Apple's Hide My Email Domain Change, and the Half That Wasn't Reversed

Apple reversed the change for Hide My Email and not for Sign in with Apple. Most coverage missed the second half.


Apple reversed part of the change, not all of it. In June 2026 Apple said both Sign in with Apple and iCloud+ Hide My Email addresses would move to a new shared domain, private.icloud.com. On 24 August 2026 it confirmed Hide My Email addresses stay on icloud.com. Sign in with Apple addresses still move to private.icloud.com later in 2026. Existing addresses on the old domains keep working either way.

What Apple originally announced

Apple's developer news post, dated 15 June 2026, said two separate address systems would consolidate onto one new domain:

  • Sign in with Apple addresses, previously issued on privaterelay.appleid.com, would be issued on private.icloud.com.
  • iCloud+ Hide My Email addresses, previously issued on icloud.com, would also be issued on private.icloud.com.

The post told developers to accept the new domain in "account systems, email validation logic, and allowlists", and told email service providers to update "domain-based filtering, suppression lists, or routing rules that explicitly enumerate relay domains". Apple also stated that existing addresses on the legacy domains would continue to work and forward mail without interruption.

Quotations from Apple Developer News, 15 June 2026. Checked: 2026-08-28.

Why the second half of that upset people

The objection had nothing to do with the addresses breaking. It was about what a dedicated domain makes possible.

A Hide My Email address on icloud.com is indistinguishable from an ordinary iCloud mailbox. A site that wanted to refuse alias signups would have to refuse every iCloud user, which no consumer business is going to do. Move those addresses onto private.icloud.com and the calculation inverts: one domain in a blocklist rejects every Hide My Email address and nobody else. The privacy feature becomes a single line in a signup filter.

This is not hypothetical. It is exactly what already happens to the shared domains used by dedicated alias providers, which is why some sites reject alias addresses at signup. Camouflage was doing real work, and the change would have removed it.

What Apple decided on 24 August 2026

Apple said that after reviewing community feedback, iCloud+ Hide My Email addresses will remain on icloud.com.

Most coverage stopped there, and that is where the reporting gets sloppy. The reversal covers Hide My Email. It does not cover Sign in with Apple: those addresses are still scheduled to move from privaterelay.appleid.com to private.icloud.com later in 2026. Existing privaterelay.appleid.com addresses continue to work.

So if you use Hide My Email to sign up for newsletters and shops, nothing changes. If you use Sign in with Apple, your future relay addresses will sit on a domain that is trivially identifiable as a relay โ€” the change people objected to, applied to the other half of the system.

Reversal reported by 9to5Mac, 24 August 2026. Checked: 2026-08-28.

Do you need to do anything?

As a user, no. Apple has been explicit that addresses on legacy domains keep forwarding. There is no migration to perform and no deadline to meet.

If you run a site or a mailing system, yes, and it is the same job either way: stop enumerating relay domains. Any allowlist, suppression list or validation regex that hardcodes privaterelay.appleid.com or icloud.com needs private.icloud.com added. Lists like that break every time a provider adds a domain, which is roughly the point of this whole episode.

The part worth generalising

An entire privacy feature used by hundreds of millions of people had its usefulness put in question by a routine infrastructure decision โ€” announced in a developer post, reversed ten weeks later after complaints. Nobody using Hide My Email had a say, and nobody could have moved their addresses if the reversal hadn't come.

That is the structural property of any alias service that hosts your addresses on its domain. It applies to Hide My Email, to Firefox Relay, to DuckDuckGo Email Protection, to SimpleLogin's shared domains, and to us if we hosted addresses on ours. The provider owns the namespace, so the provider decides what happens to it โ€” including things done for good reasons that turn out badly for you.

The only version of this that doesn't have the property is aliases on a domain you registered yourself. Nobody can move it to a blockable subdomain, nobody can retire it, and a site that blocks it is blocking one customer rather than a category. That is the actual argument for a custom domain, and it holds whether you use our service or somebody else's.

Worth being honest about the cost: a domain is an annual bill and a small amount of setup, where Hide My Email is a toggle inside an iCloud+ subscription you may already pay for. For plenty of people that trade is not worth making, and this episode ended fine for them. It is the second time in three months that a provider-domain decision has been news, though, and it will not be the last.

More: what happens to your aliases if the service shuts down ยท Hide My Email alternatives ยท will websites block my alias

Common questions

Did Apple cancel the Hide My Email domain change?
Partly. On 24 August 2026 Apple confirmed that iCloud+ Hide My Email addresses will remain on icloud.com rather than moving to private.icloud.com. The change still applies to Sign in with Apple addresses, which move from privaterelay.appleid.com to private.icloud.com later in 2026.
Do I need to update my Hide My Email addresses?
No. Apple has stated that existing addresses on the legacy domains continue to work and forward mail without interruption. There is no migration for users to perform and no deadline. Site operators do need to add private.icloud.com to any allowlist or filter that enumerates relay domains.
Why did people object to private.icloud.com?
A Hide My Email address on icloud.com is indistinguishable from an ordinary iCloud mailbox, so a site cannot block aliases without blocking all iCloud users. A dedicated relay domain lets any site reject every Hide My Email address with a single entry in a signup filter, which removes the practical protection the addresses provide.

Give every service its own address

Don't SPAM Me puts unlimited aliases on a domain you own. Any address at that domain starts working the first time mail arrives, and when spam turns up you know exactly which company leaked it. The software is free; you bring the domain, or register one during setup.

Get started โ€” free

Keep reading