Back to Blog

How Long Must a Link Keep Working? The Legal Minimums

You turned on link expiry because it felt tidy. Then someone tried to unsubscribe six weeks after the send and hit a dead page. Here is the minimum time each rule actually requires a link to keep answering, and which links you must never put behind an expiry date.

Karan Bhakuni
Karan Bhakuni
Founder, Flyn
SecuritySep 10, 202617 min readUpdated Sep 10, 2026
How Long Must a Link Keep Working? The Legal Minimums

The minimum lifetimes, rule by rule

No single law says "a link must work for N days". Several rules each demand a working route, and two attach an explicit number. Everything in this section was verified at the primary source on 2026-09-10.

Bar chart of minimum opt-out lifetimes: CAN-SPAM 30 days, CASL 60 days, UK PECR and the Gmail and Yahoo bulk rules with no stated day count, and the EU wine e-label reported as lasting the product's shelf lifeTap to enlarge
Only two of these rules name a number of days. The longest floor is the one with no number at all.

CAN-SPAM: thirty days, counted from each send

The FTC's own CAN-SPAM Act compliance guide for business is unambiguous: "Any opt-out mechanism you offer must be able to process opt-out requests for at least 30 days after you send your message." It also requires you to honor a request within 10 business days. Read those two together and the practical floor is 30 days of a working URL per message, rolling, because every send restarts its own clock. A weekly newsletter therefore has a continuously live 30 day window, not one window per quarter.

CASL: sixty days, written into the statute

Canada is stricter and puts the number in the law rather than in guidance. Section 11(2) of CASL requires the sender to ensure that the electronic address or web page used for the unsubscribe request "is valid for a minimum of 60 days after the message has been sent", and section 11(3) requires effect to be given to the request "without delay, and in any event no later than 10 business days". You can read the section on the Justice Laws site. If you send to Canadian recipients at all, 60 days is your real floor, because the stricter rule governs the shared asset.

UK PECR: no number, which is in some ways worse

Regulations 22 and 23 of the UK Privacy and Electronic Communications Regulations take a different shape. Regulation 22 turns on a simple means of refusing marketing, offered at the point of collection and in every subsequent message, and regulation 23 bars direct marketing email that gives no valid address to which the recipient can send a request that the communications cease. We are paraphrasing rather than quoting here, because legislation.gov.uk returned an empty document to us on 2026-09-10; read the regulation yourself before you cite it. Neither names a day count, and that does not give you latitude, it removes your ceiling. A refusal route that has gone dead is not a simple means of refusing, whether it died on day 31 or day 400. Separately, Article 7(3) of the UK and EU GDPR requires that withdrawing consent be as easy as giving it, and a 404 is not as easy as a tick box.

Gmail and Yahoo: not law, but they decide whether you are read

Mailbox providers publish their own rules and enforce them faster than any regulator. Gmail's email sender guidelines require senders above 5,000 messages a day to a Gmail address to include one-click unsubscribe headers, a requirement that took effect on 1 February 2024, and tell you that "Web links in the message body should be visible and easy to understand. Recipients should know what to expect when they click a link." Yahoo's sender best practices ask for a functioning list-unsubscribe header supporting one-click and say to "Honor unsubscribes within 2 days". Neither publishes a minimum lifetime for the URL, which in practice means the statutory floors above are the numbers you plan against.

The longest floors are physical, and they are written as accessibility duties rather than day counts. The ASA's note on QR codes in ads says it "will consider the wider context in which an ad appears, including where any links within an ad lead to". CAP rule 8.18 on promotional terms and conditions then lets a space-limited ad direct people to "an easily-accessible alternative source where all the significant conditions of the promotion are prominently stated". Read 8.18 as a lifetime rule, because a source that has expired is not easily accessible. EU wine labelling pushes the same duty out for years: under the ingredient and nutrition rules in Regulation (EU) 2021/2117 the e-label behind the QR code carries mandatory particulars, and Commission Notice C/2023/1190 is the interpretive guidance. Secondary readings of that notice put the duty at as long as the product remains suitable for consumption, years for a bottle, but EUR-Lex served us an empty document on 2026-09-10, so treat the shelf-life framing as unverified at source.

RuleChannelMinimum lifetimeClock startsIf the link dies
CAN-SPAM (US)EmailAt least 30 daysEach sendThe opt-out mechanism cannot process requests, per email
CASL s.11(2) (Canada)Email60 days, statutoryEach sendThe unsubscribe address is not valid for the required window
PECR reg 22 and 23 (UK)EmailNo day count statedOngoingNo simple means of refusing, no valid address for the request
Withdrawal of consent (UK and EU)Email, webFor as long as you rely on the consentConsent givenWithdrawal is no longer as easy as giving it
Gmail bulk sender rulesEmailNot statedNot statedHeader requirement unmet above 5,000 a day; delivery suffers
Yahoo sender rulesEmailNot stated; honour in 2 daysRequest receivedUnsubscribe is not functioning; complaints rise
TCPA and carrier rules (US)SMSNo published lifetime floorNot applicableThe link's shape is what is regulated, not its age
ASA and CAP rule 8.18 (UK)Print, QR, adsNo day count; the linked source must stay easily accessiblePublicationThe significant conditions of the promotion have no accessible source
EU wine e-labelLabel, packagingWhile the product is fit to drink (secondary reading, see the FAQ)Placing on marketMandatory particulars become unavailable to the buyer

The seven-point lifetime audit

Run this before a send, and once a quarter across everything already in market. It takes an hour the first time and ten minutes after that.

The seven checks

  1. List every link in the message and label each one: marketing, compliance, or legal notice. Only the first group is ever a candidate for expiry.
  2. Check the List-Unsubscribe header and confirm the URI is a direct HTTPS endpoint on your own host, not a shortener and not a redirect, and that both List-Unsubscribe and List-Unsubscribe-Post appear in the h= tag of your DKIM signature.
  3. Set the floor to 60 days if you mail anyone in Canada, 30 days otherwise, and then ask why you are expiring an opt-out route at all.
  4. Grep your expiring links for anything that has ever appeared in print, on packaging or in an ad, and remove the expiry from those.
  5. Repoint instead of expiring every offer link, and write the offer-ended page before the offer ends rather than after.
  6. Verify the hops resolve with the broken link checker and, for printed codes, the QR destination audit.
  7. Record the decision per link type in a one-page policy, so the next person on the team does not turn expiry back on for tidiness.
Pro tip

Give compliance links their own slug prefix, something like u-, legal- or label-, and make "no expiry on anything with these prefixes" a rule in your own process. A prefix is greppable in a way that an intention is not, and it survives staff turnover. Build them on a branded short link so the domain itself signals that the URL is yours and permanent.

Enforcement reality: where the cost actually lands

No regulator has fined anyone solely for an expired link, as far as we can find. That is a much narrower statement than it first reads, because the specific defect this post is about, an unsubscribe address that was not valid for the required 60 days, has already carried a price in Canada.

The Rogers Media undertaking, where the 60 day defect was priced

On 20 November 2015 the CRTC announced that Rogers Media Inc. had paid $200,000 as part of an undertaking to resolve alleged violations of CASL between July 2014 and July 2015. Three defects are named in the release, and one of them is this post's subject, word for word: "In addition, in some instances, the electronic address used to unsubscribe was allegedly not valid for the required minimum of 60 days following the sent message." The other two are commercial emails "containing an unsubscribe mechanism that did not function properly or which could not be readily performed by the recipient", and a failure to honour unsubscribe requests from some recipients within 10 business days.

Read the limits of that case honestly. It was an undertaking rather than a fine, the allegations were never proven, Rogers Media cooperated with the investigation and agreed to improve its compliance programme, and the 60 day defect travelled with two others, so nobody paid $200,000 for an expired link on its own. It is still the only named, priced enforcement action we can find that turns in part on how long an unsubscribe address stayed valid, and it happened in the one jurisdiction that puts the number in the statute rather than in guidance. If you need an answer to whether any of this has ever cost anyone anything, that is the answer.

Per-email arithmetic is the ceiling, not the evidence

Logarithmic bar chart of the CAN-SPAM statutory ceiling multiplied by send size: one email at 53,088 dollars, 1,000 emails at 53.1 million, 10,000 emails at 530.9 million, and 50,000 emails at 2.65 billionTap to enlarge
The per message ceiling is what turns a single broken opt-out route into a number nobody wants to read aloud. Statutory maximums, not outcomes: the only sum actually paid anywhere in this post is the $200,000 Rogers Media undertaking above.

CAN-SPAM penalties are assessed per message. The FTC's compliance guide states that "Each separate email in violation of the law is subject to penalties of up to $53,088", a figure that is adjusted for inflation, so check the current number before you rely on it. A single send to 50,000 addresses with a broken opt-out mechanism is therefore not one problem, it is 50,000 of them in the arithmetic, even though no regulator pursues the theoretical maximum. Canada works through administrative monetary penalties and negotiated undertakings instead, both administered by the CRTC, and the Rogers Media file above shows what a defective unsubscribe route is worth when one of those lands on you. Consent to the click tracking on those links is a different law and a different page: cookie consent for short-link click tracking covers PECR regulation 6 and the ICO's cookie enforcement, and the retargeting pixels and consent guide covers pixel fines.

The deliverability penalty arrives first, and it is worse

In practice the mailbox providers punish you long before a regulator writes to you. A dead unsubscribe route does not stop people wanting out, it makes them hit the spam button, and a rising complaint rate is the signal both providers act on. That suppresses your whole domain, not just the broken campaign. The same logic applies to links that look disposable: read why short links get flagged as spam alongside this.

A practical setup, and the disclaimer you should expect

You do not need a legal team to get this right. You need a policy that distinguishes marketing links from load-bearing ones, and a default that favours repointing over deleting.

A stack that survives an audit

  • A direct, permanent HTTPS unsubscribe endpoint on your own host, referenced in the List-Unsubscribe header with no redirect in front of it, with that header and List-Unsubscribe-Post both inside your DKIM h= tag.
  • Body links on your own branded domain, built so the destination can be edited without minting a new URL.
  • Expiry dates reserved for private file handoffs, applied deliberately rather than as a habit.
  • Offer-ended pages written in advance, so repointing is a one-minute job at the end of a campaign.
  • A quarterly sweep of printed and packaged codes, plus a spot check on anything a partner shortened for you.
  • A documented retirement rule: a slug you have distributed is never reused, encoded in whatever tooling mints your links.

This is general information, not legal advice. The dates and figures here were verified at their primary sources on 2026-09-10, but penalty amounts are adjusted over time, guidance is revised, and your obligations depend on where your recipients are and what you send. Check the current text of each rule, read Flyn's terms and GDPR page, and talk to a qualified professional before relying on any configuration. Setting a lifetime policy for the first time? Create an account, put the compliance links on a domain you control, and leave the expiry field empty by default.

Frequently Asked Questions

Can an unsubscribe link legally expire?
Not within the statutory window, and in practice you should treat it as permanent. CAN-SPAM requires your opt-out mechanism to be able to process requests for at least 30 days after you send the message, and CASL section 11(2) requires the unsubscribe address or web page to stay valid for a minimum of 60 days. Those are floors, not targets. Old emails get forwarded, archived and searched years later, and a recipient who cannot unsubscribe will report you as spam instead, which costs you more than the hosting. Keep the route live indefinitely and version the page behind it rather than the URL.
Why can a one-click unsubscribe not be a short link?
Because RFC 8058, the spec behind one-click unsubscribe, requires the List-Unsubscribe header to contain an HTTPS URI and explicitly says the sender must not return an HTTPS redirect, on the grounds that redirected POST requests have historically not worked reliably. We tested it on a live Flyn short link on 2026-09-10: posting the one-click body to the bare short domain returned 301, and posting to the canonical host returned 405 with an empty body, because the redirect route answers GET only. A client that follows the 301 turns the POST into a GET and fetches a page instead, which is the behaviour the RFC cites, so the unsubscribe is dropped either way. RFC 8058 also requires both List-Unsubscribe and List-Unsubscribe-Post to appear in the h= tag of the DKIM signature, or the receiver is told not to offer one-click at all. Put the endpoint itself in the header. Shortened links in the message body are fine.
Does a 410 response count as the link still working?
No. A 410 Gone is a correct technical signal that a resource was deliberately removed, which is precisely the problem if the resource was a compliance route. An expired Flyn link shows an expired page to browsers and returns 410 to crawlers, and that 410 is effectively a written admission that the mechanism no longer exists. If a regulator or a mailbox provider checks whether your opt-out route functioned, a 410 answers the question against you. Keep the address resolving with a 200 at the end of the hop and change what it resolves to.
How long must a QR code on packaging keep working?
Longer than almost anyone plans for. The ASA says it will consider the wider context in which an ad appears, including where any links within an ad lead to, and CAP rule 8.18 lets a space-limited promotion put its significant conditions on an easily accessible alternative source, which stops being accessible the moment the link expires. EU wine e-labels go further, because the page behind the code carries mandatory ingredient and nutrition particulars. Secondary readings of Commission Notice C/2023/1190 put the duty at as long as the product remains suitable for consumption, years for a bottle, though we could not confirm that wording at EUR-Lex. Never build a printed code on an expiring link.
What about short links in SMS, is there a lifetime rule?
No published lifetime floor that we could find. What SMS regulators and carriers actually regulate is the shape of the link: which domain it sits on, whether the path identifies the sender, whether the shortener is shared or dedicated, and whether the campaign is registered. That is a different question with different answers in each country, and it is covered separately in the guide to short link rules in SMS by country. The lifetime discipline still applies to whatever the text promised. If a message says reply STOP or points at a preference page, that destination has to keep working.
Can I expire a promotional link once the offer ends?
Expire the offer, not the link. Keep the slug resolving and repoint it at a page that says the promotion has closed and offers the next best thing. That keeps every forwarded email, screenshot and printed code functional, preserves the click data, and avoids the situation where a customer who saw your ad last week lands on an error. Expiry dates earn their place on private file handoffs, internal shares and one-time downloads, where the point of the link is that it stops. For everything you broadcast, editing the destination is the correct control.
Do Gmail and Yahoo set a minimum link lifetime?
Neither publishes one. Gmail requires one-click unsubscribe headers for senders above 5,000 messages a day to Gmail addresses, effective 1 February 2024, and says links in the body should be visible and easy to understand so recipients know what to expect. Yahoo asks for a functioning list-unsubscribe header and says to honour unsubscribes within two days. Both are about function and speed rather than duration, so the statutory 30 and 60 day floors remain the numbers you plan against. The practical effect of ignoring them is filtering, which arrives far faster than any regulatory letter.
Has anyone actually paid for an unsubscribe link that stopped working?
Once, that we can find, and it was in Canada. On 20 November 2015 the CRTC announced that Rogers Media Inc. had paid $200,000 as part of an undertaking to resolve alleged CASL violations between July 2014 and July 2015. One of the three named allegations is that, in some instances, the electronic address used to unsubscribe was allegedly not valid for the required minimum of 60 days following the sent message. The other two were an unsubscribe mechanism that did not function properly or could not be readily performed, and a failure to honour requests within 10 business days. It was an undertaking rather than a fine and the allegations were never proven, so nobody has been fined purely for an expired link, but the 60 day defect has been named in a priced enforcement action.
Is this article legal advice, and how confident are the numbers?
It is general information, not legal advice. The CAN-SPAM thirty day window and the penalty figure come from the FTC compliance guide, the sixty days from CASL section 11(2) in the statute, and the Gmail and Yahoo requirements from their own sender documentation, all checked on 2026-09-10. One item is weaker: we could not retrieve the exact wording of the EU wine e-label availability question from EUR-Lex on that date, so the shelf-life framing comes from secondary readings of Commission Notice C/2023/1190. Open the notice before you rely on it, and consult a qualified professional for your own obligations.

Ready to try Flyn?

Free plan includes 25 links/month, full analytics, and access to all 30+ free tools above. No credit card required.

Already a member? Log in

Karan Bhakuni
Karan Bhakuni· Founder, Flyn

Karan Bhakuni is the founder of Flyn. He writes about branded links, click analytics, and the link-management tooling growth teams and creators actually need, drawn from building Flyn and reading a lot of user feedback.

Find these guides useful? Add Flyn as a preferred source so more of them show up in your Google results.