Apple has reversed a planned change to its iCloud+ Hide My Email feature and will keep masked addresses on the @icloud.com domain instead of moving them to @private.icloud.com. The company changed course after users warned that the new domain would make disposable aliases easier for websites and apps to identify and potentially block during account creation, weakening one of the feature’s core privacy benefits. Apple said it made the decision after reviewing community feedback.
The reversal applies to Hide My Email aliases, which generate disposable forwarding addresses for iCloud+ users, but Apple still plans to migrate Sign in with Apple relay addresses from @privaterelay.appleid.com to @private.icloud.com later in 2026. Developers have been told to allow the new domain, while older relay addresses will continue forwarding without interruption. Reporting also noted that although Hide My Email obscures a user’s real address from services, Apple can still identify the account behind an alias for law-enforcement requests, and the feature previously faced scrutiny over a bug that exposed real email addresses in some spam-rejection scenarios before Apple fixed it.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
In June, Apple said it would unify the domains used by Sign in with Apple and Hide My Email under private.icloud.com, which would have moved Hide My Email aliases away from icloud.com.
Apple told developers whose apps or websites use Sign in with Apple to allow the private.icloud.com domain alongside privaterelay.appleid.com ahead of the relay-domain migration.
After user backlash and privacy concerns, Apple reversed its planned change to the Hide My Email feature and said aliases will continue using the icloud.com domain instead of private.icloud.com.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
techcrunch.com
Open sourcemacrumors.com
Open sourcedeveloper.apple.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.