Apple is about to make Hide My Email useless
SXX
447 points
279 comments
June 16, 2026
Related Discussions
Found 5 related stories in 108.2ms across 10,715 title embeddings via pgvector HNSW
- Apple Gives FBI a User's Real Name Hidden Behind 'Hide My Email' Feature cdrnsf · 15 pts · March 26, 2026 · 69% similar
- Blackholing My Email semyonsh · 170 pts · April 07, 2026 · 56% similar
- Apple's AI Can Now Change Your Passwords. What Could Possibly Go Wrong? speckx · 78 pts · June 09, 2026 · 55% similar
- Apple Just Lost Me syx · 444 pts · March 25, 2026 · 54% similar
- Apple fixes bug that cops used to extract deleted chat messages from iPhones cdrnsf · 506 pts · April 22, 2026 · 52% similar
Discussion Highlights (20 comments)
mortenjorck
> Long story short: now both Sign in with Apple and Hide My Email aliases are going to be issued on the @private.icloud.com subdomain. This makes it much easier to ban all aliases without affecting non-relay mailboxes on iCloud mail. Could someone clarify why having Sign in with Apple and Hide My Email on the same domain would make a blanket ban easier rather than harder? What am I missing?
giancarlostoro
If your website will block me out because I used a privacy friendly email, I want nothing to do with your website.
nerdjon
I would bet that doing so would be a pretty quick way to have your app pulled. They already require that you use Sign in with Apple, I would think that it working fully is also a requirement?
jawiggins
> If you use iCloud+ and Hide My Email, there is still time to generate more aliases on @icloud.com as the change has not yet landed and the rate limit for creating aliases is at least 30 per hour. Part of the reason to use Hide My Email was that it made keeping myself private hassle-free. Making a system to pre-generate values and then catalog them for later use is quite the hassle.
risyachka
Shameless plug - I created a chrome extension that allows to create unique email addresses that forward to your real inbox. It uses Cloudflare email routing, simplifies creating/labeling of new addresses and keeping track of them. Always 1 click away. The addresses are pre-allocated and recycled when deleted so creating a new one is faster that with Apple's hide my mail. https://github.com/webmonch/hide-my-mail-cloudflare
wxw
I pay for Fastmail just for masked email and its integration with 1Password.
doctorpangloss
email isn't really a decentralized system at all. Google, Microsoft and Amazon own e-mail delivery. Perhaps Google ads customers complained that they could not correlated private @icloud addresses, and we are now witnessing the consequences. What Apple got in exchange from Google, I don't know, I'm sure it is related to their Siri deal.
Razengan
Oh fuck. I love Hide My Email and it's been the best feature about iCloud ever since it came out. It's actually useful compared to Gmail's useless "yourrealaddress+alais" that gives away your actual email anyway, and it helped me catch quite a few spammers/data sellers. Hide My Email addresses already have a peculiar format that others could guess, and some do block those, and there's no reason to add a blatant "private." tag. This is a win for privacy-intruders, not users, just like Apple's iCloud Keychain API that has allowed Facebook, TikTok etc. to secretly track users across multiple devices and device reinstalls for years.
Cider9986
Determined sites could already easily do this. Just detect the patterns used. I agree it's a useless change though. heave_balks_0g@icloud.com It shouldn't matter for the sign in with apple because sites are already expressly supporting that. Email aliasing is hard because you want privacy from a herd of users, but then you're locked into that ecosystem versus a domain you control has no herd, but the upside is no lock-in.
frollogaston
Maybe they've started seeing sites ban @icloud.com addresses
getcrunk
Okay but banning private relay emails would also mean your site is blocking Apple sign in?
righthand
Emailfake.com Fastmail also has wonderful random email functionality you can link up to your Bitwarden client or use the Fastmail API.
elcombato
The rate limit seems to be 20/hour and not 30/hour as mentioned in the article.
vslira
Where do I sign to show my opposition to this change? Hide My Email has been essential to keep my digital life protected from abusive mail lists and frankly one of the features that make me associate icloud with a premium service
KiDD
I guess I don't understand the concern... what does it matter if a different domain is used for Sign in with Apple and Hide My Email?
k1next
For me personally, Hide My Email is binding me to the Apple ecosystem more than iMessage (but I'm European).
kylehotchkiss
Did Hide My Email addresses cause problems for deliverability for actual emails/users on iCloud?
smth-smth-ai
simplelogin from Proton works great, can recommend; for Uber I generate uber.random-word@simplelogin.com, for Slack slack.random-word etc to easily see who leaked my email
jonotime
Pro tip for doing something like this without apple. Buy or get a cheap domain name. Create a subdomain on it and have it catch and forward all messages to you when sent to that sub. For example: nytimes@mailsub.example.com -> jono@gmail anything-else@mailsub.example.com -> jono@gmail You dont even need to materialize aliases at all.
trollbridge
In the flip side, someone who blocks private.iCloud.com will block the ability to do SSO with Apple, thereby cutting themselves off from Apple’s ecosystem.