Reference
Email course statistics, with every source
Last reviewed 20 September 2026
Google asks bulk senders to keep spam complaints under 0.10 per cent and never to reach 0.30 per cent. Google and Yahoo have required SPF, DKIM, DMARC, one-click unsubscribe in the headers and a two-day unsubscribe window since February 2024. A fifth to a third of sign-ups never confirm. One in ten to one in four confirmed readers click on the final day of a five-day course. Counted here on the 1,000 most visited domains: 730 publish DMARC and 613 of those enforce it.
This is a reference page rather than an argument: the figures an email course is planned against, each one with the document it comes from, the date that document carries and the day this page last read it. Where a number is a rule somebody enforces it says so, and where it is a planning band that moves with your audience it says that instead, because those two things are quoted identically and mean nothing alike.
Two habits make the difference between a number that is worth quoting and one that is not. The first is naming the denominator. A spam complaint rate is complaints divided by the mail a provider ACCEPTED from you, not by the size of your list, so it behaves worse the smaller you are: on a mailing of a thousand delivered messages, three complaints is already the level Google asks you never to reach. The second is saying who published it. A threshold a mailbox provider enforces by filtering your mail and a conversion band somebody averaged out of other people’s campaigns are different kinds of object, and a page that prints them in the same column without saying which is which has made the reader’s job harder while looking more authoritative.
So each figure below carries a kind. A rule is written down by a provider or in law and has a date it took effect. A threshold is a number a provider publishes and acts on. An observed constant is measured rather than documented — nobody publishes it, it has held for years, and it can move without an announcement. A band is a planning range: wide on purpose, moving with who your reader is rather than with anything you can edit, and useful mainly for telling you which stage of your own funnel is broken. Nothing here is a forecast of what your course will do.
Every figure is also published elsewhere on this site, in the guide that explains it at length, and the two are held in step mechanically: one test collects every claim on every page here and fails when two of them state the same guideline differently. That is not a courtesy. This site has twice shipped two different answers to one question — the visible length of a subject line, and the share of sign-ups lost at the confirmation click — and both times the contradiction was on the page a reader was most likely to quote.
The thresholds that decide whether your mail arrives
Google asks bulk senders to keep the spam complaint rate reported in Postmaster Tools below 0.10 per cent and never to reach 0.30 per cent, and applies its bulk requirements from about 5,000 messages a day to Gmail addresses from one domain.
These are the only figures on this page that somebody enforces against you, and they are enforced by filtering rather than by a letter, so the first sign of a problem is usually a quiet fall in delivery. Both numbers are rates against mail the provider accepted from your domain, which is the detail that catches small senders: the same three complaints that are invisible on a list of a hundred thousand are the whole budget on a mailing of a thousand.
A small sender has no statistical cushion, only a structural one. That is the argument for confirmed opt-in stated as arithmetic rather than as principle: a handful of addresses that never really asked for the mail is a rate breach on a small list and a rounding error on a large one.
| What it answers | The figure | What kind of number | What is measured, and against what | Source |
|---|---|---|---|---|
| What spam complaint rate should a sender aim under? | 0.10 per cent | Threshold | Spam reports as a share of the mail Gmail accepted from your sending domain, as Postmaster Tools reports it. | |
| What spam complaint rate must a sender never reach? | 0.30 per cent | Threshold | The same rate, against mail delivered rather than against the size of the list. Yahoo publishes the same ceiling. | Google, Yahoo |
| How many complaints is that on a small mailing? | Three per thousand delivered | Threshold | The 0.30 per cent ceiling above, applied to a single mailing of a thousand delivered messages. | |
| What counts as a bulk sender? | About 5,000 a day | Rule | Messages sent to Gmail addresses from the same domain within 24 hours. Google applies its stricter requirements above that line. | |
| What happens to unauthenticated mail? | Refused, not filtered | Rule | Mail with no valid SPF or DKIM, at any volume. Gmail returns the SMTP error 5.7.26 rather than accepting the message into a spam folder. |
What these figures do not say
- 0.10 per cent
- This is the target rather than the ceiling, and the gap between the two is deliberate: a rate that sits at the ceiling has no room for one bad send.
- 0.30 per cent
- Reaching it is not a warning, it is the point at which filtering follows. Neither provider publishes what the window is or how long recovery takes.
- Three per thousand delivered
- Below a thousand it gets sharper still: on two hundred delivered messages one complaint is already half a per cent. The rate is the published figure; this row is only that figure divided out.
- About 5,000 a day
- The authentication floor applies below it too, at any volume, so a small sender is exempt from the list rather than from the rules that matter.
- Refused, not filtered
- A refusal is a bounce your sending platform sees, which is the one failure in this group that is visible immediately instead of by inference.
What a sender is required to do
Since February 2024, Google and Yahoo have both required SPF and DKIM on the sending domain, a DMARC record on the From domain, one-click unsubscribe in the message headers as RFC 8058 defines it, a visible unsubscribe link in the body, and any unsubscribe request honoured within two days.
Two sets of rules apply at once and they are not the same kind of thing. The mailbox providers publish requirements and enforce them by deciding where your mail lands; the law sets requirements and is enforced by a regulator. Where the two overlap, the providers ask for more and ask for it faster, so meeting the providers is what meeting the law looks like in practice.
The February 2024 date matters because it is when the two largest consumer mailbox operators published the same list at the same time, which moved this set of practices from advisable to load-bearing. Neither document has a version number, so the date belongs to the requirements rather than to the page they are written on.
| What it answers | The figure | What kind of number | What is measured, and against what | Source |
|---|---|---|---|---|
| What authentication is required? | SPF, DKIM and DMARC | Rule | SPF and DKIM on the sending domain from every sender; a DMARC record on the From domain from bulk senders. Required by Google and Yahoo since February 2024. | Google, Yahoo, The IETF |
| What does one-click unsubscribe actually require? | Two headers and a POST | Rule | List-Unsubscribe carrying an https URI, plus List-Unsubscribe-Post: List-Unsubscribe=One-Click. The mail client then POSTs to that URI, and RFC 8058 requires the unsubscribe to happen with no further interaction from the reader. | The IETF, Google, Yahoo |
| How quickly must an unsubscribe be honoured? | Two days | Rule | The window Google and Yahoo have both required since February 2024, counted from the request. | Google, Yahoo |
| How long does United States law allow for an opt-out? | 10 business days | Rule | The CAN-SPAM opt-out window, as the FTC compliance guide states it. It applies to every commercial message sent to a United States address, with no consent requirement and no small-sender exemption. | The United States Federal Trade Commission |
| How long must an unsubscribe link keep working? | At least 30 days | Rule | Counted from when the message was sent. The FTC guide also requires the mechanism to charge no fee and to ask for nothing beyond the address. | The United States Federal Trade Commission |
| What has to be in the footer? | A valid postal address | Rule | A street address, a registered post office box or a private mailbox with a commercial mail receiving agency, plus a clear explanation of how to opt out, in every commercial message. | The United States Federal Trade Commission |
| What does the GDPR require consent to be? | Freely given, specific, informed, unambiguous | Rule | Article 4(11), which also requires a statement or a clear affirmative action. Article 7(1) puts the burden of proof on the sender: you must be able to demonstrate that the person consented. | The European Union |
| How easy does withdrawing consent have to be? | As easy as giving it | Rule | Article 7(3): consent may be withdrawn at any time, withdrawal must be as easy as giving consent, and people must be told so before they consent. | The European Union |
What these figures do not say
- SPF, DKIM and DMARC
- The three do different jobs: SPF authorises servers, DKIM signs the message, DMARC ties both to the address a reader sees. Two out of three is not two thirds of a pass.
- Two headers and a POST
- A message with the first header and not the second does not have one-click unsubscribe, whatever the sending dashboard reports. No confirmation page, no preferences screen and no login is the requirement, not a preference.
- Two days
- It is an outer limit rather than a target, and the providers enforce it by filtering your mail rather than by writing to you. Removing the address before answering the request makes the window irrelevant.
- 10 business days
- Far longer than the providers allow, so it is the weaker of the two clocks and not the one that decides whether you have a problem.
- At least 30 days
- This is the requirement a sending platform breaks by rotating a token, and the one a reader meets as a dead link in a message from last month.
- A valid postal address
- It is also why a clipped message is a compliance problem and not only an aesthetic one: the parts that have to be reachable live at the bottom.
- Freely given, specific, informed, unambiguous
- The text names no mechanism, sets no retention period and does not contain the phrase double opt-in. What it does is define consent and make you the one who has to prove it.
- As easy as giving it
- An unsubscribe that takes more steps than the sign-up form did is the everyday version of failing this, and it is also what generates the complaints the first group of figures measures.
What the most visited domains actually publish
Resolved on 20 September 2026 across the 1,000 highest-ranked domains of Tranco list PY96J: 764 of 1,000 publish an SPF record and 730 of 1,000 publish a DMARC record, and 613 of those 730 DMARC records ask for failing mail to be quarantined or rejected rather than sitting at p=none. These are this page’s own counts rather than anybody else’s figures, and the sample, the resolver and every selector queried are printed under the table so the run can be repeated.
Every other figure on this page is somebody else’s, which is both the strength of the rest of it and the limit: each one can be checked by following a link, and each one can also be got without coming here. This group is the opposite. It is a count of what a defined, public, permanently addressable list of domains had in their DNS on one morning, so none of it can be looked up anywhere else, and all of it can be repeated by anybody who wants to disagree.
The result that argues with the received account is the policy column. The usual claim is that DMARC in the wild is decorative — published at p=none to satisfy a requirement and left there. On this sample it is not: of the domains that publish DMARC at all, 613 of 730 ask for enforcement and 444 of 730 are at p=reject outright. What is missing is not the policy, it is the record. More than a quarter of the most visited domains in the world publish no DMARC record at all, and a domain with no DMARC record is a domain anyone can put in a From line.
Two limits decide how far these counts reach. The sample is the most visited websites rather than the largest senders: it contains content-delivery and interface domains that never send a message, and none of the small sending domains an email course actually runs on. And DKIM selectors are not enumerable — no query lists the selectors a domain has published, and a great many are generated per account — so the DKIM row is a floor taken from 24 named selectors the large platforms publish under, never a share. A domain missing from it may sign every message it sends.
| What it answers | The figure | What kind of number | What is measured, and against what | Source |
|---|---|---|---|---|
| How many of the most visited domains publish an SPF record? | 764 of 1,000 | Measured here | Domains with at least one v=spf1 TXT record at the apex, out of the 1,000 highest-ranked domains of Tranco list PY96J, resolved on 20 September 2026. | This page’s own run, Tranco, The IETF |
| How many of those SPF records end in a hard fail? | 443 of 764 | Measured here | Records ending -all, which asks a receiver to reject mail from anywhere the record does not list, out of every domain in the sample that publishes an SPF record. | This page’s own run, Tranco, The IETF |
| How many publish more than one SPF record? | 3 of 1,000 | Measured here | Domains with two or more TXT records at the apex beginning v=spf1. RFC 7208 section 4.5 makes that a permanent error rather than two policies, so SPF evaluates to an error for every message. | This page’s own run, Tranco, The IETF |
| How many publish a DMARC record? | 730 of 1,000 | Measured here | Domains with a v=DMARC1 TXT record at _dmarc, out of the same sample. Google and Yahoo have both required one from bulk senders since February 2024. | This page’s own run, Tranco, The IETF |
| How many of those DMARC records ask for enforcement? | 613 of 730 | Measured here | Records at p=quarantine or p=reject rather than p=none, out of every domain in the sample that publishes a DMARC record. Not out of the sample. | This page’s own run, Tranco, The IETF |
| How many are at p=reject? | 444 of 730 | Measured here | Records at p=reject, which asks a receiver to refuse mail that claims the domain and cannot prove it, out of every domain in the sample that publishes a DMARC record. | This page’s own run, Tranco, The IETF |
| How many DMARC records collect no reports at all? | 48 of 730 | Measured here | Records carrying no rua= address, so no receiver has anywhere to send an aggregate report, out of every domain in the sample that publishes a DMARC record. | This page’s own run, Tranco, The IETF |
| How many publish a DKIM key at a well-known selector? | 456 of 999 | Measured here | Domains publishing a non-empty key at one of the 24 named selectors probed, out of the domains where every one of those probes was answered. A floor, not a share. | This page’s own run, Tranco, The IETF |
| How many have SPF, DMARC and a discoverable DKIM key? | 449 of 999 | Measured here | Domains publishing SPF, publishing DMARC and answering at one of the probed selectors, out of the domains where all three questions were answered. | This page’s own run, Tranco, The IETF |
What these figures do not say
- 764 of 1,000
- A domain whose query returned no definitive status would have been dropped from the denominator rather than counted as publishing nothing, because a timeout is not an absence. On this run, after a second pass at the ones that first failed, every domain answered.
- 443 of 764
- The rest end ~all, which asks a receiver to accept the mail and note the failure, end ?all, which asks for nothing at all, or hand the decision to another record with redirect=. A soft fail is the safer starting point and the worse resting place.
- 3 of 1,000
- Rare, and it is the failure that looks most like success: both records are visible and correct-looking in a DNS panel, nothing reports an error, and the effect is that the domain has no working SPF at all.
- 730 of 1,000
- More than a quarter of the most visited domains in the world publish none. A domain with no DMARC record is a domain anyone can put in a From line, and the root domain is usually the one worth impersonating.
- 613 of 730
- The denominator is the point. Against the whole sample the same count is a minority, and against the domains that publish DMARC it is most of them: those are different claims and the second is the one this row makes.
- 444 of 730
- Nothing in the bulk sender requirements asks for reject: a record at p=none satisfies both providers. Reject is what stops other people sending as you, which is a separate benefit and a separate decision.
- 48 of 730
- A small share, and it is the one mistake that hides all the others: a policy set without reports is a policy set without evidence, and the reports are the only place mail failing in your name is visible.
- 456 of 999
- This is the one figure on this page that cannot be read as an absence. Selectors are not enumerable, so a domain missing from this count may sign every message it sends under a label nobody outside it can guess, and many large platforms mint one per account.
- 449 of 999
- Bounded below by the DKIM floor above, so the real figure is higher by however many domains sign under a selector this run did not probe. It is printed as a floor because that is the honest version of the full-set question.
How this was measured, and what it cannot tell you
- The sample
- The 1,000 highest-ranked domains of Tranco list PY96J. Tranco aggregates the rankings published by Crux, Farsight, Majestic, Radar and Umbrella over the 30 days from 21 August 2026 to 19 September 2026, combines them with the Dowdall rule, and keeps only pay-level domains. List PY96J was generated on 19 September 2026 and is permanent: a Tranco list with an id is never regenerated, so the identical ranking can be downloaded from the same address at any time and these are its first 1,000 entries.
- The queries
- Resolved on 20 September 2026 with
digagainst 1.1.1.1, retried twice, falling back to 8.8.8.8: a TXT query at the apex for SPF, a TXT query at_dmarcfor DMARC, an MX query at the apex, and a TXT query at<selector>._domainkeyfor each selector below. A query that returned neither NOERROR nor NXDOMAIN was recorded as unanswered and its domain dropped from the denominator of that figure, never counted as an absence. - The 24 DKIM selectors probed
default, dkim, mail, smtp, google, selector1, selector2, k1, k2, k3, s1, s2, sig1, mandrill, zoho, protonmail, protonmail2, ctct1, ctct2, everlytickey1, fm1, fm2, fm3, kl- What this cannot tell you
- DKIM selectors are not enumerable. No DNS query lists the selectors a domain has published, and a great many are generated per account — Amazon SES issues three random ones per identity — so probing named selectors can only ever establish a floor. A domain with no key at any of the selectors above may still sign every message it sends. The SPF and DMARC figures have no such limit: those records live at one known name each, so their absence is real. And this sample is the most visited websites, not the largest senders: it contains content-delivery and API domains that never send mail, and it contains none of the small sending domains an email course is likely to run on.
What happens at the sign-up form
A dedicated opt-in page for a course commonly converts 15 to 30 per cent of its visitors and an inline form in a sidebar or an article footer 1 to 3 per cent. Of the addresses submitted, a fifth to a third never confirm.
These are planning bands, not measurements, and they are wide because the thing that moves them most is who is looking at the page rather than what is on it. Somebody who followed a link that said five-day course had already made most of the decision; somebody who reached the bottom of an article came for the article. No work on the form changes which of the two is reading it.
The confirmation loss is the figure people try hardest to avoid paying, and it is the one worth paying. What fails to confirm is mistyped addresses, bot submissions and interest that did not survive thirty seconds, which is precisely the population that produces the complaints the thresholds above are measured in. Part of the loss is recoverable by saying on the page that a confirmation is coming, sending it immediately, and sending exactly one reminder a day later.
| What it answers | The figure | What kind of number | What is measured, and against what | Source |
|---|---|---|---|---|
| What does a dedicated opt-in page convert? | 15 to 30 per cent | Planning band | Addresses submitted as a share of people who reached a page whose only job is the course, before any validation. | 5dayemail.com |
| What does an inline form convert? | 1 to 3 per cent | Planning band | Addresses submitted as a share of readers of the page the form sits inside: a sidebar, a footer, or the end of an article. | 5dayemail.com |
| How many sign-ups never confirm? | A fifth to a third | Planning band | Submitted addresses that never click the link in the confirmation email, under confirmed opt-in, which is what most people mean by double opt-in. | 5dayemail.com |
What these figures do not say
- 15 to 30 per cent
- A band from published landing-page benchmarks, quoted and argued in the guide cited beside it. It describes pages with one promise and one field, not a page that also sells something.
- 1 to 3 per cent
- The gap to the figure above is mostly intent rather than design, which is why the highest-leverage change to an opt-in rate is upstream of the form.
- A fifth to a third
- Stated from the other side, 67 to 80 per cent of submissions confirm. The band is wide because it depends heavily on where the confirmation lands and whether the page warned that it was coming.
What happens across the five days
Of confirmed readers, plan for 20 to 40 per cent clicking on day one, 15 to 30 per cent on day three and 10 to 25 per cent on day five, which is one in ten to one in four finishing. Cumulative unsubscribes across a five-day course usually total 2 to 8 per cent of confirmed readers.
Engagement does not decay smoothly. It falls sharply from day one to day two, flattens across the middle, and often ticks up on the last day, because the subject line says the course is finishing and the readers still present have selected themselves. Reading day one as the baseline is the commonest way to misread your own numbers: it arrives while the reader is still looking at the inbox, having just clicked a confirmation link, and no later day will match it.
Completion is counted as a click and not as an open, and that is not a stylistic preference. Apple Mail Privacy Protection loads remote content through a proxy whether or not the reader looked at the message, so the pixel an open is measured by fires regardless. The resulting open rate is not noisy, it is wrong in a consistent and flattering direction. A click is an act somebody chose to perform, inflated a little by security scanners, so it is an upper bound rather than a headcount.
| What it answers | The figure | What kind of number | What is measured, and against what | Source |
|---|---|---|---|---|
| What share of confirmed readers click on day one? | 20 to 40 per cent | Planning band | Clicks on the single link in the first lesson, as a share of readers who confirmed. The high point of the sequence. | 5dayemail.com |
| What share of confirmed readers click in the middle of the course? | 15 to 30 per cent | Planning band | Clicks on day three as a share of readers who confirmed, after the day-two fall. | 5dayemail.com |
| What completion rate should a five-day course expect? | 10 to 25 per cent | Planning band | Clicks on the final day as a share of readers who confirmed: one in ten to one in four. Longer courses sit lower. | 5dayemail.com |
| How many people leave during a five-day course? | 2 to 8 per cent | Planning band | Cumulative unsubscribes by the last day, as a share of readers who confirmed. | 5dayemail.com |
| Why not measure any of this with open rates? | Opens are unmeasurable | Rule | Apple Mail Privacy Protection routes remote image loads through a proxy whether or not the message was opened. Apple states plainly that the feature stops senders knowing when mail has been opened. | Apple |
What these figures do not say
- 20 to 40 per cent
- It arrives seconds after a confirmation click, which is why it is not a baseline for anything that follows.
- 15 to 30 per cent
- The flat part. Days three and four shed few readers, because the people still there have a habit and the end is in sight.
- 10 to 25 per cent
- Several times smaller than any open-based figure, and it means something for that reason. The largest determinant is how well the opt-in page matched the person who signed up, which is decided before anybody reads a word.
- 2 to 8 per cent
- Much above that band means the opt-in page promised something the course is not delivering, which is a copy problem rather than a deliverability one.
- Opens are unmeasurable
- On any list with a substantial share of Apple Mail readers, and most consumer lists have one, the open rate rises when nobody reads anything.
What the inbox shows, and where it cuts
A phone reliably shows the first 30 to 40 characters of a subject line, and Gmail stops rendering a message at about 102,400 bytes and replaces the rest with a link.
Both of these are observed constants: nobody publishes them, they have held for years, and either could move without an announcement. They are here because they are the two figures that decide whether the writing is read at all, and because a page of sourced numbers that quietly omits the unsourceable ones is a page that has hidden its own limits.
The character figure is a pixel measurement being reported in characters, so it moves with the width of the letters you chose. Treat the narrowest inbox your readers use as the budget, and put the interesting word before the cut rather than trying to land exactly on it.
| What it answers | The figure | What kind of number | What is measured, and against what | Source |
|---|---|---|---|---|
| How much of a subject line does a phone show? | The first 30 to 40 characters | Observed | What iPhone Mail, held upright, displays before the line runs out. A desktop client with a reading pane shows roughly 60, and a wide browser window roughly 70. | 5dayemail.com |
| At what size does Gmail clip a message? | 102,400 bytes | Observed | The size of the message content, counted in bytes as UTF-8, at which Gmail stops rendering and appends a "View entire message" link. That is where the familiar 102 KB figure comes from. | 5dayemail.com |
What these figures do not say
- The first 30 to 40 characters
- An approximation of a pixel width, stated as one. The line itself can be longer; what it cannot be is a line whose point is at the end.
- 102,400 bytes
- Google does not document it, so it is an observed constant rather than a promise. Everything after the cut is still delivered and simply not on screen, including the unsubscribe link and the postal address.
How to read the four kinds of number
- Rule
- Written down by a mailbox provider or in law, with a date it took effect. Not advice: the provider enforces it by filtering your mail, and the regulator by other means.
- Threshold
- A number a provider publishes and acts on. Quoted with its denominator, because a rate measured against mail delivered is not a rate measured against a list.
- Observed
- Measured rather than documented. Nobody publishes it, it has held for a long time, and it can move without an announcement, so it is a working assumption rather than a promise.
- Planning band
- A range to plan against, wide on purpose. It moves with who your reader is far more than with anything you can edit, and its use is telling you which stage of your own funnel is broken.
- Measured here
- Counted on this page, by resolving DNS across a named public list of domains on a named day. Nobody else publishes it. The sample, the resolver and every selector queried are printed under the table, so the count can be repeated and disagreed with rather than believed.
Common questions
What spam complaint rate do Gmail and Yahoo allow?
Google asks bulk senders to keep the spam complaint rate reported in Postmaster Tools below 0.10 per cent and never to reach 0.30 per cent, and Yahoo publishes the same 0.30 per cent ceiling. Both are rates against mail the provider accepted from your domain rather than against the size of your list, so on a mailing of a thousand delivered messages three complaints is already the level to stay under.
What counts as a bulk sender?
Google applies its bulk sender requirements from about 5,000 messages a day to Gmail addresses from the same domain. The authentication floor applies at any volume: mail with no valid SPF or DKIM is refused rather than filtered, and Gmail returns the SMTP error 5.7.26 for it.
How quickly does an unsubscribe have to be honoured?
Google and Yahoo have both required two days since February 2024, and they enforce it by filtering your mail. United States law is far more generous: the FTC compliance guide gives 10 business days, and requires the unsubscribe mechanism to keep working for at least 30 days after the message was sent.
How many people never confirm their email address?
A fifth to a third of sign-ups never confirm, which is the band commonly cited for double opt-in and is a planning range rather than a measurement. Stated from the other side, 67 to 80 per cent of submitted addresses confirm. What is lost is concentrated in mistyped addresses, bot submissions and interest that did not survive thirty seconds.
How many of the most visited domains publish SPF, DKIM and DMARC?
Resolved on 20 September 2026 across the 1,000 highest-ranked domains of Tranco list PY96J, 764 publish an SPF record and 730 publish a DMARC record, of which 613 are at p=quarantine or p=reject rather than p=none. DKIM cannot be counted the same way, because selectors are not enumerable and no query lists them: 456 of the 999 domains whose probes were all answered had a key at one of 24 named selectors, which is a floor rather than a share.
What completion rate should a five-day email course expect?
Measured as a click on the final day, plan for 10 to 25 per cent of confirmed readers, which is one in ten to one in four, with longer courses lower. Measure it with a click rather than an open: Apple Mail Privacy Protection loads remote content through a proxy whether or not the message was opened, so open rates rise when nobody reads anything.
The value of a benchmark is not the number. It is that it tells you which stage is actually broken, so you stop rewriting day four when the problem is a confirmation email nobody can find — and it only tells you that if you know which figures somebody enforces, which are measured, and which are a wide band somebody averaged. That is why every row above says which it is, and why a figure this page could not source is not on it.
Sources, with what each one is dated
- Google, Email sender guidelinesUndated and revised without notice. The requirements it sets out have applied since February 2024. Read on 19 September 2026.
- Yahoo, Sender best practicesUndated and revised without notice. Yahoo announced the same set of requirements as Google, for the same February 2024 date. Read on 19 September 2026.
- The IETF, RFC 8058: signalling one-click functionality with the List-Unsubscribe headerPublished 2017. A standards-track RFC is never edited; it is replaced by another. Read on 19 September 2026.
- The IETF, RFC 7208: Sender Policy FrameworkPublished 2014. Read on 19 September 2026.
- The IETF, RFC 6376: DomainKeys Identified MailPublished 2011. Read on 19 September 2026.
- The IETF, RFC 7489: Domain-based Message Authentication, Reporting and ConformancePublished 2015. Read on 19 September 2026.
- The United States Federal Trade Commission, CAN-SPAM Act: a compliance guide for businessThe Act dates from 2003 and has been in force since 2004. The guide itself is undated and revised without notice. Read on 19 September 2026.
- The European Union, Regulation (EU) 2016/679, the GDPR, full text on EUR-LexAdopted 27 April 2016 and applicable since 25 May 2018. Read on 19 September 2026.
- Apple, Use Mail Privacy Protection, in the iPhone User GuideThe feature arrived with iOS 15, in 2021. The guide is revised with each release. Read on 19 September 2026.
- 5dayemail.com, Email course conversion and completion rates: what to expectLast reviewed 18 September 2026. Read on 19 September 2026.
- 5dayemail.com, Email course subject lines: what an inbox showsLast reviewed 18 September 2026. Read on 19 September 2026.
- 5dayemail.com, Email size checker: the published methodology, including the clipping pointLast reviewed 18 September 2026. Read on 19 September 2026.
- Tranco, Tranco list PY96J, a research-oriented ranking of the most visited domainsGenerated 19 September 2026 from the thirty days to that date, and permanent: a Tranco list with an id is never regenerated or edited. Read on 20 September 2026.
Where these figures are explained
Each of these guides argues one group of the figures above at length, with the same sources.
- Email deliverability for small senders: what decides it
What deliverability is, how SPF, DKIM and DMARC fit together, and what the Google and Yahoo bulk sender rules require of a small sender.
- Unsubscribe requirements: one-click and List-Unsubscribe
What one-click unsubscribe requires under RFC 8058, the two-day honouring window in the Google and Yahoo rules, and what the endpoint must return.
- GDPR and email courses: consent, records, and erasure
What the GDPR text actually requires for an email list: consent under Art. 4(11), the burden of proof in Art. 7(1), erasure under Art. 17.
- CAN-SPAM for course senders: the footer checklist
The seven CAN-SPAM requirements from the FTC compliance guide, what they mean for an email course, and how the law differs from GDPR and CASL.
- Email course conversion and completion rates: what to expect
Realistic ranges for opt-in conversion, confirmation loss, day-by-day drop-off and completion, with a worked funnel from a thousand visitors.
- Confirmed opt-in (double opt-in): what it costs and buys
What double opt-in (confirmed opt-in) is, what it costs you in list size, and why the mailbox providers have settled the argument.
- Email course subject lines: the Day N of M pattern
Why a Day 2 of 5 prefix beats a clever subject line in a course, how long the rest can be on a phone, and twenty worked examples across three niches.
These pages are about the format rather than about any particular tool. The rest of the set is on the guides index , and what this site itself does is on the home page.
Thinking of writing one of these?
5dayemail hosts a five-to-ten day email course: you write it once, and everyone who joins your list gets one email a day, in order, starting from the day they confirm.
Accounts are opened a few at a time rather than by signing up. Leave your address and you will be written to when the next ones open.
One message, when there is room. No course emails, no newsletter, and the address is not passed on. Ask and it is deleted; what is kept, and for how long, is in the privacy policy.