iCloud+ Hide My Email addresses will remain on icloud.com
developer.apple.com
developer.apple.com
Comments about lock-in aren’t wrong, but it has to be this way. You can make arbitrary email addresses at your own domain, but anybody who feels like it can trivially automatically detect that those are all you.
Personally I use unique at own domain only where I’m identifying myself anyway, like my bank, and Fastmail masked email where I’m not. For most things it’s not actually that terrible to accept a small risk that they’re offline for a day between your being booted without warning and you changing your email address with them.
I continue to use it everywhere for a few reasons:
- if someone emails me acting all friendly like we've had some previous relationship but it's sent to linked@mydomain or github@mydomain I know they've just scraped my contact details and it's spam
- similarly, if a vendor leaks or sells my data and I start receiving marketing from somewhere I don't expect it's easier to trace the source of the leak (and in some cases just blackhole that entire email address)
- I already use a password manager and have different passwords on every site, but having a different email address too raises the barrier further for someone trying to script an automated attack based off some other pwned data set.
Much better to maintain an explicit list of names you're currently allowing.
They’re not exactly the same thing. Aliases are alternate addresses (under one domain) you set up yourself, while a catch-all just accepts any address in the domain as valid. While iCloud Mail does allow catch-all¹, aliases are capped at a maximum of three².
¹ https://support.apple.com/en-gb/guide/icloud/mm9e3ee0680f/ic...
² https://support.apple.com/en-gb/guide/icloud/mm074af79454/ic...
I had thought about a catch all, but was worried about bots. What is the best option?
Do you create addresses such as:
eyeball@customdomain.com (for the eye doctor)
tooth@customdomain.com (for the dentist)
bank@customdomain.com
realfirstname@
reddit@
...
...
I would like the ability that if I am in a situation that someone says "give me your email for..." and I would like the ability to just hand them something that is disposable. Would I just stand up say 10 addresses like:random1, random2, random3... then delete them at some point in the future?
I really like Cloud's Hide My Email, but have been looking for alternatives since I am not sure where Apple is heading post Tim Cook.
Fastmail is probably the best $60/year I spend
I have been looking at Fastmail, along with Purelymail ($10/year), which seems to have similar features.
Migadu has been on my radar also, and at $19/yr it is worth giving it a try.
So far I think he's returned at least two domains to their previous owners, because letting them laps was a mistake.
This is exactly why I do it, it's eye opening to see exactly which companies leaked your address. As a result of being able to blackhole the leaked addresses I no longer get any spam, the Dvorak dream.
I actually caught a company outright selling my address to AWS of all places, I didn't even know Amazon purchased mailing lists.
AWS were crafty because they didn't directly sell a service, they only offered "resources" for "business leaders" because they knew nothing about what I might need.
Explore the AWS [REDACTED] where business leaders can access eBooks, guides, and customer stories to find practical advice on building or improving upon a data strategy. Learn how you can leverage data as a strategic asset, make better decisions with insights from data, and innovate faster.
I use my gmail address for everything and I don't really get spam (except from services I've subscribed to legitimately but haven't bothered to configure to not send promotional mail).
I never really get promotional mail from 3rd parties at all.
Is this just gmail filters being very good?
I've been getting someone else's e-mail traffic for about 5 years now, on two separate Gmail accounts, and while occasionally hilarious, it is somewhat scary to see how much I can know about their lives from the type of e-mails they get. I have replied to inform some of the senders about the situation with the suggestion that they could tell the other person involved to use a new e-mail address, but it is still happening. You'd think that they would need to see some of the important work-related mail they receive yet they are apparently utterly oblivious.
I occasionally also get similar mail to my own domain through a catch-all filter.
It's quite funny how little some people understand about what an e-mail address is, or how it's supposed to be used, even today.
It certainly felt that way when someone was giving my GMail out to the cashier at the hardware store where I got no end of digital receipts which I couldn't unsubscribe from because they're providing the email address to the cashier each time. As they were receipts from a large verified brand Google treated them with the highest priority.
But might gmail junk filters be the best junk mail filters for nefarious proprietary reasons, possibly?
Even the simplest bayesian filter will score better than gmail.
Same thoughts. I'm annoyed with the number of services that blocks alias domains.
At least I don't see services attempting to block @icloud.com domains.
Whereas a Fastmail masked email or iCloud relay is still in the backend tied to your real account and identity which means it provides privacy generally for you but is traceable enough that it is unappealing for predators.
Sadly mailinator and similar services aren't really working anymore.
You assume that the domain is used by one person or what?
Also, the point of these is typically to prevent spam. Noone is going to spend a fraction of a cent or second to try and figure out who is behind the adress.
Yes. It's not a guarantee but you can identify several strong signals that suggest that.
> point is to prevent spam
also yes
If you want to degoogle, you still have to go to each site and change your staticuser@gmail.com individually.
Most users already do not use custom domains if that's the catch.
What the above comments re fastmail is about their masked email service this gives addresses like <random>@fastmail.com so this is the same lockin as Apple with the same benefits of noone is going to block that domain.
We need to give kudos when they are due.
Apple's Private Cloud Compute should have won some kind of Nobel Privacy Prize, which for some reason does not yet exist.
Only pointing this out because I love Apple's privacy story and don't want your reply to be misconstrued as sarcasm, and thus the reason why it enjoys a singular exemption is because its ineffective.
It is not a VPN only in the technical approach.
"We blocked people for using special hacker privacy tools. Stop using the special tools if you want service." versus "we blocked people for using the most popular kind of end device. Buy a second, really obscure brand of device if you want service."
(In the US, that is. Outside the US, Android devices are more popular but Apple still has the plurality because there's only one of it)
In this day and age, privacy is luxury, so that's what they sell.
I don't think there are any ethical motivations for them (or any other large corporation - none of them have morals so they cannot act morally). It's just that there's a market niche, so it will be filled by someone.
Superbowl ads, TV ads, radio ads, print ads, billboard ads, public transit ads, youtube ads, podcast ads, search ads, e-mail ads, social media ads, in-app ads, in-store ads, sports team sponsorship, individual athlete sponsorship, stadium naming, product placement ads, elevator ads, cinema ads, bathroom ads.
And Coca-Cola doesn't increase their advertising budget just because someone finds a new place to slap ads on - they just re-allocate their spending.
Sure, Google and Facebook make a good chunk of money from ads. But it's a very, very competitive business.
if any, Apple user are the most expensive ads money industry willing to pay for
Heck, I don’t even do my own oil changes anymore despite it being easy. Life gets busy, you know?
Apple sells hardware, Google is an ad company.
There's obviously no real technical limitation since if you live in the EU you can sideload an alternative browser in theory (though apple has made it unrealistic in practice since they're ignoring the spirit of the law and instead doing their darndest to resist giving users even a whit of freedom).
And Firefox is in the iOS App Store. I know what you meant to say, and that it’s not the same as Firefox on Android, but it’s wrong to say you’re not allowed to install Firefox.
https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-b...
I also can't use Safari because I want my tabs and bookmarks to sync between my desktop machine (linux) and my phone (iOS), and Safari is the only major browser which can't do that.
Not to mention Safari is just an inferior browser which seems possibly designed to hold back Progressive Web Apps so that everyone has to make app-store apps and tithe a percent of all profits to apple.
Also Brave supports per site JavaScript blocking on iOS.
So there’s more privacy tools available than you think/assume.
they advertise that they do. that is not the same as doing
Apple literally wanted to scan all your photos and automatically report you to law enforcement if a fuzzy hash happened to match an opaque database.
Its only upside was a fact that it was actual VPN for all the apps while AFAIK private relay limited to Safari.
Whole thing is 99c a month. Makes Gmail seem like a joke in comparison.
Until you get an email from an iCloud address on Gmail and see it go right to spam haha. Suddenly Gmail is cheap again
World’s a twisted place!
I would guess the average Gmail user doesn’t know that it reports virtually all iCloud as Spam - believing instead that it’s genuinely being filtered by quality engineering at Google.
Took me only one missed dentist appointment several years ago to get that idea. Now I'm just getting profits. No other spam since I'm using email aliases.
Is it a benefit to you? If it is why should you not pay for that benefit?
Nothing is free.
Plus, it's not for the dev, it's for the users of the website.
https://www.apple.com/legal/privacy/data/en/sign-in-with-app...
>When you use Sign in with Apple on Safari, Apple sees when you sign in to a website so that Apple can authenticate your sign in, but Apple does not retain a history of what websites you sign in to or when you use Sign in with Apple.
No leaked email address, no need for anyone to store password, people using iCloud instead of Gmail.
What they're asking, for it to cost zero, sounds perfectly reasonable here.
They were planning to change it to a custom domain, which would allow sites to easily filter out and reject "Hide my email" users based on the email.
They have now reverted their plans to change this, meaning "hide my email" is still "@icloud.com".
Whereas people's Apple emails are often at @icloud.com
So I don't think it masks you amongst all iCloud users. I'm confused how this is much better!
These are two separate services. The problem was with the latter not the former. If the service decides to block @private.icloud.com they might as well remove Apple's sign in button.
UPD: I obviously mean alias addresses template make most of them too easy to recognize.
---
Just checked, they can. Phew. If the forwarding alias was detectable/always used the same schema, that'd also make them borderline useless, just like the `privaterelay` subdomain
PS: I guess its just misunderstsnding and I really meant addresses themself are not human-like enough.
Is breest-tas.7n@icloud.com really that hard to detect as hide my email?
Now if they could completely remove liquid glass...
The "Sign-up via Apple" button and creating an iCloud email yourself have a slightly higher barrier than creating a new throwaway hidemyemail email (1 API call w/o captcha/phone verification or whatever).
We might find out later this year if some site starts blocking @icloud.com but keeps allowing @private.icloud.com.
My guess is that the bounce rate got too high and bot farms were using iCloud addresses like this.
Because the bounce rate of Hide My Email addresses being deliverable is going to rise over time, by design.
Whenever I start getting spam at an address that's been leaked, I deactivate it. I've done the same with my oldest gmail account, but the work required there is notably higher.
Keeping it on a subdomain fixes that problem, to some degree. If the user is named ffjvhtu57325cjdjvg501a2@icloud.com no one is going to think that’s a real address. It’s very obviously a private one. So it’s not like they were “camouflaged.“
It’s a little odd they’re switching the subdomain though.
Like for my usage there are no bounce issues with the ~400 legitimate providers that I have Hide My Email addresses from. The only ones with bounce issues are the spammers who've acquired leaked addresses that I've deactivated.
They are not changing the subdomain. There isn’t one. The announcement is they are leaving it as-is.
The email addresses for sign-in with Apple do use the @private.iCloud.com subdomain, but again, that’s not a change.
I couldn't. "Uses Apple products" is one of the more reliable signals of willingness and ability to spend money on stuff online.
They’re not switching the subdomain. They’re keeping it the same. That’s the news.
They’re switching the subdomain for the “Sign in with Apple” sign ups, which is not the same service.
why would random selection from sets of predefined strings and joining them using a "." need any LLM involvement? Oh you need to check if it already taken... maybe for that? I'd use a database though...
These days some people would even generate GUIDs with some language model, I guess...
The generated words agree in grammatical gender and plural forms, so by definition it’s a language model.
The reason for random email addresses is YOU finally can identify each vendor uniquely by the email they send you stuff.
It isn't about anonymizing, it's about identifying them.
I've been doing it for 30+ years on my own domains.
The toplevel “Hide My Email” iCloud feature is a different thing, can be done independently of a SIWA flow (you can just go into settings and make more addresses, all it needs is a name and a notes field) and uses @icloud.com in order to make your anonymized email address look indistinguishable from other iCloud users.
The former is “filterable”, yes, but it’s moot because you only get those if you offer Sign In With Apple in the first place, and if you want real emails, you would already know to just… not do that.
The latter is very much not filterable.
The confusing thing though, is that when a user uses Sign In With Apple, they are offered two options: “share my email” which gives the site your real address, and “hide my email” which gives an @private.appleid.com address. But this “hide my email” option is a totally different thing from the separate “hide my email” service, which lets you make arbitrarily many @icloud.com private aliases to forward to your real address. Critically, the latter toplevel Hide My Email feature works with sites that don’t use Sign In With Apple. It’s just stupidly unfortunate that Apple calls both of these features “hide my email.”
[0]: https://developer.apple.com/app-store/review/guidelines/#sig...
For example, I can have hn@mydomain.com for hn only mails, if they share my mail address, I'll know.
However filtering for these hide my e-mail addresses is quite easy if you are motivated to do it, they have a recognizable pattern.
rtwnj6tj7@privaterelay.appleid.com
> Starting later this year, new Sign in with Apple addresses, previously issued on privaterelay.appleid.com, will be issued on private.icloud.com. Existing addresses on privaterelay.appleid.com will continue to work and forward mail to users without interruption.
> After further consideration and reviewing community feedback, iCloud+ Hide My Email addresses will remain on icloud.com.
A lot of those are Hide My Email aliases that, by design, you can’t tell apart from real human addresses.
They're now saying the new domain will be private.icloud.com. Isn't it just as targetable?
> Sign in with Apple addresses, previously issued on privaterelay.appleid.com, will be issued on private.icloud.com.
> iCloud+ Hide My Email addresses will remain on icloud.com.
Hide My Email is the manually generated ones, for websites that accept an arbitrary email address. This is the one where it's valuable for the relays to be identical to genuine iCloud addresses, otherwise websites could try to block it and force you to use a more revealing email address, undermining privacy.
If so, will be interesting to see if that will get worse.
Sign in with Apple email addresses are email addresses for the Sign in with Apple button.
If you dig more you could find the bug, but AFAIK it was that if you sent a large attachment, the bounce email would contain your real address.
A mitigation for the cause of https://www.404media.co/apple-hide-my-email-vulnerability-re...
> abc@icloud.com forwards to real@gmail.com
If they switched the new domain and did nothing else, it would say:
> abc@privaterelay.appleid.com forwards to real@gmail.com
That's no better. Fixing that privacy leak is unrelated to whatever the destination domain is.
02 Jul 2026 03:47:04 UTC | Apple 'Hide My Email' Vulnerability Reveals Peoples' Real Email Addresses | https://www.404media.co/apple-hide-my-email-vulnerability-re... | https://news.ycombinator.com/item?id=48756295
03 Jul 2026 22:56:51 UTC | Apple 'Hide My Email' Vulnerability Reveals Peoples' Real Email Addresses | https://www.404media.co/apple-hide-my-email-vulnerability-re... | https://news.ycombinator.com/item?id=48780999
04 Jul 2026 17:01:39 UTC | Security Roundup: Apple's Hide My Email Service Fails to Hide Your Email | https://www.wired.com/story/security-roundup-apples-hide-my-... | https://news.ycombinator.com/item?id=48786928
04 Jul 2026 18:54:24 UTC | Apple Hide My Email Reveals the Users Real Email | https://www.404media.co/apple-hide-my-email-vulnerability-re... | https://news.ycombinator.com/item?id=48787842
05 Jul 2026 06:26:38 UTC | Security Roundup: Apple's Hide My Email Service Fails to Hide Your Email | https://www.wired.com/story/security-roundup-apples-hide-my-... | https://news.ycombinator.com/item?id=48791735
07 Jul 2026 02:16:06 UTC | Apple 'Hide My Email' Vulnerability Reveals Peoples' Real Email Addresses | https://www.404media.co/apple-hide-my-email-vulnerability-re... | https://news.ycombinator.com/item?id=48812946
12 Jul 2026 01:05:37 UTC | Apple Hide My Email bug, possibly related to disclosure vulnerability | https://lapcatsoftware.com/articles/2026/7/2.html | https://news.ycombinator.com/item?id=48877353
Recommended reading:
19 Aug 2026 15:22:13 UTC | Alvarez vs. Apple, Inc. (N.D. Cal., July 15, 2026) [pdf] | https://ia803202.us.archive.org/25/items/gov.uscourts.cand.4... | https://news.ycombinator.com/item?id=49362811
21 Jul 2026 15:31:41 UTC | Apple Fixes Hide My Email Vulnerability After 404 Media Coverage | https://www.404media.co/apple-fixes-hide-my-email-vulnerabil... | https://news.ycombinator.com/item?id=48993637
23 Jul 2026 20:11:07 UTC | How Apple's Hide My Email exploit worked and why you're still at risk | https://easyoptouts.com/guides/apple-hide-my-email-was-leaki... | https://news.ycombinator.com/item?id=49027365
24 Aug 2026 20:24:44 UTC | Apple Won't Change Hide My Email Domain After Backlash | https://www.macrumors.com/2026/08/24/apple-hide-my-email-dom... | https://news.ycombinator.com/item?id=49425379
Yes, vendor lock in sucks, but I have $20k worth of apple hardware already so that ship has sailed and overall Im pretty happy with it.
been a user for a couple years now and no complaints
Neither visa nor MasterCard networks have the ability to verify cardholder name.
Everyone behaves as if they do, but your name cannot be verified.
Which is to say, all of these cards have name anonymization, not just robinhood.
But I haven't tried this, so ymmv.
https://en.wikipedia.org/wiki/Address_verification_service#:...
Vendors like Stripe may do more than Visa/MC though.