Don't SPAM Me vs Apple Hide My Email

Excellent if you live inside Apple's ecosystem. The trade-off appears the moment you want to leave it.


If you already pay for iCloud+ and live on Apple devices, Hide My Email is excellent and costs you nothing extra. It's built into Sign in with Apple and into Safari's autofill, so generating an address is genuinely frictionless. Two limits matter: the addresses are on Apple's domain, and it works best inside Apple's ecosystem. Don't SPAM Me puts the aliases on a domain you own and works anywhere, but has no OS integration and no reply support.

Comparison

Apple Hide My EmailDon't SPAM Me
PriceIncluded with iCloud+ (subscription required)Free software + your domain
Address domain@icloud.comYour own domain
Number of addressesApple publishes no limitUnlimited
Creating an addressBuilt into iOS, macOS, Safari, Sign in with AppleAutomatic on first mail — type it into any form
Reply from the address in Mail✗ Not yet
Deactivate / reactivate✓ (hard SMTP 550)
Requires 2FA on the account
Custom domain✗ — separate iCloud+ feature (see below)✓ Required
Works outside Apple devicesVia iCloud.com, but the integration is the point✓ Any device, any client
Per-alias spam attribution
Leak alerts naming the sender
Survives leaving the provider
Apple facts from Apple's iCloud user guide. Checked: 2026-08-19. Apple's documentation states an iCloud+ subscription and two-factor authentication are required, that addresses can be stopped and reactivated, and that you can send and reply from them in Mail. No maximum number of addresses is published.

The confusion worth clearing up first

Hide My Email and Custom Email Domain are two different iCloud+ features

They get conflated constantly, including by people recommending them. Hide My Email generates random @icloud.com addresses that forward to you. Custom Email Domain lets you use your own domain with iCloud Mail.

They are separate features and Hide My Email addresses are not created on your custom domain. So "I have iCloud+ so I already have custom-domain aliases" is not quite right — you have custom-domain mailboxes, and separately you have random Apple-domain aliases.

What Apple does better

  • The integration. This is the real advantage and it's hard to overstate. Sign in with Apple offers to hide your address at the moment you're creating an account; Safari offers a Hide My Email address inline when you tap an email field. No other alias service can reach into the OS like that. The friction is close to zero, which matters more than any feature list because it determines whether you actually use it.
  • Replies work from within Mail.
  • It's already paid for if you subscribe to iCloud+ for storage, which many people do.
  • Apple's incentives are reasonable here. They sell hardware and subscriptions, not advertising against your mail.

Where it's limited

The addresses are Apple's

Every Hide My Email address ends @icloud.com. If you ever leave the Apple ecosystem — a work switch, a change of preference, a household consolidating on something else — every address has to be replaced at every service using it. For someone who has used Sign in with Apple across a few hundred accounts, that's a substantial project, and any account whose password reset goes to a dead address becomes a support ticket.

This is the general provider-domain problem and it applies to DuckDuckGo and Relay too. It's just more acute here, because the whole appeal is deep ecosystem integration — which is exactly what makes leaving expensive. The full argument.

The addresses are opaque

Hide My Email generates random addresses. You can label them, which helps inside Apple's interface, but the address itself tells you nothing. Seeing spam arrive at a random string doesn't identify the company at a glance; you have to look the label up.

With a readable per-service address the source is on the To: line. That's a small thing that compounds over a few hundred addresses.

It's ecosystem-shaped

Management happens through Apple's interfaces. It works via iCloud.com from anywhere, but if you're on Windows or Android day-to-day, you're using a tool designed for somewhere you aren't.

Who should pick which

If you…Choose
Already pay for iCloud+ and use Apple devicesApple Hide My Email — it's included and the integration is excellent
Want zero-friction address creation at signupApple Hide My Email
Need to reply from the addressApple Hide My Email
Use Windows, Android or Linux day-to-dayDon't SPAM Me
Might leave the Apple ecosystem one dayDon't SPAM Me
Want readable addresses that name the companyDon't SPAM Me
Want to know which company leaked each addressDon't SPAM Me
Don't want an iCloud+ subscriptionDon't SPAM Me, or DuckDuckGo Email Protection (free)

Using both

Perfectly sensible, and probably what a lot of Apple users should do. Hide My Email is hard to beat for casual signups where its OS prompt appears — the convenience means you'll actually use it. A custom domain makes more sense for the accounts you'd hate to lose: banking, government, utilities, anything where being locked out is a genuine problem.

Splitting on that basis costs nothing extra if you already have iCloud+ and gets you the convenience where it helps and the portability where it counts.

The verdict

If you're inside the Apple ecosystem and paying for iCloud+, use Hide My Email. It's included, it's well made, and the integration is genuinely better than anything a third party can offer.

Consider a custom domain for the accounts that matter, or if you're not confident you'll still be on Apple devices in five years. The cost of that hedge is a domain registration; the cost of not taking it is re-addressing your entire digital life at whatever point you change your mind.

More: all alias services compared · vs DuckDuckGo · custom domain vs provider domain

Give every service its own address

Don't SPAM Me puts unlimited aliases on a domain you own. Any address at that domain starts working the first time mail arrives, and when spam turns up you know exactly which company leaked it. The software is free; you bring the domain, or register one during setup.

Get started — free

Keep reading