Skip to content
Your Rights

How to report a company that ignores your unsubscribe request

The click-by-click filing process: pull the full email headers, attach the dates, and report the sender to the FTC, your EU DPA, or the UK ICO.

Email Unsubscriber Team 8 min read
Flat vector illustration of a cream complaint form dropping into an official filing slot, beside a document of email headers, a magnifying glass, a calendar marked at day 11, and a shield.

You marked the date you unsubscribed. Ten business days went by. The same sender keeps dropping promos in your inbox, and now you want to do more than sigh and delete. This is the filing process, step by step: what to collect, where to send it, and what happens after you hit submit.

To report a sender that ignores your unsubscribe, file with your regulator and attach proof. In the U.S., report at reportfraud.ftc.gov with the email’s full headers, your opt-out date, and the dates of every message after the 10-business-day window. In the EU, file with your national data protection authority; in the UK, report to the ICO.

This is a practical filing guide, not legal advice. For the penalties, the statute, and the settlement record behind these rules, see your rights when ‘unsubscribe’ doesn’t stop the emails.

When has a sender actually crossed the line?

File only after the legal window has closed, or your complaint has no violation to point at. Under U.S. CAN-SPAM, a commercial sender has 10 business days to honor your opt-out. A Gmail or Yahoo bulk sender gets 48 hours under those providers’ deliverability rules. Under EU and UK law, withdrawal must be honored without undue delay, which a modern system should treat as near-immediate.

The date you clicked is the whole case. Emails that arrive inside the window are legitimate timing artifacts, and reporting them wastes your effort and the regulator’s. Emails that arrive after it are the violation you file on. For the exact day-counting (weekends and holidays do not count toward the 10), read how long a company can email you after you unsubscribe. Once you are past day 10 and the mail keeps coming, you have something to report.

What evidence do you need before you file?

Collect four things. A regulator acts on documented timelines, not annoyance, so assemble this before you open any complaint form:

  • The date you first unsubscribed. A screenshot of the confirmation page, or the “you have been removed” email, timestamps your opt-out. If you used your provider’s native unsubscribe, the date you clicked is enough.
  • The dates of every email after the window. List each message that landed past the 10-business-day (or 48-hour) mark. Two or three post-window emails from the same sender show a pattern, not a fluke.
  • The full headers of at least one offending email. Headers carry the real sending domain, the routing path, and the send timestamp. The next section shows how to pull them.
  • A screenshot of the unsubscribe page, if it demanded more than your email. CAN-SPAM bars a sender from making you log in, pay a fee, or hand over extra details to opt out. A page that does is a second violation on its own.

Keep the original messages intact in a folder. Do not delete them and do not forward-and-delete, or the headers vanish with the message.

How do you pull the full email headers?

Headers are the evidence a regulator can verify, and every major client hides them one menu deep. Here is the extraction for the three you are most likely using:

  1. Gmail. Open the message. Click the three-dot More menu next to the Reply arrow, then choose Show original. A new tab shows the full raw headers with a Copy to clipboard and a Download Original button. Google documents this on its trace-an-email page.
  2. Outlook on the web. Open the message, click the three dots () at the top right, choose View, then View message source. The raw headers open in a panel you can select and copy.
  3. Outlook desktop. Double-click the message to open it in its own window, then go to File then Properties. The Internet headers box at the bottom holds the full header text. Microsoft covers this on its internet-message-headers page.

If a form asks you to attach the email rather than paste text, forward it as an attachment (not a normal forward, which strips the original headers). The result: a copy of the raw headers you can paste into any complaint form or hand to any regulator.

How do you file a complaint with the FTC?

Report at reportfraud.ftc.gov, the FTC’s central intake for consumer complaints. The flow takes a few minutes:

  1. Click Report Now. The site opens with a short set of questions to route your report.
  2. Pick the category that fits. Choose the option covering unwanted or spam email and continue.
  3. Describe what happened. Paste the full headers you copied and write the timeline in plain language: the sender’s From address, the date you first unsubscribed, and the dates of every email that arrived after the 10-business-day window.
  4. Add your contact details. These are optional in parts, but an email address lets the FTC send your report confirmation.
  5. Submit. You get a report number on screen, and a copy by email if you supplied an address.

The FTC’s CAN-SPAM guide sets the 10-business-day rule your complaint rests on, and the FTC’s 2025 penalty schedule puts the ceiling at $53,088 per non-compliant email, a figure the agency has held in place for 2026. Your report becomes one line in the case a regulator can build.

What happens after you file with the FTC?

Nothing lands in your inbox, and that is normal. The FTC does not resolve or reply to individual reports. It routes every complaint into the Consumer Sentinel Network, a secure database that federal, state, local, and international law enforcement agencies use to track fraud.

Cases get built from volume. When enough reports name the same sender, investigators see the pattern and can act on it. The FTC’s own record proves the mechanism: the Experian and Verkada CAN-SPAM settlements grew out of accumulated complaints, not a single dramatic filing. Your report will not trigger a phone call, and it is not supposed to. It is a data point in a case file that a sender’s next hundred violations will thicken.

How do you report in the EU?

File with your national data protection authority. The European Data Protection Board maintains a directory of every member DPA with names, addresses, and contact links, covering all 27 EU states plus Iceland, Liechtenstein, and Norway. Pick the authority for the country you live in.

The legal footing is stronger here than in the U.S. Under GDPR Article 7(3), you may withdraw consent at any time, withdrawing it must be as easy as giving it was, and processing must stop without undue delay. A sender that keeps emailing after you opt out, or that forces you through a login or a form to leave, breaches the rule. Attach the same evidence you gathered for the FTC. Unlike the FTC, DPAs do investigate individual complaints and hold direct enforcement power over companies operating in their jurisdiction.

How do you report spam in the UK?

Report to the Information Commissioner’s Office through its report-spam-emails form. Unsolicited marketing email falls under the Privacy and Electronic Communications Regulations (PECR), which require your consent before a sender markets to you, with a narrow “soft opt-in” exception for existing customers. The form asks for the sender, the dates, and the message details.

The ICO does not reply to complaints one by one. It uses the reports to spot senders worth investigating and to prioritize enforcement. The teeth got sharper in 2026: the Data (Use and Access) Act 2025 raised the maximum PECR fine to £17.5 million or 4 percent of global annual turnover, whichever is higher, effective 5 February 2026, up from the old £500,000 cap. A single report will not move a regulator, but it joins the pattern that does.

How should you preserve the evidence?

Keep the raw material where a regulator’s timeline can rest on it. The complaint form captures a snapshot, but if an investigator ever follows up months later, you want the originals. Build a small record and leave it alone:

  • Keep the offending emails in a dedicated folder, unread-status untouched, never deleted. The headers only survive inside the intact message.
  • Save the header text separately as a plain file per email, named with the sender and date, so you are not re-extracting it later.
  • Log a simple table: sender address, date you first unsubscribed, and each date a message arrived afterward. Three columns are enough to make the violation legible at a glance.
  • Screenshot the unsubscribe page if it asked for more than your email, since that page can change or disappear.

Documented timestamps are the difference between a complaint a regulator can act on and one it files away. Without them, no agency can move.

How do you track which senders ignored you?

Tracking who honored the opt-out and who blew past it is the tedious part of this whole process. You unsubscribe from dozens of lists in one sitting, and two weeks later you cannot recall which sender is now in violation and which quietly complied.

That record-keeping is what the Email Unsubscriber app is built to keep. It scans your inbox in your browser, so your email content never reaches our servers, dispatches one-click unsubscribes, logs every action with its date in an audit history, and flags any sender still mailing you after you opted out with a “Still Emailing” marker. The senders who ignore the 10-day rule stop being invisible, which is the timeline you paste into the complaint form. It is a one-off payment, with nothing to cancel.

Frequently asked questions

How do I report a company that keeps emailing after I unsubscribe?

Wait until the legal window closes, then file with your regulator and attach proof. In the U.S., report at reportfraud.ftc.gov with the email's full headers, the date you first opted out, and the dates of every message that arrived after the 10-business-day deadline. In the EU, file with your national data protection authority; in the UK, report to the ICO.

Where do I report spam emails in the US?

Report to the Federal Trade Commission at reportfraud.ftc.gov. Click Report Now, pick the category that fits, and paste the offending email's full headers plus the timeline into the description. You get a report number, and the FTC feeds it into the Consumer Sentinel Network, a database that law enforcement agencies across the country can search.

How do I get the full headers of an email to report it?

In Gmail, open the message, click the three-dot More menu next to Reply, and choose Show original, then Copy to clipboard. In Outlook on the web, open the message, click the three dots, choose View, then View message source. In Outlook desktop, open the message and go to File then Properties to read the Internet headers box.

Does the FTC respond to individual spam complaints?

No. The FTC does not resolve or reply to individual reports. It aggregates them in the Consumer Sentinel Network and opens cases when a pattern emerges against the same sender. The Experian and Verkada CAN-SPAM cases were built from accumulated complaints, so filing yours adds weight even without a personal response.

How do I report unwanted marketing emails in the EU?

File a complaint with your national data protection authority. The European Data Protection Board keeps a directory of every member DPA with contact links. Attach the same evidence: the full email headers, your opt-out date, and the later message dates. Unlike the FTC, DPAs investigate individual complaints and hold direct enforcement power over companies in their jurisdiction.

How do I report spam emails to the ICO in the UK?

Use the ICO's report-spam-emails form. It asks for the sender, the dates, and details of the messages. The ICO does not reply to complaints individually, but it uses the reports to spot patterns and enforce PECR. Since February 2026 the maximum PECR fine is 17.5 million pounds or 4 percent of global turnover, whichever is higher.

What evidence do I need to report an unsubscribe violation?

Four things: the date you first unsubscribed, the dates of every email received after the legal window closed, the full headers of at least one of those later emails, and a screenshot of the unsubscribe page if it demanded more than your email address. Keep the original messages intact; do not delete them or the headers disappear with them.

Is it worth reporting a company for ignoring an unsubscribe?

Yes, even though you will not get a personal reply. Regulators build enforcement cases from volume, so each documented complaint against a repeat sender counts toward the case file. Blocking the sender stops the mail reaching you today, and reporting feeds the record that eventually forces the sender to comply or pay.