Apple has reversed a planned change to iCloud+ Hide My Email that would have moved newly generated privacy aliases to a more obvious private.icloud.com domain, according to MacRumors. Hide My Email addresses will continue using Apple’s regular icloud.com domain, keeping the aliases less distinguishable from ordinary iCloud Mail addresses.
The reversal follows user criticism of a June plan to unify domains for Sign in with Apple and iCloud+ Hide My Email. Apple’s developer note at the time said future addresses for both services would use private.icloud.com, while Sign in with Apple aliases would move away from privaterelay.appleid.com. Apple’s latest message is short but consequential: “After further consideration and reviewing community feedback,” the company is keeping iCloud+ Hide My Email on icloud.com.
Why the domain mattered
Hide My Email lets iCloud+ subscribers create random addresses that forward to their real inbox, so a shopping site, newsletter, app, or online account does not need the user’s personal email address. Apple’s support pages describe the feature as a way to generate unique addresses in Safari, Mail, Apple Pay, iCloud settings, and supported third-party apps, then deactivate or manage them later if spam or unwanted messages arrive.
The feature depends partly on blending in. If an alias uses the same icloud.com domain as a normal iCloud email address, a website cannot reliably tell from the domain alone whether the user provided a privacy alias or a primary mailbox. A dedicated private.icloud.com suffix would have made the alias type obvious. Any service that wanted to discourage, flag, or block privacy aliases could have done so with a simple domain rule.
That is why the change drew a sharper reaction than a normal address-format tweak. For people using aliases to reduce tracking, contain spam, or separate accounts from their real identity, detectability is not a cosmetic problem. It can make the privacy tool less useful precisely at the moment a user is trying to avoid handing over a durable identifier.
What changes for users now
For iCloud+ Hide My Email users, the practical answer is simple: there is no migration to prepare for if Apple follows through on the reversal. New Hide My Email addresses should continue to use icloud.com, and existing iCloud+ aliases should keep working as before. Users can still create, label, deactivate, reactivate, or delete addresses through iCloud settings or iCloud.com, and replies can still route through the same alias so the real address stays hidden from the recipient.
Sign in with Apple is the piece to keep watching. Apple’s June developer announcement covered both Sign in with Apple and iCloud+ Hide My Email, but the reported reversal specifically addresses iCloud+ Hide My Email aliases. Developers and privacy-conscious users should watch Apple’s developer documentation for whether Sign in with Apple relay addresses remain on privaterelay.appleid.com, move to a different format, or receive a separate update.
Users who rely on aliases for sensitive accounts should still treat Hide My Email as one privacy layer, not a full anonymity system. Apple can forward mail because it operates the relay. The services you sign into still see other signals such as payment details, device fingerprints, phone numbers, shipping addresses, IP behavior, and account activity. An email alias reduces one durable identifier; it does not make the rest of an account private by default.
A quick privacy checkup
If you use Hide My Email heavily, this is a good moment to review the aliases already attached to important accounts. In iPhone or iPad settings, open your Apple Account, go to iCloud, then Hide My Email. On a Mac, the same controls are under System Settings, Apple Account, iCloud, and Hide My Email. On the web, Apple’s iCloud+ settings let you search addresses, copy one, edit its label or note, and change the forwarding address.
Keep aliases that protect accounts you still use. Deactivate aliases tied to sites that send unwanted mail or no longer need access to you. Be careful before deleting an inactive alias, because Apple’s support documentation warns that deletion is permanent and the address cannot be reactivated later.
The broader lesson is useful beyond Apple. Privacy features often fail not because encryption disappears, but because implementation details make private behavior easy to classify. Apple’s reversal keeps iCloud+ aliases harder to identify by domain, which is exactly the kind of small design choice that determines whether a consumer privacy feature works in the messy reality of websites, sign-up forms, spam filters, and anti-abuse systems.