The "private relay" feature first sends web traffic to a server maintained by Apple, where it is stripped of a piece of information called an IP address. From there, Apple sends the traffic to a second server maintained by a third-party operator who assigns the user a temporary IP address and sends the traffic onward to its destination website.
The use of an outside party in the second hop of the relay system is intentional, Apple said, to prevent even Apple from knowing both the user's identity and what website the user is visiting.
Very interesting. But what stops Apple from looking at the packet from the user device and seeing the destination address?