iCloud+ Hide My Email addresses will remain on icloud.com

(developer.apple.com)

597 points | by K7PJP 1 day ago

31 comments

  • kqp 1 day ago
    This is a huge selling point. Private email relays often get blocked, the only lasting solution is to put them on the same domain as, and in the same format as, a significant number of non-private email addresses. As far as I’m aware the only other provider doing this is Fastmail.

    Comments about lock-in aren’t wrong, but it has to be this way. You can make arbitrary email addresses at your own domain, but anybody who feels like it can trivially automatically detect that those are all you.

    Personally I use unique at own domain only where I’m identifying myself anyway, like my bank, and Fastmail masked email where I’m not. For most things it’s not actually that terrible to accept a small risk that they’re offline for a day between your being booted without warning and you changing your email address with them.

    • glenngillen 1 day ago
      Totally agree with unique at own domain isn't actually privacy. It wouldn't take much of a paper trail to work out the details.

      I continue to use it everywhere for a few reasons:

      - if someone emails me acting all friendly like we've had some previous relationship but it's sent to linked@mydomain or github@mydomain I know they've just scraped my contact details and it's spam

      - similarly, if a vendor leaks or sells my data and I start receiving marketing from somewhere I don't expect it's easier to trace the source of the leak (and in some cases just blackhole that entire email address)

      - I already use a password manager and have different passwords on every site, but having a different email address too raises the barrier further for someone trying to script an automated attack based off some other pwned data set.

      • cube00 1 day ago
        > - similarly, if a vendor leaks or sells my data and I start receiving marketing from somewhere I don't expect it's easier to trace the source of the leak (and in some cases just blackhole that entire email address)

        This is exactly why I do it, it's eye opening to see exactly which companies leaked your address. As a result of being able to blackhole the leaked addresses I no longer get any spam, the Dvorak dream.

        I actually caught a company outright selling my address to AWS of all places, I didn't even know Amazon purchased mailing lists.

        AWS were crafty because they didn't directly sell a service, they only offered "resources" for "business leaders" because they knew nothing about what I might need.

        Explore the AWS [REDACTED] where business leaders can access eBooks, guides, and customer stories to find practical advice on building or improving upon a data strategy. Learn how you can leverage data as a strategic asset, make better decisions with insights from data, and innovate faster.

        • serbuvlad 1 day ago
          I find this very interesting in 2026.

          I use my gmail address for everything and I don't really get spam (except from services I've subscribed to legitimately but haven't bothered to configure to not send promotional mail).

          I never really get promotional mail from 3rd parties at all.

          Is this just gmail filters being very good?

          • Corrado 22 hours ago
            Yes, gmail filters are VERY good.
            • jjav 3 hours ago
              Hard disagree. Unless by "good" you mean that a third of your legitimate email is shoved in spam by gmail. That is not good, by any measure.

              Even the simplest bayesian filter will score better than gmail.

            • IndySun 12 hours ago
              >Yes, gmail filters are VERY good.

              But might gmail junk filters be the best junk mail filters for nefarious proprietary reasons, possibly?

          • windowliker 23 hours ago
            Gmail filters are very good. But if someone with the same name as you starts using your e-mail address for everything because they don't understand or care about needing to see the e-mails they receive then there's very little you can do to stop it other than unsubbing from lists they sign up for (where possible).

            I've been getting someone else's e-mail traffic for about 5 years now, on two separate Gmail accounts, and while occasionally hilarious, it is somewhat scary to see how much I can know about their lives from the type of e-mails they get. I have replied to inform some of the senders about the situation with the suggestion that they could tell the other person involved to use a new e-mail address, but it is still happening. You'd think that they would need to see some of the important work-related mail they receive yet they are apparently utterly oblivious.

            I occasionally also get similar mail to my own domain through a catch-all filter.

            It's quite funny how little some people understand about what an e-mail address is, or how it's supposed to be used, even today.

            • cube00 23 hours ago
              > very little you can do to stop it other than unsubbing from lists they sign up for (where possible)

              It certainly felt that way when someone was giving my GMail out to the cashier at the hardware store where I got no end of digital receipts which I couldn't unsubscribe from because they're providing the email address to the cashier each time. As they were receipts from a large verified brand Google treated them with the highest priority.

              • radlad 19 hours ago
                You can create a custom filter for this kind of thing, fwiw.
            • osiriskang 18 hours ago
              I've been in a similar situation for almost a decade now. There's an elderly woman who's email address is one character away on the keyboard from my own, and I often get emails meant for her. I tried for years to respond to inform them that they are using the incorrect email address, to no avail. At this point I've started to go in and disable/cancel anything that is signed up for with my email address and have to aggressively filter spam.
            • nemomarx 21 hours ago
              why'd you get a Gmail with your personal name? isn't it kinda risky to give that out to every site and etc?
              • windowliker 14 hours ago
                Got it years ago when Gmail was still in beta. My friend sent me an invite and yes I was actually excited to get invited to use the new 'Google Mail'. 1GB mailbox? Wow cool! How times change. The address is mostly dormant but still required for certain services/accounts so I can't just delete it. Probably better to squat it anyway, all things considered.
          • kolinko 23 hours ago
            Gmail filters are very good, dod you check your spam folder?
            • inigyou 20 hours ago
              Gmail blackholes even more spam, not even sending it to your spam folder.
            • serbuvlad 22 hours ago
              No why would I do that? :)
          • pfa87 1 day ago
            [flagged]
      • kqp 1 day ago
        I agree with all of this. I’d add that it’s useful for sorting and searching. Things like keyword matching, from address, and from domain aren’t as consistent as you’d hope, but companies do need to actually email the address they were given, so you can use it to reliably identify emails from them.
      • jiveturkey 1 day ago
        But all 3 of those use cases, plus privacy, can be addressed with word.salad@bigdomain.com. So you may as well get the privacy bit in there.
        • r4ndomname 1 day ago
          True, but it requires setting up a mailbox at bigdomain.com for every use case. With your own domain you can just setup a catchall mainbox like catchemall@yourdomain.com and don’t even need to remember any mailbox@bigdomain.com name. Just use github@ and it will be automatically be catched by your catchall.
          • setopt 1 day ago
            So any mail to anyrandomstring@yourdomain.com is actually received? Sounds like something that works great when only you do it, but might quickly be abused if it catches on?
            • dcminter 1 day ago
              If you do this you immediately get thousands of emails a day from bots trying common first names etc.

              Much better to maintain an explicit list of names you're currently allowing.

              • fingerlocks 1 day ago
                Going back on topic, Apple offers mail hosting for custom domain, along with the optional “one mailbox, infinite aliases” feature we’re discussing right now. I’ve been using it for a while now and no bot spam. No spam at all actually.
              • degamad 23 hours ago
                Surprisingly not. I have catch-all emails on several of my domains, and rarely get common name spam. I've blacklisted less than a dozen names on my domains in over 20 years.
                • dcminter 13 hours ago
                  I guess it varies then. When I did it (probably 15 or 20 years ago mind) I unleashed a torrent of spam so voluminous that I had to write scripts to clean it up my inbox after I turned it off again.
                • mrweasel 22 hours ago
                  A friend of mine does the same. Catch-all, and buying expired domains he thinks funny or related to projects and customers he previously worked with. On multiple occasions he has received emails that truly where never meant for him, not spam but actual emails.

                  So far I think he's returned at least two domains to their previous owners, because letting them laps was a mistake.

              • ksbd-pls-finish 18 hours ago
                It never happened to me - I use a catch all and almost never got emails like this. Why would bots try to guess emails on random domains when there are billions of known emails to send spam to.
              • iso1631 1 day ago
                I do this and have done for over a decade (and used to from about 1998 to 2006 when I ran my own mail server), and don't receive any emails like this
                • dcminter 13 hours ago
                  It was probably some time in the early 2000s that I tried it. I'm actually pretty surprised others didn't/don't have the same issue.
              • zikduruqe 1 day ago
                This past weekend, I finally have purchased my own domain and was contemplating using it for email.

                I had thought about a catch all, but was worried about bots. What is the best option?

                Do you create addresses such as:

                    eyeball@customdomain.com (for the eye doctor)
                    tooth@customdomain.com (for the dentist)
                    bank@customdomain.com 
                    realfirstname@
                    reddit@
                    ...
                    ...
                
                I would like the ability that if I am in a situation that someone says "give me your email for..." and I would like the ability to just hand them something that is disposable. Would I just stand up say 10 addresses like:

                random1, random2, random3... then delete them at some point in the future?

                I really like Cloud's Hide My Email, but have been looking for alternatives since I am not sure where Apple is heading post Tim Cook.

                • iamjameshall 23 hours ago
                  I use Migadu to host my email, and they have a really cool wildcard-style system where I can basically define a regex string, and any email address matching that string goes to my main email. In my case, I use a specific set of numbers just before the @ as the matching string (let’s say, “45”), so email to firstname45@domain works, or doctor45@domain, or library45@domain all get delivered. Since the spammers don’t know this, I don’t get any spam. But I still have the benefit of being able to make up arbitrary emails on the spot for any purpose.
                  • zikduruqe 23 hours ago
                    Outstanding. That's a super idea.

                    Migadu has been on my radar also, and at $19/yr it is worth giving it a try.

                • AndroidKitKat 1 day ago
                  For things I know ahead of time I'm going to need to give someone an email for (e.g. the dentist), I'll pre-make that address and have it ready for when they ask for it. For one-offs / unprepared asks for my email I usually just give them my 'main' initials@personaldomain.com e-mail just for the simplicity... Fastmail does let you use *@personaldomain.com to forward to your main address, but for the rare circumstance in which you need to reply to one of those emails, you do need to configure it in the settings.

                  Fastmail is probably the best $60/year I spend

                  • zikduruqe 1 day ago
                    Thanks. I really don't use email that often; I might get 20 emails a month, and those are just notifications versus actual actionable communications that require a response.

                    I have been looking at Fastmail, along with Purelymail ($10/year), which seems to have similar features.

              • ahmedfromtunis 1 day ago
                [flagged]
    • riddlemethat 1 day ago
      I configured about a dozen domains to have MX records for the mailinator disposable inbox service for about a decade for free as a gift and the domains were toxic for any other email use case for years afterwards… they were so abused you couldn’t even sign up for most web services with any email associated by the time I stopped renewing them… there are still GitHub lists of disposable email addresses that list to blacklist those domains (and many other), so, I agree. If the big providers don’t offer disposable email addresses there is no good option.
      • mrweasel 22 hours ago
        So assuming that I wanted a domain, which would be worthless on any mailing listing and pretty much any service, only good for regular emails, then letting them sit a mailinator aliases for a year or so is a good option?

        Sadly mailinator and similar services aren't really working anymore.

        • duskwuff 17 hours ago
          No - if you did that, you're likely to end up with an email address which many services will treat as suspicious or reject entirely, both for incoming and outbound mail. And you'll still get spam.
      • nunez 1 day ago
        Mailinator was an awesome service when it first worked. Thank you!!!
      • ocdtrekkie 1 day ago
        The reason it's toxic is because the Venn diagram between disposable email addresses and email addresses used for CSAM is a circle: If you accept disposable email and allow users to upload anything, you will have CSAM.

        Whereas a Fastmail masked email or iCloud relay is still in the backend tied to your real account and identity which means it provides privacy generally for you but is traceable enough that it is unappealing for predators.

        • dwroberts 1 day ago
          Why CSAM specifically? Isn’t it mostly going to be just vanilla fraud?
          • ocdtrekkie 1 day ago
            Disposable mail providers generate a ton of spam too, but CSAM is illegal to host, so it's pretty risky to allow them unmitigated.
            • inigyou 20 hours ago
              Citation needed that you'll go to jail if a user uploads child porn to your site and you remove it when notified
    • tjoff 1 day ago
      > You can make arbitrary email addresses at your own domain, but anybody who feels like it can trivially automatically detect that those are all you.

      You assume that the domain is used by one person or what?

      Also, the point of these is typically to prevent spam. Noone is going to spend a fraction of a cent or second to try and figure out who is behind the adress.

      • leshenka 1 day ago
        > You assume that the domain is used by one person or what?

        Yes. It's not a guarantee but you can identify several strong signals that suggest that.

        > point is to prevent spam

        also yes

        • tjoff 1 day ago
          In other words, no point or value in selling yourself to apple.
    • jdoe1337halo 20 hours ago
      Yep I have a few @firefox.com addresses from the inital launch of Firefox Relay. Come in handy for some of the more stubborn sites that block private addresses.
    • teekert 1 day ago
      Indeed, Proton’s passmail are sometimes not accepted sadly.
    • 8cvor6j844qw_d6 1 day ago
      > This is a huge selling point.

      Same thoughts. I'm annoyed with the number of services that blocks alias domains.

      At least I don't see services attempting to block @icloud.com domains.

    • chrisweekly 17 hours ago
      Fastmail is awesome. Happy customer for many years. Zero problems.
  • hollow-moe 1 day ago
    Using icloud.com domain for legit and hidden adresses is such a typical Apple strategy of holding their own users and "others" (ie. other web services, other users etc) hostage simultaneously. But at least here it is actually a good reason that works for the user.
    • HeavenFox 1 day ago
      Case in point: many websites block all VPN except iCloud Private Relay. Thank you Apple!
      • consumer451 1 day ago
        Seriously, Apple is "big tech," but they are the only one that appears to give a crap about privacy at all. And really, they put a lot of money and effort into it.

        We need to give kudos when they are due.

        Apple's Private Cloud Compute should have won some kind of Nobel Privacy Prize, which for some reason does not yet exist.

        • TheDong 1 day ago
          They still don't let me install uBlock origin + noscript. Whitelisting per-domain and per-site what can run Javascript does more for my privacy than anything else, and I can do that with firefox on linux and android, but on iOS I'm not allowed to install firefox.

          There's obviously no real technical limitation since if you live in the EU you can sideload an alternative browser in theory (though apple has made it unrealistic in practice since they're ignoring the spirit of the law and instead doing their darndest to resist giving users even a whit of freedom).

          • kstrauser 1 day ago
            They also don’t allow you to install Windows executables. They do allow you to run adblockers designed for Safari, like Wipr, and there are any number of noscript-alikes, like StopTheScript. I’m not saying that to be snarky, but to say that different platforms have different ways of doing things.

            And Firefox is in the iOS App Store. I know what you meant to say, and that it’s not the same as Firefox on Android, but it’s wrong to say you’re not allowed to install Firefox.

            • pjerem 1 day ago
              Since Apple specifically disallows using other web engines on the App Store, I have bad news for you : Firefox on the App Store is just a reskinned safari and as such, a lot of features cannot be implemented because they depend on the web rendering engine.
              • kstrauser 1 day ago
                That would be news to me if it wasn’t what I already said, that iOS Firefox isn’t the same as Android Firefox.
                • degamad 22 hours ago
                  It sounds like their point is that it's not Firefox at all, inasmuch as you can't use the most popular Firefox extensions.
          • nexus6 1 day ago
            Well there’s UBlock for Safari, yeah it’s not UBlock Origin but it’s not that nothing is available. https://apps.apple.com/gb/app/ublock-origin-lite/id674534269...

            Also Brave supports per site JavaScript blocking on iOS.

            So there’s more privacy tools available than you think/assume.

          • ezfe 1 day ago
            ublock origin is supported by Safari
            • TheDong 1 day ago
              ublock origin _lite_

              https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-b...

              I also can't use Safari because I want my tabs and bookmarks to sync between my desktop machine (linux) and my phone (iOS), and Safari is the only major browser which can't do that.

              Not to mention Safari is just an inferior browser which seems possibly designed to hold back Progressive Web Apps so that everyone has to make app-store apps and tithe a percent of all profits to apple.

              • weiran 1 day ago
                PWAs hold themselves back, they don’t need any help from Safari.
              • astafrig 1 day ago
                The only thing Safari seems inferior at is draining batteries.
        • int_19h 1 day ago
          Apple is luxury big tech.

          In this day and age, privacy is luxury, so that's what they sell.

          I don't think there are any ethical motivations for them (or any other large corporation - none of them have morals so they cannot act morally). It's just that there's a market niche, so it will be filled by someone.

          • saretup 1 day ago
            It’s an additional layer of wall for their walled garden to keep the technically proficient users that are more likely to hop walls.
            • leshenka 1 day ago
              Technically proficient users can figure out their own solutions for throwaway emails e.g. aforementioned Fastmail.
              • inigyou 20 hours ago
                Many systems out there have specific exceptions from their VPN policy for iCloud emails and iCloud private relay. Places that would immediately block fastmail because of its alias feature will not block iCloud because too many people use it. Market share is real power. You can ban 0.1% of your customers, you can't ban 30% of your customers.
              • brookst 23 hours ago
                Sure, but technically proficient users often have other things they want to spend their time on, outside of exercising technical proficiency on every single thing.

                Heck, I don’t even do my own oil changes anymore despite it being easy. Life gets busy, you know?

          • theshrike79 5 hours ago
            Privacy is the niche they know Google can never follow.

            Apple sells hardware, Google is an ad company.

          • tonyhart7 1 day ago
            money from advertising basically dwarf user lifetime purchase of privacy tax you mentioned
            • michaelt 1 day ago
              The ad business has a lot of people chasing after the same ad spend.

              Superbowl ads, TV ads, radio ads, print ads, billboard ads, public transit ads, youtube ads, podcast ads, search ads, e-mail ads, social media ads, in-app ads, in-store ads, sports team sponsorship, individual athlete sponsorship, stadium naming, product placement ads, elevator ads, cinema ads, bathroom ads.

              And Coca-Cola doesn't increase their advertising budget just because someone finds a new place to slap ads on - they just re-allocate their spending.

              Sure, Google and Facebook make a good chunk of money from ads. But it's a very, very competitive business.

              • tonyhart7 21 hours ago
                yet and they still dwarf

                if any, Apple user are the most expensive ads money industry willing to pay for

        • TiredOfLife 1 day ago
          > but they are the only one that appears to give a crap about privacy at all.

          they advertise that they do. that is not the same as doing

          Apple literally wanted to scan all your photos and automatically report you to law enforcement if a fuzzy hash happened to match an opaque database.

          • zackwu 10 hours ago
            no one is saying Apple is the saint. It's just better in comparison to other big techs who want your privacy as much and don't even pretend to care
        • cryptoegorophy 1 day ago
          Only thing I wish they were 20 years sooner.
        • refulgentis 1 day ago
          The person you're replying to is saying "Sites I use block all VPNs besides Apple's subscription service VPN" - I'm not sure they're not blocking it just because they fervently believe in Apple's privacy commitments and engineering :)

          Only pointing this out because I love Apple's privacy story and don't want your reply to be misconstrued as sarcasm, and thus the reason why it enjoys a singular exemption is because its ineffective.

          • SkyPuncher 1 day ago
            I’ve never been under the impression that privacy relay is anything like a true VPN. I mostly thought it stopped BS that happens on public WiFi and public sniffing. It’s meant to protect you only until you get to a major carriers infrastructure.
            • snazz 1 day ago
              The design is supposed to be better than a true VPN, because neither Apple nor the exit node (Akamai, Cloudflare, Fastly) are supposed to know both who you are and what you’re doing. Of course, Apple pays them for this service, so they could exchange info.
            • ezfe 1 day ago
              It is a VPN in the sense that your traffic flows privately through a third party. This is what most people refer to when they say VPN.

              It is not a VPN only in the technical approach.

              • monk_grilla 1 day ago
                It's something of a "private relay", you might say.
          • inigyou 20 hours ago
            They don't block it because of the publicity it would generate. Social factors matter.

            "We blocked people for using special hacker privacy tools. Stop using the special tools if you want service." versus "we blocked people for using the most popular kind of end device. Buy a second, really obscure brand of device if you want service."

            (In the US, that is. Outside the US, Android devices are more popular but Apple still has the plurality because there's only one of it)

      • vallerie 1 day ago
        Private Relay also works because it's on by default for everyone paying for iCloud (including everyone just on the 0.99/month tier for photo backup) - so Apple can use it across their apps (e.g. loading images in Apple Mail) and it doesn't let you single out privacy conscious users!
      • inigyou 20 hours ago
        I worked at a place that was contractually mandated to block VPNs except iCloud Private Relay and we had a special exception in the code for this.
      • jeroenhd 1 day ago
        I don't think websites block Google's VPN either, although that's not quite as popular as Apple's VPN solution.
        • SXX 1 day ago
          Google VPN is only on Pixel phones now. It also only available in few countries.

          Its only upside was a fact that it was actual VPN for all the apps while AFAIK private relay limited to Safari.

    • dilyevsky 1 day ago
      how is the user being held hostage? you can redirect hide my email addresses to any domain
      • travoc 1 day ago
        Marketing turds can't just block registrations from all of @icloud.com.
        • dymk 1 day ago
          That doesn’t explain how the user is held “hostage” by Apple
          • hollow-moe 4 hours ago
            The user is held hostage as much as the platforms because it's used as "currency" to force other sites to do things they may not want to, i.e. create accounts using private emails, and the platforms are held hostage by these same users expecting to be able to create accounts using their legit or private icloud emails. It looks like some kind of "who will break first", is there a service big enough to be able to block all icloud emails and it'd be a sufficient inconvenience to force apple to rethink how private email works ?
          • HeavenFox 1 day ago
            Hostage may be a bad analogy. More like a game of chicken. Imagine you are a regular @icloud.com email user. Apple is basically saying "I dare you to block all @icloud.com email and lose all these customers"
            • inigyou 20 hours ago
              So the website is being "held hostage", not the user.
            • bobthepanda 1 day ago
              you could say the same thing about AWS or Cloudflare hosting anybody and everybody. Spain actually started blocking a bunch of their IP blocks during football matches due to a poorly thought out legal decision.
        • N19PEDL2 1 day ago
          Can they block registrations from @private.icloud.com?
          • cr3ative 1 day ago
            Yes, they would have been able to if the proposal had gone ahead.
      • aareet 1 day ago
        I think the other answers are misinterpreting your question. A user is held "hostage" because unlike fastmail where the format is word.salad@yourdomain; if you ever wanted to ditch iCloud completely, you'd have to go through every single account you used it for and update the email. As someone who has shed his gmail account I can tell you it's not easy to update email address on every site you've ever used it on. The issue people are raising is that apple doesn't let you use your own domain, and generate random emails at that domain. Not my complaint, but I can see the perspective.
        • pasc1878 1 day ago
          Yes you can do word.salad@yourdomain with fastmail but that ius no different to other mail providers.

          What the above comments re fastmail is about their masked email service this gives addresses like <random>@fastmail.com so this is the same lockin as Apple with the same benefits of noone is going to block that domain.

        • flyingshelf 1 day ago
          I mean, that is no different than any other provider.

          If you want to degoogle, you still have to go to each site and change your staticuser@gmail.com individually.

          Most users already do not use custom domains if that's the catch.

  • philip1209 1 day ago
    I wish I could set up "Sign in with Apple" on a blog without paying $99/yr for a developer license.
    • chanux 1 day ago
      Is your audience very Apple heavy?
    • pasc1878 1 day ago
      Why do you want this.

      Is it a benefit to you? If it is why should you not pay for that benefit?

      Nothing is free.

      • Jleagle 1 day ago
        You say nothing is free, but Amazon, Discord, Dropbox, Facebook, GitHub, Google, Instagram, Microsoft, Paypal, Reddit, Slack, Steam, TikTok, Twitter etc all offer it for free.

        Plus, it's not for the dev, it's for the users of the website.

        • Schiendelman 1 day ago
          It's not free - you're agreeing for them to track and advertise to your customers. Apple does not do that with your Apple login data.
          • inigyou 20 hours ago
            Huh? Of course Apple does that, and charges you for the privilege as well.
            • happyopossum 19 hours ago
              Understandable assumption if you haven't been paying attention to Apple and privacy, but incorrect:

              https://www.apple.com/legal/privacy/data/en/sign-in-with-app...

              >When you use Sign in with Apple on Safari, Apple sees when you sign in to a website so that Apple can authenticate your sign in, but Apple does not retain a history of what websites you sign in to or when you use Sign in with Apple.

              • inigyou 18 hours ago
                I can lie too.
                • Schiendelman 17 hours ago
                  Tell me more! What evidence do you have that Apple is lying?
                  • inigyou 8 hours ago
                    Lying would make money. Apple likes money. Apple has a lot of money. Many other companies that were in positions similar to Apple have been caught lying. The reason for that was money.
                    • Schiendelman 6 hours ago
                      Do you understand how easy it would be to prove Apple lied about that if they did?
        • khalic 1 day ago
          And they all sell your data
          • fugigigjfn 19 hours ago
            It’s so tiring to hear people repeat this automatically without even thinking. It’s true in thumb cases, but in many other cases, the data is more valuable to them to keep private or use for other purposes, or it’s value when the sold is not enough to warrant inclusion in the privacy policies.

            You’re adding nothing to the discussion and you should delete your comment

            • khalic 11 hours ago
              Sure thing
      • whstl 1 day ago
        It's mutually beneficial to everyone involved, Apple, the blog, the user.

        No leaked email address, no need for anyone to store password, people using iCloud instead of Gmail.

        What they're asking, for it to cost zero, sounds perfectly reasonable here.

      • sunaookami 1 day ago
        Since when did we start accepting that paying for providing OAuth sign-in for other companies is good?
        • inigyou 20 hours ago
          I wish you had to pay for all of them. We'd see a lot less of them.
  • NotThatFast 1 day ago
    One of the best things about it. Also being able to add several emails per custom domain for free.

    Whole thing is 99c a month. Makes Gmail seem like a joke in comparison.

    Until you get an email from an iCloud address on Gmail and see it go right to spam haha. Suddenly Gmail is cheap again

    • wafflemaker 1 day ago
      Best thing to do with Gmail spam is to make an auto filter to mark all spam as not spam.

      Took me only one missed dentist appointment several years ago to get that idea. Now I'm just getting profits. No other spam since I'm using email aliases.

      • dannyw 1 day ago
        Unfortunately you can only do that for yourself, your recipients almost certainly aren't doing the same. It doesn't address the "gmail deliverability" issue.
    • Quothling 1 day ago
      Maybe it's because I live in a country where e-mai isn't really used that much for personal communication, but wouldn't this mainly be a gmail issue? If mails I wanted ended up in the spam folder I'd not use gmail. I mean, I pay for protonmail, so I wouldn't use gmail to begin with, but if mails I wanted ended up in my protonmail spamfolder and I couldn't do anything about it, then I'd switch away from protonmail.
      • NotThatFast 1 day ago
        You are 100% correct and yet the masses still prefer it.

        World’s a twisted place!

        I would guess the average Gmail user doesn’t know that it reports virtually all iCloud as Spam - believing instead that it’s genuinely being filtered by quality engineering at Google.

      • DrewADesign 1 day ago
        If you’re talking about people with the technical sophistication to consider software services based on their technical merits, then sure. Your average user couldn’t even tell you the first thing about which non-content-based criteria might inform a spam score… or have even heard of a spam score. So they will absolutely not blame Gmail if another provider’s email gets spam flagged… they’d probably just think “why don’t they just get a Gmail account,” à la iMessage users/green texts.
  • joshuat 1 day ago
    I'm glad they listened - I use this feature extensively and would like to continue to
  • DarmokTanagra 1 day ago
    I use hide my email and single use credit card numbers all the time, its a fantastic system combined with some basic email forwarding rules.

    Yes, vendor lock in sucks, but I have $20k worth of apple hardware already so that ship has sailed and overall Im pretty happy with it.

    • _zoltan_ 1 day ago
      single use card tied to you, or via some privacy frontend? if the latter, care to share your experience?
      • DarmokTanagra 21 hours ago
        many cards offer virtual card numbers, robinhood card offers name anonymization.

        been a user for a couple years now and no complaints

        • rsync 18 hours ago
          A reminder:

          Neither visa nor MasterCard networks have the ability to verify cardholder name.

          Everyone behaves as if they do, but your name cannot be verified.

          Which is to say, all of these cards have name anonymization, not just robinhood.

          • zackwu 10 hours ago
            yeah I found it out a while back and since then I've been using randomly generated names during checkout every time - no issues ever
          • DarmokTanagra 18 hours ago
            I was unaware of that, is address also unverifiable?
        • _zoltan_ 19 hours ago
          robinhood is not available here in Switzerland unfortunately.
  • giwook 1 day ago
    Can someone explain the backstory behind this? I'm reading some of the comments here and I feel like I'm missing something here.
    • dannyw 1 day ago
      For the "hide my email" feature, Apple currently and has always used "@icloud.com". This masks you amongst all iCloud users.

      They were planning to change it to a custom domain, which would allow sites to easily filter out and reject "Hide my email" users based on the email.

      They have now reverted their plans to change this, meaning "hide my email" is still "@icloud.com".

      • nailer 1 day ago
        I suspect many people actually feel better about Apple owning this fuckup and reversing it than they would have Apple hadn't fucked up in the first place.
      • frabcus 1 day ago
        Except the post says it will be @private.icloud.com

        Whereas people's Apple emails are often at @icloud.com

        So I don't think it masks you amongst all iCloud users. I'm confused how this is much better!

        • leshenka 1 day ago
          The post says that "Sign in with Apple" will issue emails on @private.icloud.com but "Hide my email" will continue issuing addresses on @icloud.com

          These are two separate services. The problem was with the latter not the former. If the service decides to block @private.icloud.com they might as well remove Apple's sign in button.

  • SXX 1 day ago
    Oh I glad there is still someone at Apple who understood its insanity. If only they made it generate a bit more sensible alias names.

    UPD: I obviously mean alias addresses template make most of them too easy to recognize.

    • merlindru 1 day ago
      Can't the aliases be renamed?

      ---

      Just checked, they can. Phew. If the forwarding alias was detectable/always used the same schema, that'd also make them borderline useless, just like the `privaterelay` subdomain

      • SXX 1 day ago
        What do you mean renamed? Alias address certainly are not changeable. You can randomize next one from 2-3 options, but most of them still follow pattern that is easy to recognize.

        PS: I guess its just misunderstsnding and I really meant addresses themself are not human-like enough.

      • simongr3dal 1 day ago
        But the private relay domain is only used when you sign up through “Sign in with Apple”? A thing you have to support if your iOS app already supports sign up with other third party authentication providers.
  • wijayaerick 1 day ago
    iCloud Hide My Email sharing the same domain with normal email (icloud.com) is the reason why I use iCloud over other email alias services like simplelogin and addy.
  • aucisson_masque 1 day ago
    Apple had been on a steady path of bad decisions since a few years, I'm glad to see they reverted at least on this one.

    Now if they could completely remove liquid glass...

  • srevenant 14 hours ago
    Don't mix use cases. Privacy is different from uniquely identifying senders.

    The reason for random email addresses is YOU finally can identify each vendor uniquely by the email they send you stuff.

    It isn't about anonymizing, it's about identifying them.

    I've been doing it for 30+ years on my own domains.

  • delduca 21 hours ago
    If you pay for iCloud + a domain, you can have ${anything}@${yourdomain}. Works like a charm.

    For example, I can have hn@mydomain.com for hn only mails, if they share my mail address, I'll know.

  • floam 1 day ago
    Good. This would have made blocking them trivial.
  • postalcoder 1 day ago
    I've noticed a chilling new trend of apple listening to the community.
    • VCFundedGenYer 1 day ago
      My guess is Ternus is starting to take more and more control. Tim was pretty absent and phoning it in the past few years.
    • nate 1 day ago
      Anyone have a theory why this even made it to this point? the switch was such obviously a bad idea. just corporate weirdness that no one there bothered to raise their hand and be like "uh, are we really doing this?" or was there a story here that anyone knows about?
      • jofzar 1 day ago
        It's email reputation, it the always the answer with this kind of stuff.

        My guess is that the bounce rate got too high and bot farms were using iCloud addresses like this.

        • Marsymars 1 day ago
          The bounce rate of what, exactly?

          Because the bounce rate of Hide My Email addresses being deliverable is going to rise over time, by design.

          Whenever I start getting spam at an address that's been leaked, I deactivate it. I've done the same with my oldest gmail account, but the work required there is notably higher.

          • MBCook 1 day ago
            If they were moved to plain old icloud.com, I could absolutely see a bunch of companies starting to filter out all icloud.com email addresses to avoid private relay. Either just because they’re jerks or from bounce issues.

            Keeping it on a subdomain fixes that problem, to some degree. If the user is named ffjvhtu57325cjdjvg501a2@icloud.com no one is going to think that’s a real address. It’s very obviously a private one. So it’s not like they were “camouflaged.“

            It’s a little odd they’re switching the subdomain though.

            • int_19h 1 day ago
              > If they were moved to plain old icloud.com, I could absolutely see a bunch of companies starting to filter out all icloud.com email addresses to avoid private relay.

              I couldn't. "Uses Apple products" is one of the more reliable signals of willingness and ability to spend money on stuff online.

            • jtbayly 1 day ago
              Hide My Email already uses plain old @iCloud.com as the domain.

              They are not changing the subdomain. There isn’t one. The announcement is they are leaving it as-is.

              The email addresses for sign-in with Apple do use the @private.iCloud.com subdomain, but again, that’s not a change.

            • drdexebtjl 1 day ago
              Hide My Email addresses are not just a random string at icloud.com. They use plausibly-human names, probably generated by a language model. There’s no easy-to-check pattern.

              They’re not switching the subdomain. They’re keeping it the same. That’s the news.

              They’re switching the subdomain for the “Sign in with Apple” sign ups, which is not the same service.

              • fodkodrasz 1 day ago
                > Hide My Email addresses are not just a random string at icloud.com. They use plausibly-human names, probably generated by a language model.

                why would random selection from sets of predefined strings and joining them using a "." need any LLM involvement? Oh you need to check if it already taken... maybe for that? I'd use a database though...

                These days some people would even generate GUIDs with some language model, I guess...

                • drdexebtjl 22 hours ago
                  It’s probably not an LLM, nor a small transformer-based model, but it is a language model. Probably the kind that powered auto-correct before GPT.

                  The generated words agree in grammatical gender and plural forms, so by definition it’s a language model.

            • Marsymars 1 day ago
              Right, but I'm asking "what bounce issues?"

              Like for my usage there are no bounce issues with the ~400 legitimate providers that I have Hide My Email addresses from. The only ones with bounce issues are the spammers who've acquired leaked addresses that I've deactivated.

              • saurik 1 day ago
                If you merely deactivate your email address rather than closing your account or changing your notification settings or whatever, then the next time a legitimate service goes to send you a legitimate email that you asked for, it will bounce. In some sense this "shouldn't matter", as in a purely P2P system the only people who would notice are the sender and Apple -- and Apple knows what is going on, so should not penalize senders the way, say, Google would if they see you sending a ton of email to their domains and they all bounce -- but people tend to use services to help send email and centrally pool their reputation (such as mailchimp) and so these services themselves then watch the bounce rate of their individual customers and either charge them more or ban their access due to the bounce rate increase.
                • xp84 1 day ago
                  Is Apple really stupid enough that they BOUNCE emails after you deactivate, rather than just silent discard? What's the point of bouncing unwanted emails these days? It's not like these bounces go to humans who go "Oh, gee! This address must not work. Allow me to go and figure out how to contact him!" It's just a stream of full-on spam with completely fake return addresses, and crap from email campaign software.
                  • Marsymars 1 day ago
                    I mean my hope is to get the senders' IP/accounts/email reputation flagged for having additional bounces.
      • super256 1 day ago
        Maybe hidemyemail allows easily creating many accounts on a site. And some big site didn't like it.

        The "Sign-up via Apple" button and creating an iCloud email yourself have a slightly higher barrier than creating a new throwaway hidemyemail email (1 API call w/o captcha/phone verification or whatever).

        We might find out later this year if some site starts blocking @icloud.com but keeps allowing @private.icloud.com.

        • pests 1 day ago
          It does, and I know a friend of a friend who uses them for Walmart accounts to bot pokemon drops. Those and office aliases.
      • LgWoodenBadger 21 hours ago
        Whoever operates the smtp servers for icloud.com complained loudly enough that their job was too hard because of all the traffic, but not loudly enough for someone smart enough to hear about it, until it was announced to the public.
    • cush 1 day ago
      Hmm it’s almost as if people are paying good money for iCloud+ or something. They aren’t google and shouldn’t be retiring their services as if they’re giving them away for free
      • herpdyderp 1 day ago
        While I applaud this specific change, Apple has been known to stick to their guns and I used to believe they were almost always in the right for doing so because it led to better outcomes. So my take is that it's chilling because Apple has so lost their way that they can't figure out these obviously stupid directions internally before making a fool of themselves to the public (and I agree with that take).
  • scosman 1 day ago
    it will still be on "private.icloud.com". Just as filterable...
    • ninkendo 1 day ago
      private.icloud.com (née privaterelay.appleid.com) is the address for “Sign In With Apple”, which is an oauth-style service that sites opt into to let you use your Apple ID to sign in. Sites offering this as a signup option are already aware it gives users an option to use a private anonymized email address.

      The toplevel “Hide My Email” iCloud feature is a different thing, can be done independently of a SIWA flow (you can just go into settings and make more addresses, all it needs is a name and a notes field) and uses @icloud.com in order to make your anonymized email address look indistinguishable from other iCloud users.

      The former is “filterable”, yes, but it’s moot because you only get those if you offer Sign In With Apple in the first place, and if you want real emails, you would already know to just… not do that.

      The latter is very much not filterable.

      The confusing thing though, is that when a user uses Sign In With Apple, they are offered two options: “share my email” which gives the site your real address, and “hide my email” which gives an @private.appleid.com address. But this “hide my email” option is a totally different thing from the separate “hide my email” service, which lets you make arbitrarily many @icloud.com private aliases to forward to your real address. Critically, the latter toplevel Hide My Email feature works with sites that don’t use Sign In With Apple. It’s just stupidly unfortunate that Apple calls both of these features “hide my email.”

      • samschooler 1 day ago
        Agree with the comment largely; though: Apple does have a policy where apps need to use SIWA if other oauth providers are present (Google) [0]. So sites do "opt in" to this, but are forced by apple to use SIWA if they're using any other provider.

        [0]: https://developer.apple.com/app-store/review/guidelines/#sig...

      • _ks3e 1 day ago
        Not arbitrarily many aliases - there's a limit of (as of two or three weeks ago) 768.
        • _zoltan_ 1 day ago
          I wonder how a single user runs into that.
          • inigyou 20 hours ago
            Sign up to 768 websites
        • leshenka 1 day ago
          3x256? Weird, perculiar number.
    • internet2000 1 day ago
      It won't. The news here is that it won't.
    • LPisGood 1 day ago
      Others have addressed the validity of your comment, but I’d like to discuss another aspect. Even if it is filter, I think most people would not want to filter. Apple makes it very easy to use private relay and many people that buy Apple products do use private relay. Even if you know, it’s a private relay email address, surely you want a user who buys expensive technology products to use your website in almost all circumstances.
  • bni 1 day ago
    As I user of this service I like this.

    However filtering for these hide my e-mail addresses is quite easy if you are motivated to do it, they have a recognizable pattern.

    • Keirmot 1 day ago
      They do, but then your net can get false positives. Even if unlikely, someone can have the email potent-tomatoq4@icloud.com
  • amazingamazing 1 day ago
    Good. What else can really be said? Only way for it to work and not be trivially blocked is to mix with legit emails.
    • jambalaya8 1 day ago
      A lot of places also don't really like icloud addresses in general. This is one of Apple's better offerings though.
  • Vinnl 1 day ago
    I wonder if the initial reason to move them to a separate domain, was because they started to see providers blackholing icloud.com anyway, thus also hurting non-aliased emails?

    If so, will be interesting to see if that will get worse.

  • etaioinshrdlu 1 day ago
    I'm a bit confused - when i see these signups, they look like this to me:

    rtwnj6tj7@privaterelay.appleid.com

    • anon7000 1 day ago
      I think the post is very explicit. First sentence:

      > Starting later this year, new Sign in with Apple addresses, previously issued on privaterelay.appleid.com, will be issued on private.icloud.com. Existing addresses on privaterelay.appleid.com will continue to work and forward mail to users without interruption.

      • jshier 1 day ago
        That's the Sign in with Apple domain, not the Hide My Email domain. HME is remaining at icloud.com instead of moving to private.icloud.com as well. From the linked article:

        > After further consideration and reviewing community feedback, iCloud+ Hide My Email addresses will remain on icloud.com.

    • drdexebtjl 1 day ago
      How many sign ups you have with an @icloud.com address?

      A lot of those are Hide My Email aliases that, by design, you can’t tell apart from real human addresses.

  • xaviervn 1 day ago
    I don't understand how this changes anything. IIRC, the complaints were about Apple making the Hide My Email addresses different than regular ones.

    They're now saying the new domain will be private.icloud.com. Isn't it just as targetable?

    • NobodyNada 1 day ago
      It's talking about two different services:

      > Sign in with Apple addresses, previously issued on privaterelay.appleid.com, will be issued on private.icloud.com.

      > iCloud+ Hide My Email addresses will remain on icloud.com.

    • LoganDark 1 day ago
      Sign in with Apple is Apple's SSO, like Sign in with Google. Services have to support this one explicitly, and it already had a special subdomain, so the specific subdomain is simply changing.

      Hide My Email is the manually generated ones, for websites that accept an arbitrary email address. This is the one where it's valuable for the relays to be identical to genuine iCloud addresses, otherwise websites could try to block it and force you to use a more revealing email address, undermining privacy.

  • Mindwipe 23 hours ago
    Good. Thank you for listening, iCloud team.
  • tingletech 1 day ago
    this opens some crazy "apple developer" dialog on my mac rather than a web page. I had to crank up chrome to read it. And it makes no sense, I have no clue what a sign on with apple address is. I guess I'm glad my hide my email addresses won't change because that would be a PITA.
    • ezfe 1 day ago
      You have the developer app installed. It does seem to be deep linking wrong.

      Sign in with Apple email addresses are email addresses for the Sign in with Apple button.

  • prism56 1 day ago
    Good! Was there ever a compelling reason why they went for this switch initially?
    • floam 1 day ago
      Yes, to fully fix a certain class of bug on their infra.
      • culi 1 day ago
        Do you know any more about it or have a link where I can read more?
        • floam 1 day ago
          I’ll try to add more later, but it is believed that multiple times, a bug in some random API has allowed for the “hidden” Apple account to be revealed because they resolve hide my emails to the original internally. Using a separate namespace would be the universal fix.

          A mitigation for the cause of https://www.404media.co/apple-hide-my-email-vulnerability-re...

          • nvme0n1p1 1 day ago
            This doesn't follow. The bounce message used to (effectively) say,

            > abc@icloud.com forwards to real@gmail.com

            If they switched the new domain and did nothing else, it would say:

            > abc@privaterelay.appleid.com forwards to real@gmail.com

            That's no better. Fixing that privacy leak is unrelated to whatever the destination domain is.

            • floam 1 day ago
              No, using a different domain makes it easy to across the board add a rule: don’t treat as Apple ID.
              • dannyw 1 day ago
                I'm not sure if I'm following. Apple is capable of creating a lookup table, or an atomic database read query.
        • gruez 1 day ago
          https://news.ycombinator.com/item?id=48559935

          If you dig more you could find the bug, but AFAIK it was that if you sent a large attachment, the bounce email would contain your real address.

  • ozereray1 1 day ago
    It is reassuring to see Apple maintaining this domain consistency. Changing it would have broken a lot of automated routing rules for those of us relying on it for privacy.
  • 1vuio0pswjnm7 14 hours ago
    01 Jul 2026 10:19:45 UTC | Apple 'Hide My Email' vulnerability reveals peoples' real email addresses | https://www.404media.co/apple-hide-my-email-vulnerability-re... | https://news.ycombinator.com/item?id=48744606

    02 Jul 2026 03:47:04 UTC | Apple 'Hide My Email' Vulnerability Reveals Peoples' Real Email Addresses | https://www.404media.co/apple-hide-my-email-vulnerability-re... | https://news.ycombinator.com/item?id=48756295

    03 Jul 2026 22:56:51 UTC | Apple 'Hide My Email' Vulnerability Reveals Peoples' Real Email Addresses | https://www.404media.co/apple-hide-my-email-vulnerability-re... | https://news.ycombinator.com/item?id=48780999

    04 Jul 2026 17:01:39 UTC | Security Roundup: Apple's Hide My Email Service Fails to Hide Your Email | https://www.wired.com/story/security-roundup-apples-hide-my-... | https://news.ycombinator.com/item?id=48786928

    04 Jul 2026 18:54:24 UTC | Apple Hide My Email Reveals the Users Real Email | https://www.404media.co/apple-hide-my-email-vulnerability-re... | https://news.ycombinator.com/item?id=48787842

    05 Jul 2026 06:26:38 UTC | Security Roundup: Apple's Hide My Email Service Fails to Hide Your Email | https://www.wired.com/story/security-roundup-apples-hide-my-... | https://news.ycombinator.com/item?id=48791735

    07 Jul 2026 02:16:06 UTC | Apple 'Hide My Email' Vulnerability Reveals Peoples' Real Email Addresses | https://www.404media.co/apple-hide-my-email-vulnerability-re... | https://news.ycombinator.com/item?id=48812946

    12 Jul 2026 01:05:37 UTC | Apple Hide My Email bug, possibly related to disclosure vulnerability | https://lapcatsoftware.com/articles/2026/7/2.html | https://news.ycombinator.com/item?id=48877353

    Recommended reading:

    19 Aug 2026 15:22:13 UTC | Alvarez vs. Apple, Inc. (N.D. Cal., July 15, 2026) [pdf] | https://ia803202.us.archive.org/25/items/gov.uscourts.cand.4... | https://news.ycombinator.com/item?id=49362811

    21 Jul 2026 15:31:41 UTC | Apple Fixes Hide My Email Vulnerability After 404 Media Coverage | https://www.404media.co/apple-fixes-hide-my-email-vulnerabil... | https://news.ycombinator.com/item?id=48993637

    23 Jul 2026 20:11:07 UTC | How Apple's Hide My Email exploit worked and why you're still at risk | https://easyoptouts.com/guides/apple-hide-my-email-was-leaki... | https://news.ycombinator.com/item?id=49027365

    24 Aug 2026 20:24:44 UTC | Apple Won't Change Hide My Email Domain After Backlash | https://www.macrumors.com/2026/08/24/apple-hide-my-email-dom... | https://news.ycombinator.com/item?id=49425379

  • delduca 1 day ago
    That was a stupid idea (the prev one)
  • rubyfan 1 day ago
    Now if they would only figure out how to Hide My Phone Number then these feature would actually impact privacy.
  • sukiankarim13 15 hours ago
    sukiankarim13@icloud.com
  • sanjay_dev 23 hours ago
    [dead]
  • trueno 1 day ago
    thank god -.-