Apple reverses Hide My Email domain change to preserve user privacy
Apple has walked back a planned shift for its masked email addresses, keeping them on the standard iCloud domain to prevent websites from identifying and blocking them during sign-up.

Apple has reversed a technical decision that threatened to undermine the core privacy function of its Hide My Email feature. The company confirmed the change in a developer note on Monday, stating that new masked addresses will remain on the standard @icloud.com domain rather than migrating to a new @private.icloud.com address.
The original plan, announced in June, would have allowed websites to distinguish between a user’s real email address and a random one generated by the service. Critics argued that this distinction would render the feature largely ineffective, as companies could easily block the new domain during the sign-up process to ensure they were capturing a verifiable identity.
Hide My Email is a feature included with Apple’s iCloud+ subscription that generates random email addresses to protect user identity. By keeping masked addresses on the same domain as real ones, Apple ensures that websites cannot tell whether they are dealing with a genuine user or a privacy shield.
Apple did not officially explain the rationale for the reversal in its developer note. However, John Gruber of Daring Fireball reported that employees on the Hide My Email team had "strong objections" to the change, a sentiment shared by users on social media platforms such as Reddit.
The domain change will still proceed for a different segment of Apple’s email-relay system. New Sign in with Apple addresses are scheduled to move to the @private.icloud.com domain later this year. This shift is less controversial because websites already know a user is signing in with Apple, meaning the distinct domain does not expose the same level of privacy risk.
The reversal comes after earlier scrutiny of the feature’s reliability. Earlier this year, Apple patched a bug that allowed the real email address behind a mask to be viewed. The company reportedly knew of the exploit for at least a year before fixing it, following coverage by 404 Media.

