you to honor a request within 10 business days. Read those two together and the practical floor is 30 days of a working URL per message, rolling, because every send restarts its own clock. A weekly newsletter therefore has a continuously live 30 day window, not one window per quarter.
CASL: sixty days, written into the statute
Canada is stricter and puts the number in the law rather than in guidance. Section 11(2) of CASL requires the sender to ensure that the electronic address or web page used for the unsubscribe request "is valid for a minimum of 60 days after the message has been sent", and section 11(3) requires effect to be given to the request "without delay, and in any event no later than 10 business days". You can read the section on the Justice Laws site. If you send to Canadian recipients at all, 60 days is your real floor, because the stricter rule governs the shared asset.
UK PECR: no number, which is in some ways worse
Regulations 22 and 23 of the UK Privacy and Electronic Communications Regulations take a different shape. Regulation 22 turns on a simple means of refusing marketing, offered at the point of collection and in every subsequent message, and regulation 23 bars direct marketing email that gives no valid address to which the recipient can send a request that the communications cease. We are paraphrasing rather than quoting here, because legislation.gov.uk returned an empty document to us on 2026-09-10; read the regulation yourself before you cite it. Neither names a day count, and that does not give you latitude, it removes your ceiling. A refusal route that has gone dead is not a simple means of refusing, whether it died on day 31 or day 400. Separately, Article 7(3) of the UK and EU GDPR requires that withdrawing consent be as easy as giving it, and a 404 is not as easy as a tick box.
Gmail and Yahoo: not law, but they decide whether you are read
Mailbox providers publish their own rules and enforce them faster than any regulator. Gmail's email sender guidelines require senders above 5,000 messages a day to a Gmail address to include one-click unsubscribe headers, a requirement that took effect on 1 February 2024, and tell you that "Web links in the message body should be visible and easy to understand. Recipients should know what to expect when they click a link." Yahoo's sender best practices ask for a functioning list-unsubscribe header supporting one-click and say to "Honor unsubscribes within 2 days". Neither publishes a minimum lifetime for the URL, which in practice means the statutory floors above are the numbers you plan against.
Print, packaging and the QR code that outlives your campaign
The longest floors are physical, and they are written as accessibility duties rather than day counts. The ASA's note on QR codes in ads says it "will consider the wider context in which an ad appears, including where any links within an ad lead to". CAP rule 8.18 on promotional terms and conditions then lets a space-limited ad direct people to "an easily-accessible alternative source where all the significant conditions of the promotion are prominently stated". Read 8.18 as a lifetime rule, because a source that has expired is not easily accessible. EU wine labelling pushes the same duty out for years: under the ingredient and nutrition rules in Regulation (EU) 2021/2117 the e-label behind the QR code carries mandatory particulars, and Commission Notice C/2023/1190 is the interpretive guidance. Secondary readings of that notice put the duty at as long as the product remains suitable for consumption, years for a bottle, but EUR-Lex served us an empty document on 2026-09-10, so treat the shelf-life framing as unverified at source.
| Rule | Channel | Minimum lifetime | Clock starts | If the link dies |
|---|---|---|---|---|
| CAN-SPAM (US) | At least 30 days | Each send | The opt-out mechanism cannot process requests, per email | |
| CASL s.11(2) (Canada) | 60 days, statutory | Each send | The unsubscribe address is not valid for the required window | |
| PECR reg 22 and 23 (UK) | No day count stated | Ongoing | No simple means of refusing, no valid address for the request | |
| Withdrawal of consent (UK and EU) | Email, web | For as long as you rely on the consent | Consent given | Withdrawal is no longer as easy as giving it |
| Gmail bulk sender rules | Not stated | Not stated | Header requirement unmet above 5,000 a day; delivery suffers | |
| Yahoo sender rules | Not stated; honour in 2 days | Request received | Unsubscribe is not functioning; complaints rise | |
| TCPA and carrier rules (US) | SMS | No published lifetime floor | Not applicable | The link's shape is what is regulated, not its age |
| ASA and CAP rule 8.18 (UK) | Print, QR, ads | No day count; the linked source must stay easily accessible | Publication | The significant conditions of the promotion have no accessible source |
| EU wine e-label | Label, packaging | While the product is fit to drink (secondary reading, see the FAQ) | Placing on market | Mandatory particulars become unavailable to the buyer |
The one-click unsubscribe can never be a short link
This is the part that surprises people who have spent a decade shortening everything, and it is the single most useful thing in this post. A list-unsubscribe header is not a link a human clicks. It is an endpoint a mail client posts to, and the spec rules out a redirect in the response.
What RFC 8058 actually says
RFC 8058, the spec behind the one-click unsubscribe that Gmail and Yahoo now expect, says in section 3.1 that "The List-Unsubscribe header field MUST contain one HTTPS URI", and it is explicit about redirects: the mail sender "MUST NOT return an HTTPS redirect, since redirected POST actions have historically not worked reliably, and many browsers have turned redirected HTTP POSTs into GETs". A short link is a redirect, and the header URI is the one place a redirect is not allowed. Put a shortened URL there and you have built a one-click unsubscribe whose one click may never reach your suppression list, which is exactly the failure mode the mailbox providers are measuring you on.
What a POST to a real short link actually does
We measured this instead of assuming it. On 2026-09-10 we sent the one-click body to a live Flyn short link with curl. Posting to the bare short domain returned 301 with a Location header pointing at the canonical host, which is host canonicalisation rather than the link's own redirect, and is already the answer the spec forbids. Posting to the canonical host returned 405 with an empty body, because the redirect route answers GET and nothing else. Then the part worth knowing: a client that follows that 301 the way browsers do downgrades the POST to a GET, fetches the destination and gets a 200, so the unsubscribe body is dropped in silence and the address stays on your list. That is the precise failure RFC 8058 names when it says browsers "have turned redirected HTTP POSTs into GETs". Two responses, 301 and 405, and neither of them is an unsubscribe. Other shorteners will return different codes; what they all share is that the header URI is a redirect instead of the endpoint the spec asks for.
If your one-click unsubscribe goes through a shortener, you do not have a one-click unsubscribe. You have a redirect that a mail client is allowed to give up on.
Both unsubscribe headers have to be inside the DKIM signature
This is the other half of the spec, and it is the most common reason a correctly built one-click unsubscribe is never offered to the reader at all. RFC 8058 section 3.1 says the message "MUST have a valid DomainKeys Identified Mail (DKIM) signature that covers at least the List-Unsubscribe and List-Unsubscribe-Post headers". Section 4 is more specific: those two headers "MUST be covered by the signature and included in the h= tag of a valid DKIM-Signature header field". The consequence is in the same paragraph, and it is the bit people miss: if the message lacks that signature, the mail receiver "SHOULD NOT offer a one-click unsubscribe for that message". So audit your own h= tag, not just your header list. A DKIM signature that omits List-Unsubscribe-Post leaves you with a header Gmail can read and a one-click path it is told to ignore, which from the reader's side looks identical to having no header at all.
Short links are still fine everywhere else in the email
Nothing here argues against shortening the rest of your email. Campaign links, footer links, even the visible "unsubscribe" anchor in the body can be tracked links, as long as the destination works for the full statutory window. The constraint is narrow: the URI inside the List-Unsubscribe and List-Unsubscribe-Post headers must be a direct endpoint on a host you control. For the body links, the newsletter click tracking guide is the place to start, and a custom domain keeps them on your own brand so Gmail's "visible and easy to understand" expectation is met rather than dodged.
Links you must never expire, and links you may
Once you accept that some links are load bearing, the policy writes itself. Sort every link you ever send into two buckets before you touch an expiry field.
The never list
- Unsubscribe and preference centre links. Minimum 30 days under CAN-SPAM, 60 under CASL, and in practice forever, because old emails get forwarded and searched.
- Privacy notice, terms and cookie policy links. People are entitled to read what they agreed to long after the send.
- Legally required product information. Ingredients, allergens, energy labels, safety instructions, the e-label behind a QR code on a bottle.
- Significant conditions of a promotion reached from a space-limited ad, because CAP rule 8.18 expects that source to stay easily accessible.
- The STOP or preference destination promised in a text message. No regulator publishes a lifetime for it, but the message made a promise. The channel rules themselves are in the SMS marketing links guide.
- Anything printed. Packaging, leaflets, menus, vehicle livery, trade show stands. You cannot recall paper. The print and digital QR guide is blunt about this.
- Receipts, invoices and order confirmations. Retention duties often run for years.
The fair-game list
- Time-boxed offer pages, as long as the slug survives and lands somewhere honest.
- Event registration after the event, for the same reason.
- One-time downloads and file handoffs, where expiry is the point. These are the cases the expires-after-clicks guide and click limits exist for.
- Internal or test links that never left your team.
- Password protected shares with a named recipient and a known end date. The security side of that decision is covered in the guide to link passwords, expiry and data retention.
| Link type | Safe to expire? | What to do instead |
|---|---|---|
| Unsubscribe in an email body | No | Keep live indefinitely; never shorten the header URI |
| List-Unsubscribe header URI | No | Direct HTTPS endpoint on your own host, no redirect |
| Privacy notice or terms | No | Permanent URL, version the page not the link |
| QR code on packaging or a label | No | Permanent slug, repoint the destination as the product changes |
| Promotion terms reached from an ad | No | Keep the slug, swap in an offer-ended page |
| Limited-time offer page | The content, not the link | Repoint to an offer-ended page |
| Event sign-up | The content, not the link | Repoint to a recap or the next event |
| One-time file handoff | Yes | Expiry date plus a click limit is the right tool here |
The short-link case: expire the destination, not the address
Here is the resolution that makes all of this workable, and it is specific to short links. A short link has two halves: the address you handed out, and the destination it points at. Almost every time someone reaches for expiry, what they want is for the content to stop being available. They kill the address instead, because that is the button the interface offers.
Repoint instead of expiring
Editing the destination of a live link is the correct move for anything you have already sent. The address keeps resolving, the visitor lands on a page that says the offer ended and points somewhere useful, and nothing in your print run or email archive goes dark. Changing a link's destination is one edit. A short link is a redirect, and the point of a redirect is that the address and the target are separable.
What an expired Flyn link actually returns
If you do set an expiry date, know the behaviour. An expired Flyn link serves an expired page to a browser and returns 410 to crawlers, which is the correct signal for a resource that is intentionally gone. That is good engineering and terrible compliance if the link was an opt-out route, because a 410 is a very definite way of telling a regulator the mechanism no longer works. Setting an expiry date is a single field on the link form, which makes it easy to apply by accident to something you already mailed; capping a link by click count instead is a Pro feature. The expire a link article already recommends pointing the link at an offer-ended page rather than letting it die, and that advice is the right default, not a workaround.
Links created without an account expire on their own: most anonymous Flyn links last about 24 hours, and links from the password tool about 3 hours. Never put an unsubscribe route, a legal notice or anything destined for print behind one. If a recipient says a link is dead, the anonymous link expired and link shows not found explain what they are seeing.
Never reuse a slug you have already mailed
Slugs are unique per domain, so once a link is deleted the address is free again. Do not take it. A slug you have mailed or printed is now in email archives, CRM records and somebody's photo roll, and pointing it at a new campaign means old recipients land on the wrong thing. Treat every slug you have distributed as permanently retired, pick new ones with the slug generator, and keep naming rules consistent through custom slugs. If you are auditing what is still alive, run the list through the bulk short link health checker or check individual hops with the redirect checker.
The seven-point lifetime audit
Run this before a send, and once a quarter across everything already in market. It takes an hour the first time and ten minutes after that.
The seven checks
- List every link in the message and label each one: marketing, compliance, or legal notice. Only the first group is ever a candidate for expiry.
- Check the List-Unsubscribe header and confirm the URI is a direct HTTPS endpoint on your own host, not a shortener and not a redirect, and that both List-Unsubscribe and List-Unsubscribe-Post appear in the h= tag of your DKIM signature.
- Set the floor to 60 days if you mail anyone in Canada, 30 days otherwise, and then ask why you are expiring an opt-out route at all.
- Grep your expiring links for anything that has ever appeared in print, on packaging or in an ad, and remove the expiry from those.
- Repoint instead of expiring every offer link, and write the offer-ended page before the offer ends rather than after.
- Verify the hops resolve with the broken link checker and, for printed codes, the QR destination audit.
- Record the decision per link type in a one-page policy, so the next person on the team does not turn expiry back on for tidiness.
Give compliance links their own slug prefix, something like u-, legal- or label-, and make "no expiry on anything with these prefixes" a rule in your own process. A prefix is greppable in a way that an intention is not, and it survives staff turnover. Build them on a branded short link so the domain itself signals that the URL is yours and permanent.
Enforcement reality: where the cost actually lands
No regulator has fined anyone solely for an expired link, as far as we can find. That is a much narrower statement than it first reads, because the specific defect this post is about, an unsubscribe address that was not valid for the required 60 days, has already carried a price in Canada.
The Rogers Media undertaking, where the 60 day defect was priced
On 20 November 2015 the CRTC announced that Rogers Media Inc. had paid $200,000 as part of an undertaking to resolve alleged violations of CASL between July 2014 and July 2015. Three defects are named in the release, and one of them is this post's subject, word for word: "In addition, in some instances, the electronic address used to unsubscribe was allegedly not valid for the required minimum of 60 days following the sent message." The other two are commercial emails "containing an unsubscribe mechanism that did not function properly or which could not be readily performed by the recipient", and a failure to honour unsubscribe requests from some recipients within 10 business days.
Read the limits of that case honestly. It was an undertaking rather than a fine, the allegations were never proven, Rogers Media cooperated with the investigation and agreed to improve its compliance programme, and the 60 day defect travelled with two others, so nobody paid $200,000 for an expired link on its own. It is still the only named, priced enforcement action we can find that turns in part on how long an unsubscribe address stayed valid, and it happened in the one jurisdiction that puts the number in the statute rather than in guidance. If you need an answer to whether any of this has ever cost anyone anything, that is the answer.
Per-email arithmetic is the ceiling, not the evidence
CAN-SPAM penalties are assessed per message. The FTC's compliance guide states that "Each separate email in violation of the law is subject to penalties of up to $53,088", a figure that is adjusted for inflation, so check the current number before you rely on it. A single send to 50,000 addresses with a broken opt-out mechanism is therefore not one problem, it is 50,000 of them in the arithmetic, even though no regulator pursues the theoretical maximum. Canada works through administrative monetary penalties and negotiated undertakings instead, both administered by the CRTC, and the Rogers Media file above shows what a defective unsubscribe route is worth when one of those lands on you. Consent to the click tracking on those links is a different law and a different page: cookie consent for short-link click tracking covers PECR regulation 6 and the ICO's cookie enforcement, and the retargeting pixels and consent guide covers pixel fines.
The deliverability penalty arrives first, and it is worse
In practice the mailbox providers punish you long before a regulator writes to you. A dead unsubscribe route does not stop people wanting out, it makes them hit the spam button, and a rising complaint rate is the signal both providers act on. That suppresses your whole domain, not just the broken campaign. The same logic applies to links that look disposable: read why short links get flagged as spam alongside this.
A practical setup, and the disclaimer you should expect
You do not need a legal team to get this right. You need a policy that distinguishes marketing links from load-bearing ones, and a default that favours repointing over deleting.
A stack that survives an audit
- A direct, permanent HTTPS unsubscribe endpoint on your own host, referenced in the List-Unsubscribe header with no redirect in front of it, with that header and List-Unsubscribe-Post both inside your DKIM h= tag.
- Body links on your own branded domain, built so the destination can be edited without minting a new URL.
- Expiry dates reserved for private file handoffs, applied deliberately rather than as a habit.
- Offer-ended pages written in advance, so repointing is a one-minute job at the end of a campaign.
- A quarterly sweep of printed and packaged codes, plus a spot check on anything a partner shortened for you.
- A documented retirement rule: a slug you have distributed is never reused, encoded in whatever tooling mints your links.
Not legal advice
This is general information, not legal advice. The dates and figures here were verified at their primary sources on 2026-09-10, but penalty amounts are adjusted over time, guidance is revised, and your obligations depend on where your recipients are and what you send. Check the current text of each rule, read Flyn's terms and GDPR page, and talk to a qualified professional before relying on any configuration. Setting a lifetime policy for the first time? Create an account, put the compliance links on a domain you control, and leave the expiry field empty by default.
Frequently Asked Questions
Can an unsubscribe link legally expire?
Why can a one-click unsubscribe not be a short link?
Does a 410 response count as the link still working?
How long must a QR code on packaging keep working?
What about short links in SMS, is there a lifetime rule?
Can I expire a promotional link once the offer ends?
Do Gmail and Yahoo set a minimum link lifetime?
Has anyone actually paid for an unsubscribe link that stopped working?
Is this article legal advice, and how confident are the numbers?
Free tools for this
Three Flyn tools that pair well with the strategy in this article, all free, no signup needed.
Security Headers Checker
Audit HTTP security headers.
Redirect Checker
Trace 301/302 redirect chains.
URL Cleaner
Strip tracking params from any URL.
Keep reading
Three related deep-dives from the Flyn blog.
Retargeting Pixels and Consent: GDPR & CCPA
12 min read

Are Short Links Safe? How to Check Before You Click
13 min read
Does a Short Link Click Need Cookie Consent? Law by Law
31 min read
Ready to try Flyn?
Free plan includes 25 links/month, full analytics, and access to all 30+ free tools above. No credit card required.
Already a member? Log in

Karan Bhakuni is the founder of Flyn. He writes about branded links, click analytics, and the link-management tooling growth teams and creators actually need, drawn from building Flyn and reading a lot of user feedback.
Find these guides useful? Add Flyn as a preferred source so more of them show up in your Google results.