Apple canceled its plan to move new iCloud+ Hide My Email aliases to @private.icloud.com: they will remain on @icloud.com. Users objected because a dedicated privacy domain would make masked addresses easy for websites to identify, block, or flag.
Published byEdited with GPT-5.6 LunaImages generated with GPT Image 1.5
Research answer

Create a landscape editorial hero image for this Studio Global article: What changes did Apple make to its iCloud+ Hide My Email and Sign in with Apple email-domain plans after community backlash, why did users o. Article summary: Apple abandoned the plan to issue new iCloud+ Hide My Email aliases under `@private.icloud.com`, but kept the corresponding change for new Sign in with Apple relay addresses. Apple said the reversal followed “further con. Topic tags: general, documentation, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks,
Apple has split its planned email-domain change in two. After announcing in June that both iCloud+ Hide My Email and Sign in with Apple would use @private.icloud.com, Apple said on August 24 that Hide My Email aliases will remain on @icloud.com. New Sign in with Apple addresses will still move from @privaterelay.appleid.com to @private.icloud.com later in 2026, and existing relay addresses will continue working without interruption. 10
Apple’s original plan was to consolidate newly generated addresses from both privacy features under @private.icloud.com. Existing Hide My Email aliases ending in @icloud.com and existing Sign in with Apple addresses ending in @privaterelay.appleid.com were expected to keep forwarding. 15
The revised plan is narrower:
@icloud.com.@private.icloud.com later in 2026.@privaterelay.appleid.com remain valid and continue forwarding.Apple attributed the Hide My Email reversal to “further consideration” and community feedback. It has not said that any particular security disclosure caused the decision. 10
The concern was not that changing the domain would automatically reveal the mailbox behind an alias. The concern was that @private.icloud.com would clearly identify an address as an Apple privacy relay.
A website or app could detect that domain with a simple domain check, then reject the address, require a different email, or treat it as a signal in fraud and risk screening. That would make the feature easier to block at signup. 44
By contrast, @icloud.com is also used for ordinary iCloud email addresses. A Hide My Email alias using that domain is less conspicuous to a service that is trying to distinguish masked addresses from conventional mailboxes. That distinction is central to the backlash: users feared the proposed change would reduce the feature’s practical privacy and its ability to preserve plausible deniability, even if Apple’s forwarding infrastructure itself remained unchanged. 35
Developers using Sign in with Apple should treat the change as a transition between relay domains rather than a replacement of the old one.
Update account systems, email validation rules, regular expressions, allowlists, and any domain-specific logic to accept new addresses ending in @private.icloud.com as well as existing addresses ending in @privaterelay.appleid.com. Apple’s earlier guidance also referenced @icloud.com in relay-domain handling, so systems should avoid assuming that there is only one valid Apple relay suffix. 8
10
Most importantly, do not migrate or invalidate existing users simply because their address uses the legacy domain. Apple says existing @privaterelay.appleid.com addresses will continue to work and forward mail without interruption. 10
If an app or website sends messages through Apple’s private email relay, developers must register the domains and subdomains used for outbound email in Apple’s developer account. Apple’s configuration guidance also requires the registered email sources to pass an SPF check. 6
That means teams should review:
Apple’s documentation describes the relay as forwarding messages to one of the user’s verified Apple Account email addresses. 3
The domain controversy arrived alongside separate reports about weaknesses in Apple’s privacy systems. Those incidents do not show that @private.icloud.com would itself leak an email address or IP address, but they help explain why users scrutinized a change that could make privacy aliases easier to classify.
A reported flaw in Hide My Email could expose the real address behind an alias when a message sent to the alias was rejected as spam. The underlying address could appear in sender-side mail-transfer logs, undermining the feature’s central privacy promise. Apple said it deployed a fix on July 3, 2026, and later testing reported that the issue could no longer be reproduced. 47
49
54
A patch does not necessarily erase historical exposure: third-party mail systems may retain older delivery logs. Reports therefore warned that addresses exposed before the fix could remain in records outside Apple’s control. 48
60
Researchers also reported that some WebKit-related traffic could bypass iCloud Private Relay and expose a user’s real IP address. The reported paths included passkey-related WebAuthn requests, WebTransport, and DNS prefetching. 19
20
23
A later report described an apparent fix in iOS 26.6.1, but the evidence in the available reporting concerns a reported patch rather than a broader explanation from Apple about the architecture or impact. 18
These issues involve different mechanisms from email-domain visibility. The Hide My Email flaw concerned address exposure through bounced mail, while the Private Relay reports concerned network traffic that could escape the relay path. Neither establishes that the proposed @private.icloud.com domain would directly disclose a user’s identity.
The direct explanation is community opposition to blockability: users argued that moving Hide My Email to a dedicated privacy domain would give websites an easy way to identify and reject aliases. Apple’s own announcement confirms the reversal followed community feedback. 10
The contemporaneous security disclosures are best understood as reputational context, not proven causation. They made confidence in Apple’s privacy safeguards more fragile, but Apple has not linked those reports to the domain decision. The practical result is a compromise: Hide My Email keeps the less conspicuous @icloud.com suffix, while Sign in with Apple developers must prepare to support @private.icloud.com alongside the legacy relay domain.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Apple canceled its plan to move new iCloud+ Hide My Email aliases to @private.icloud.com: they will remain on @icloud.com.
Apple canceled its plan to move new iCloud+ Hide My Email aliases to @private.icloud.com: they will remain on @icloud.com. Users objected because a dedicated privacy domain would make masked addresses easy for websites to identify, block, or flag.
Developers should accept both @privaterelay.appleid.com and @private.icloud.com, update validation and allowlists, and verify relay email domains and SPF records.
Apple canceled its plan to move new iCloud+ Hide My Email aliases to @private.icloud.com: they will remain on @icloud.com. Users objected because a dedicated privacy domain would make masked addresses easy for websites to identify, block, or flag.
Published byEdited with GPT-5.6 LunaImages generated with GPT Image 1.5
Research answer

Create a landscape editorial hero image for this Studio Global article: What changes did Apple make to its iCloud+ Hide My Email and Sign in with Apple email-domain plans after community backlash, why did users o. Article summary: Apple abandoned the plan to issue new iCloud+ Hide My Email aliases under `@private.icloud.com`, but kept the corresponding change for new Sign in with Apple relay addresses. Apple said the reversal followed “further con. Topic tags: general, documentation, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks,
Apple has split its planned email-domain change in two. After announcing in June that both iCloud+ Hide My Email and Sign in with Apple would use @private.icloud.com, Apple said on August 24 that Hide My Email aliases will remain on @icloud.com. New Sign in with Apple addresses will still move from @privaterelay.appleid.com to @private.icloud.com later in 2026, and existing relay addresses will continue working without interruption. 10
Apple’s original plan was to consolidate newly generated addresses from both privacy features under @private.icloud.com. Existing Hide My Email aliases ending in @icloud.com and existing Sign in with Apple addresses ending in @privaterelay.appleid.com were expected to keep forwarding. 15
The revised plan is narrower:
@icloud.com.@private.icloud.com later in 2026.@privaterelay.appleid.com remain valid and continue forwarding.Apple attributed the Hide My Email reversal to “further consideration” and community feedback. It has not said that any particular security disclosure caused the decision. 10
The concern was not that changing the domain would automatically reveal the mailbox behind an alias. The concern was that @private.icloud.com would clearly identify an address as an Apple privacy relay.
A website or app could detect that domain with a simple domain check, then reject the address, require a different email, or treat it as a signal in fraud and risk screening. That would make the feature easier to block at signup. 44
By contrast, @icloud.com is also used for ordinary iCloud email addresses. A Hide My Email alias using that domain is less conspicuous to a service that is trying to distinguish masked addresses from conventional mailboxes. That distinction is central to the backlash: users feared the proposed change would reduce the feature’s practical privacy and its ability to preserve plausible deniability, even if Apple’s forwarding infrastructure itself remained unchanged. 35
Developers using Sign in with Apple should treat the change as a transition between relay domains rather than a replacement of the old one.
Update account systems, email validation rules, regular expressions, allowlists, and any domain-specific logic to accept new addresses ending in @private.icloud.com as well as existing addresses ending in @privaterelay.appleid.com. Apple’s earlier guidance also referenced @icloud.com in relay-domain handling, so systems should avoid assuming that there is only one valid Apple relay suffix. 8
10
Most importantly, do not migrate or invalidate existing users simply because their address uses the legacy domain. Apple says existing @privaterelay.appleid.com addresses will continue to work and forward mail without interruption. 10
If an app or website sends messages through Apple’s private email relay, developers must register the domains and subdomains used for outbound email in Apple’s developer account. Apple’s configuration guidance also requires the registered email sources to pass an SPF check. 6
That means teams should review:
Apple’s documentation describes the relay as forwarding messages to one of the user’s verified Apple Account email addresses. 3
The domain controversy arrived alongside separate reports about weaknesses in Apple’s privacy systems. Those incidents do not show that @private.icloud.com would itself leak an email address or IP address, but they help explain why users scrutinized a change that could make privacy aliases easier to classify.
A reported flaw in Hide My Email could expose the real address behind an alias when a message sent to the alias was rejected as spam. The underlying address could appear in sender-side mail-transfer logs, undermining the feature’s central privacy promise. Apple said it deployed a fix on July 3, 2026, and later testing reported that the issue could no longer be reproduced. 47
49
54
A patch does not necessarily erase historical exposure: third-party mail systems may retain older delivery logs. Reports therefore warned that addresses exposed before the fix could remain in records outside Apple’s control. 48
60
Researchers also reported that some WebKit-related traffic could bypass iCloud Private Relay and expose a user’s real IP address. The reported paths included passkey-related WebAuthn requests, WebTransport, and DNS prefetching. 19
20
23
A later report described an apparent fix in iOS 26.6.1, but the evidence in the available reporting concerns a reported patch rather than a broader explanation from Apple about the architecture or impact. 18
These issues involve different mechanisms from email-domain visibility. The Hide My Email flaw concerned address exposure through bounced mail, while the Private Relay reports concerned network traffic that could escape the relay path. Neither establishes that the proposed @private.icloud.com domain would directly disclose a user’s identity.
The direct explanation is community opposition to blockability: users argued that moving Hide My Email to a dedicated privacy domain would give websites an easy way to identify and reject aliases. Apple’s own announcement confirms the reversal followed community feedback. 10
The contemporaneous security disclosures are best understood as reputational context, not proven causation. They made confidence in Apple’s privacy safeguards more fragile, but Apple has not linked those reports to the domain decision. The practical result is a compromise: Hide My Email keeps the less conspicuous @icloud.com suffix, while Sign in with Apple developers must prepare to support @private.icloud.com alongside the legacy relay domain.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Apple canceled its plan to move new iCloud+ Hide My Email aliases to @private.icloud.com: they will remain on @icloud.com.
Apple canceled its plan to move new iCloud+ Hide My Email aliases to @private.icloud.com: they will remain on @icloud.com. Users objected because a dedicated privacy domain would make masked addresses easy for websites to identify, block, or flag.
Developers should accept both @privaterelay.appleid.com and @private.icloud.com, update validation and allowlists, and verify relay email domains and SPF records.