{"code":"var Component=(()=>{var p=Object.create;var o=Object.defineProperty;var u=Object.getOwnPropertyDescriptor;var m=Object.getOwnPropertyNames;var g=Object.getPrototypeOf,y=Object.prototype.hasOwnProperty;var w=(n,e)=>()=>(e||n((e={exports:{}}).exports,e),e.exports),f=(n,e)=>{for(var a in e)o(n,a,{get:e[a],enumerable:!0})},s=(n,e,a,r)=>{if(e&&typeof e==\"object\"||typeof e==\"function\")for(let t of m(e))!y.call(n,t)&&t!==a&&o(n,t,{get:()=>e[t],enumerable:!(r=u(e,t))||r.enumerable});return n};var v=(n,e,a)=>(a=n!=null?p(g(n)):{},s(e||!n||!n.__esModule?o(a,\"default\",{value:n,enumerable:!0}):a,n)),b=n=>s(o({},\"__esModule\",{value:!0}),n);var l=w((S,d)=>{d.exports=_jsx_runtime});var A={};f(A,{default:()=>c});var i=v(l());function h(n){let e={a:\"a\",blockquote:\"blockquote\",code:\"code\",em:\"em\",h2:\"h2\",h3:\"h3\",img:\"img\",li:\"li\",ol:\"ol\",p:\"p\",strong:\"strong\",ul:\"ul\",...n.components};return(0,i.jsxs)(i.Fragment,{children:[(0,i.jsx)(e.p,{children:'On 24 August 2026, Apple published a developer note with an unglamorous title: \"Update: New domain for Sign in with Apple.\" It contains one sentence that is genuinely interesting, and it is not the one about the new domain.'}),`\n`,(0,i.jsxs)(e.blockquote,{children:[`\n`,(0,i.jsxs)(e.p,{children:[\"After further consideration and reviewing community feedback, iCloud+ Hide My Email addresses will remain on \",(0,i.jsx)(e.code,{children:\"icloud.com\"}),\".\"]}),`\n`]}),`\n`,(0,i.jsxs)(e.p,{children:[\"That is Apple reversing a decision it announced ten weeks earlier. And the reason it reversed is a good illustration of something most people get wrong about how these privacy features actually work: \",(0,i.jsx)(e.strong,{children:\"for an email alias, being identifiable is the failure mode.\"})]}),`\n`,(0,i.jsx)(e.p,{children:(0,i.jsx)(e.img,{alt:\"Apple relay email domain change\",src:\"/images/blog/sign-in-with-apple-private-icloud-com-domain-change-hide-my-email-2026/hero.webp\",width:\"1024\",height:\"541\"})}),`\n`,(0,i.jsx)(e.h2,{id:\"key-takeaways\",children:\"Key Takeaways\"}),`\n`,(0,i.jsxs)(e.ul,{children:[`\n`,(0,i.jsxs)(e.li,{children:[(0,i.jsx)(e.strong,{children:\"Sign in with Apple relay addresses are moving\"}),\" from \",(0,i.jsx)(e.code,{children:\"privaterelay.appleid.com\"}),\" to \",(0,i.jsx)(e.code,{children:\"private.icloud.com\"}),\", starting later this year.\"]}),`\n`,(0,i.jsxs)(e.li,{children:[(0,i.jsx)(e.strong,{children:\"iCloud+ Hide My Email addresses are staying\"}),\" on \",(0,i.jsx)(e.code,{children:\"icloud.com\"}),\". Apple planned to move them in June and cancelled that in August.\"]}),`\n`,(0,i.jsxs)(e.li,{children:[(0,i.jsx)(e.strong,{children:\"Nothing you already use breaks.\"}),\" Existing addresses on the old domains keep working and keep forwarding.\"]}),`\n`,(0,i.jsxs)(e.li,{children:[(0,i.jsx)(e.strong,{children:\"The reversal exists because a dedicated domain is a blocklist entry.\"}),\" A site can reject an entire domain. It cannot reject \",(0,i.jsx)(e.code,{children:\"icloud.com\"}),\" without rejecting every real iCloud user.\"]}),`\n`,(0,i.jsxs)(e.li,{children:[(0,i.jsx)(e.strong,{children:\"Expect phishing to exploit this.\"}),\" A new, unfamiliar Apple domain appearing in your inbox is exactly the kind of change attackers build campaigns around.\"]}),`\n`]}),`\n`,(0,i.jsx)(e.h2,{id:\"three-different-things-all-called-private\",children:'Three Different Things, All Called \"Private\"'}),`\n`,(0,i.jsx)(e.p,{children:\"Before anything else, this needs untangling, because the June plan made intuitive sense only if you conflate two of these \\u2014 and the reason it was wrong is that they are not the same product.\"}),`\n`,(0,i.jsx)(e.h3,{id:\"1-sign-in-with-apples-private-email-relay\",children:\"1. Sign in with Apple's private email relay\"}),`\n`,(0,i.jsxs)(e.p,{children:['When you tap \"Sign in with Apple\" on an app or website and choose to hide your address, Apple generates a relay address for ',(0,i.jsx)(e.strong,{children:\"that specific developer\"}),\" and forwards their mail to you. It is free with any Apple Account.\"]}),`\n`,(0,i.jsxs)(e.ul,{children:[`\n`,(0,i.jsxs)(e.li,{children:[\"Current domain: \",(0,i.jsx)(e.code,{children:\"@privaterelay.appleid.com\"})]}),`\n`,(0,i.jsxs)(e.li,{children:[\"New domain: \",(0,i.jsx)(e.code,{children:\"@private.icloud.com\"}),\", for newly issued addresses, starting later this year\"]}),`\n`,(0,i.jsxs)(e.li,{children:[\"Managed on your Mac at \",(0,i.jsx)(e.strong,{children:\"System Settings \\u2192 [your name] \\u2192 Sign in with Apple\"})]}),`\n`]}),`\n`,(0,i.jsx)(e.h3,{id:\"2-icloud-hide-my-email\",children:\"2. iCloud+ Hide My Email\"}),`\n`,(0,i.jsx)(e.p,{children:\"A paid iCloud+ feature. You generate aliases yourself, for anything at all \\u2014 a newsletter, a form, a shop \\u2014 with a label and a note so you remember what each one was for. It is not tied to any sign-in flow.\"}),`\n`,(0,i.jsxs)(e.ul,{children:[`\n`,(0,i.jsxs)(e.li,{children:[\"Domain: \",(0,i.jsx)(e.code,{children:\"@icloud.com\"}),\" \\u2014 \",(0,i.jsx)(e.strong,{children:\"unchanged\"})]}),`\n`,(0,i.jsxs)(e.li,{children:[\"Managed on your Mac at \",(0,i.jsx)(e.strong,{children:\"System Settings \\u2192 [your name] \\u2192 iCloud \\u2192 Hide My Email\"})]}),`\n`,(0,i.jsx)(e.li,{children:\"Also available inline in Safari and Mail by clicking an address field and choosing Hide My Email\"}),`\n`]}),`\n`,(0,i.jsx)(e.h3,{id:\"3-icloud-private-relay\",children:\"3. iCloud Private Relay\"}),`\n`,(0,i.jsxs)(e.p,{children:['Not email at all. It is a two-hop relay for Safari browsing and certain unencrypted traffic, designed to keep any single party from seeing both who you are and what you are looking at. It shares the word \"relay\" and nothing else. We covered a real-world failure mode of this one in ',(0,i.jsx)(e.a,{href:\"/blog/icloud-private-relay-leaking-real-ip-address-passkeys-webkit-mac-2026\",children:\"iCloud Private Relay leaking your real IP address\"}),\".\"]}),`\n`,(0,i.jsxs)(e.p,{children:[\"The confusion is not the reader's fault: \",(0,i.jsx)(e.strong,{children:'both of the first two present a button labeled \"Hide My Email.\"'}),\" One gives you a \",(0,i.jsx)(e.code,{children:\"privaterelay.appleid.com\"}),\" address, the other an \",(0,i.jsx)(e.code,{children:\"icloud.com\"}),\" address, and Apple has never made the distinction loud. That shared label is almost certainly why unifying the domains looked tidy in June.\"]}),`\n`,(0,i.jsx)(e.h2,{id:\"what-apple-said-in-both-versions\",children:\"What Apple Said, in Both Versions\"}),`\n`,(0,i.jsx)(e.p,{children:\"Worth reading side by side, because the change is precise.\"}),`\n`,(0,i.jsx)(e.p,{children:(0,i.jsx)(e.strong,{children:\"15 June 2026:\"})}),`\n`,(0,i.jsxs)(e.blockquote,{children:[`\n`,(0,i.jsxs)(e.p,{children:[\"Later this summer, Apple will unify the email domains used by Sign in with Apple and iCloud+ Hide My Email under a single, shared domain: \",(0,i.jsx)(e.strong,{children:\"private.icloud.com\"}),\".\"]}),`\n`,(0,i.jsx)(e.p,{children:\"New addresses generated for both features will be issued on the new domain. For example:\"}),`\n`,(0,i.jsxs)(e.ul,{children:[`\n`,(0,i.jsxs)(e.li,{children:[\"Sign in with Apple addresses, previously issued on \",(0,i.jsx)(e.code,{children:\"privaterelay.appleid.com\"}),\", will be issued on \",(0,i.jsx)(e.code,{children:\"private.icloud.com\"}),\".\"]}),`\n`,(0,i.jsxs)(e.li,{children:[\"iCloud+ Hide My Email addresses, previously issued on \",(0,i.jsx)(e.code,{children:\"icloud.com\"}),\", will be issued on \",(0,i.jsx)(e.code,{children:\"private.icloud.com\"}),\".\"]}),`\n`]}),`\n`,(0,i.jsx)(e.p,{children:\"Existing addresses on the legacy domains will continue to work and forward mail to users without interruption.\"}),`\n`]}),`\n`,(0,i.jsx)(e.p,{children:(0,i.jsx)(e.strong,{children:\"24 August 2026:\"})}),`\n`,(0,i.jsxs)(e.blockquote,{children:[`\n`,(0,i.jsxs)(e.p,{children:[\"Starting later this year, new Sign in with Apple addresses, previously issued on \",(0,i.jsx)(e.code,{children:\"privaterelay.appleid.com\"}),\", will be issued on \",(0,i.jsx)(e.code,{children:\"private.icloud.com\"}),\". Existing addresses on \",(0,i.jsx)(e.code,{children:\"privaterelay.appleid.com\"}),\" will continue to work and forward mail to users without interruption.\"]}),`\n`,(0,i.jsxs)(e.p,{children:[\"After further consideration and reviewing community feedback, iCloud+ Hide My Email addresses will remain on \",(0,i.jsx)(e.code,{children:\"icloud.com\"}),\".\"]}),`\n`]}),`\n`,(0,i.jsx)(e.p,{children:'Two changes between them. Hide My Email is out of the migration. And the timeline moved from \"later this summer\" to \"starting later this year\" \\u2014 the original schedule has already slipped past, which is worth noting if you are planning around it.'}),`\n`,(0,i.jsx)(e.h2,{id:\"why-keeping-hide-my-email-on-icloudcom-is-the-right-call\",children:\"Why Keeping Hide My Email on icloud.com Is the Right Call\"}),`\n`,(0,i.jsx)(e.p,{children:\"Here is the mechanism, and it is worth understanding because it generalizes to every alias service.\"}),`\n`,(0,i.jsx)(e.p,{children:\"An email alias protects you only if the recipient cannot cheaply tell it is an alias. The moment a service can identify alias addresses, it can refuse them \\u2014 and services have strong incentives to refuse them, because an alias is a customer they cannot re-identify, cannot match against a data broker's records, and cannot keep reaching if you burn the address.\"}),`\n`,(0,i.jsx)(e.p,{children:\"John Gruber put the user's side of it directly when the reversal was announced:\"}),`\n`,(0,i.jsxs)(e.blockquote,{children:[`\n`,(0,i.jsx)(e.p,{children:'we often want to use such hidden email addresses on sites that would prefer to block those addresses and try to force us to use our \"real\" addresses'}),`\n`]}),`\n`,(0,i.jsxs)(e.p,{children:[\"A dedicated \",(0,i.jsx)(e.code,{children:\"private.icloud.com\"}),\" domain is a single string. Any signup form could reject it in one line of validation. Every alias Apple had ever issued would become simultaneously worthless at any site that added that line.\"]}),`\n`,(0,i.jsxs)(e.p,{children:[(0,i.jsx)(e.code,{children:\"icloud.com\"}),\" cannot be treated that way. It is the domain hundreds of millions of people use for their ordinary personal email. A service that blocks \",(0,i.jsx)(e.code,{children:\"icloud.com\"}),\" to stop aliases blocks a large share of its actual customers. \",(0,i.jsx)(e.strong,{children:\"Hide My Email's protection is not cryptographic \\u2014 it is that the aliases are hiding among real addresses.\"}),\" Moving them to a distinct domain would have removed the hiding place.\"]}),`\n`,(0,i.jsx)(e.p,{children:\"That is what Apple appears to have concluded, and it is the correct conclusion. It is also a rare example of a shipped plan being pulled back on a privacy argument rather than a technical one.\"}),`\n`,(0,i.jsx)(e.h2,{id:\"and-why-sign-in-with-apple-moving-is-not-the-same-problem\",children:\"And Why Sign in with Apple Moving Is Not the Same Problem\"}),`\n`,(0,i.jsx)(e.p,{children:\"It would be easy to finish that argument and conclude Apple has left Sign in with Apple users exposed. That is not right, and it is worth being precise about why.\"}),`\n`,(0,i.jsxs)(e.p,{children:[\"Sign in with Apple relay addresses were \",(0,i.jsx)(e.strong,{children:\"already\"}),\" on a dedicated, obviously identifiable domain. \",(0,i.jsx)(e.code,{children:\"privaterelay.appleid.com\"}),\" announces itself. Any service that wanted to reject them has been able to since 2019. Moving to \",(0,i.jsx)(e.code,{children:\"private.icloud.com\"}),\" is a lateral move on that axis \\u2014 a different identifiable domain, not a newly identifiable one.\"]}),`\n`,(0,i.jsx)(e.p,{children:\"There is also a structural reason the exposure matters less. A Sign in with Apple relay address is not something you type into a form. It is issued as part of an authentication flow that the site chose to offer. A site that does not want relay addresses does not implement Sign in with Apple. The blocking scenario that makes Hide My Email fragile does not really arise.\"}),`\n`,(0,i.jsxs)(e.p,{children:[\"So the honest summary is: \",(0,i.jsx)(e.strong,{children:\"Apple protected the feature that needed protecting and moved the one that did not.\"}),\" The June plan would have damaged one of them, and Apple caught it.\"]}),`\n`,(0,i.jsx)(e.p,{children:(0,i.jsx)(e.img,{alt:\"Comparing Apple's private email systems\",src:\"/images/blog/sign-in-with-apple-private-icloud-com-domain-change-hide-my-email-2026/content-1.webp\",width:\"1024\",height:\"572\"})}),`\n`,(0,i.jsx)(e.h2,{id:\"what-actually-changes-for-you\",children:\"What Actually Changes For You\"}),`\n`,(0,i.jsx)(e.p,{children:\"For most people, very little \\u2014 but the details are worth knowing before they surprise you.\"}),`\n`,(0,i.jsxs)(e.p,{children:[(0,i.jsx)(e.strong,{children:\"Your existing addresses do not change.\"}),\" Every \",(0,i.jsx)(e.code,{children:\"privaterelay.appleid.com\"}),\" address you already have keeps working and keeps forwarding. Apple says so explicitly in both announcements. You do not need to update anything, re-register anywhere, or migrate accounts.\"]}),`\n`,(0,i.jsxs)(e.p,{children:[(0,i.jsx)(e.strong,{children:\"New sign-ins will produce a domain you have not seen before.\"}),\" After the change, using Sign in with Apple on a new service issues an address at \",(0,i.jsx)(e.code,{children:\"private.icloud.com\"}),\". If you keep records of which alias went to which service, expect two domains in that list from here on.\"]}),`\n`,(0,i.jsxs)(e.p,{children:[(0,i.jsx)(e.strong,{children:\"A small number of sites will reject the new domain.\"}),\" Any service whose signup validation, allowlist, or anti-abuse rule hardcodes \",(0,i.jsx)(e.code,{children:\"privaterelay.appleid.com\"}),\" will not recognize \",(0,i.jsx)(e.code,{children:\"private.icloud.com\"}),\" until it is updated. Apple's note is explicitly asking developers to accept both. Not all of them will read it.\"]}),`\n`,(0,i.jsxs)(e.p,{children:[(0,i.jsx)(e.strong,{children:\"Corporate mail filtering may hold messages.\"}),\" If you use Sign in with Apple for anything work-adjacent and your organization filters by sender or recipient domain, a brand-new domain can land in quarantine.\"]}),`\n`,(0,i.jsx)(e.h2,{id:\"the-phishing-window\",children:\"The Phishing Window\"}),`\n`,(0,i.jsx)(e.p,{children:\"This is the part with a real security consequence, and it is the part nobody is writing about.\"}),`\n`,(0,i.jsxs)(e.p,{children:[\"Apple published this to developers. There is no consumer-facing announcement, no notification in Settings, no email to users. The first time most people encounter \",(0,i.jsx)(e.code,{children:\"private.icloud.com\"}),\" will be when it simply appears \\u2014 in a From line, in an account settings page, in a password manager entry.\"]}),`\n`,(0,i.jsxs)(e.p,{children:[\"An unfamiliar domain that genuinely belongs to Apple, appearing without warning, during a publicized transition, is close to ideal conditions for a phishing campaign. The messages practically write themselves: \",(0,i.jsx)(e.em,{children:\"your Apple relay address is being migrated, confirm your account to avoid losing access to services you signed in with.\"})]}),`\n`,(0,i.jsx)(e.p,{children:\"Some rules that hold regardless of this change:\"}),`\n`,(0,i.jsxs)(e.ul,{children:[`\n`,(0,i.jsxs)(e.li,{children:[(0,i.jsx)(e.strong,{children:\"Apple does not require you to do anything for this migration.\"}),\" Any message asking you to confirm, verify, migrate, or re-authenticate a relay address is fraudulent. There is no user-facing step, because there is no user-facing step.\"]}),`\n`,(0,i.jsxs)(e.li,{children:[(0,i.jsx)(e.strong,{children:\"Never act on a link in an email about your Apple Account.\"}),\" Open System Settings yourself and look. If a change is real, it is visible there.\"]}),`\n`,(0,i.jsxs)(e.li,{children:[(0,i.jsx)(e.strong,{children:\"Check where a link actually goes.\"}),\" \",(0,i.jsx)(e.code,{children:\"private.icloud.com\"}),\" is Apple. \",(0,i.jsx)(e.code,{children:\"private-icloud.com\"}),\", \",(0,i.jsx)(e.code,{children:\"privateicloud.com\"}),\", \",(0,i.jsx)(e.code,{children:\"private.icloud.com.example.net\"}),\", and \",(0,i.jsx)(e.code,{children:\"icloud-private.com\"}),\" are not. Attackers register lookalikes for exactly this kind of moment.\"]}),`\n`,(0,i.jsxs)(e.li,{children:[(0,i.jsx)(e.strong,{children:\"A password prompt you did not initiate is the signal.\"}),\" Legitimate macOS password prompts follow an action you just took. We covered how convincingly this can be faked in \",(0,i.jsx)(e.a,{href:\"/blog/fake-mac-crash-report-password-prompt-crashstealer-malware-protection-2026\",children:\"the fake Mac crash report password prompt\"}),\".\"]}),`\n`]}),`\n`,(0,i.jsxs)(e.p,{children:[\"If you want the broader hardening pass, our \",(0,i.jsx)(e.a,{href:\"/blog/mac-security-privacy-guide-2026\",children:\"Mac security and privacy guide\"}),\" covers the surrounding settings.\"]}),`\n`,(0,i.jsx)(e.h2,{id:\"auditing-what-you-actually-have\",children:\"Auditing What You Actually Have\"}),`\n`,(0,i.jsx)(e.p,{children:\"A good moment to look, since most people have never checked.\"}),`\n`,(0,i.jsx)(e.p,{children:(0,i.jsx)(e.strong,{children:\"Which apps use Sign in with Apple:\"})}),`\n`,(0,i.jsxs)(e.p,{children:[\"On a Mac, open \",(0,i.jsx)(e.strong,{children:\"System Settings\"}),\", click your name at the top of the sidebar, then \",(0,i.jsx)(e.strong,{children:\"Sign in with Apple\"}),\". You get every app and site where you used it, and you can stop using Sign in with Apple for any of them individually.\"]}),`\n`,(0,i.jsx)(e.p,{children:\"Read that list carefully before revoking anything. Turning off Sign in with Apple for a service breaks the relay address, which means the service can no longer reach you \\u2014 including for password resets. If you have no other login method registered there, you can lock yourself out. Set up an alternative sign-in first.\"}),`\n`,(0,i.jsx)(e.p,{children:(0,i.jsx)(e.strong,{children:\"Which Hide My Email aliases exist:\"})}),`\n`,(0,i.jsxs)(e.p,{children:[(0,i.jsx)(e.strong,{children:\"System Settings \\u2192 [your name] \\u2192 iCloud \\u2192 Hide My Email\"}),\". Each entry shows its label, its note, and the address it forwards to. You can deactivate an alias you no longer want, which stops delivery without deleting the record of what it was for.\"]}),`\n`,(0,i.jsx)(e.p,{children:(0,i.jsx)(e.strong,{children:\"Where mail is forwarded:\"})}),`\n`,(0,i.jsx)(e.p,{children:\"Same pane. If you have several personal addresses on your Apple Account, one of them is the forwarding target for all your aliases. Confirm it is one you still read \\u2014 a forwarding address you have abandoned is a silent failure that only surfaces when you need an account recovery message.\"}),`\n`,(0,i.jsx)(e.h3,{id:\"two-things-worth-doing-while-you-are-in-there\",children:\"Two things worth doing while you are in there\"}),`\n`,(0,i.jsxs)(e.p,{children:[(0,i.jsx)(e.strong,{children:\"Label your aliases properly.\"}),\" The note field exists so that in two years you can tell what an alias was for. An unlabelled alias is an address you will be afraid to deactivate.\"]}),`\n`,(0,i.jsxs)(e.p,{children:[(0,i.jsx)(e.strong,{children:\"Check that your recovery paths do not depend on a relay.\"}),\" If a critical account's only contact address is a Sign in with Apple relay, and you later revoke that app's access, recovery for that account goes with it. Keep at least one path that does not route through a relay you might turn off.\"]}),`\n`,(0,i.jsx)(e.p,{children:(0,i.jsx)(e.img,{alt:\"Auditing Sign in with Apple and Hide My Email\",src:\"/images/blog/sign-in-with-apple-private-icloud-com-domain-change-hide-my-email-2026/content-2.webp\",width:\"1024\",height:\"572\"})}),`\n`,(0,i.jsx)(e.h2,{id:\"for-developers-and-administrators\",children:\"For Developers and Administrators\"}),`\n`,(0,i.jsx)(e.p,{children:\"If you operate anything that touches email addresses, there is concrete work here. Apple's ask:\"}),`\n`,(0,i.jsxs)(e.blockquote,{children:[`\n`,(0,i.jsxs)(e.p,{children:[\"Developers with apps or websites that use Sign in with Apple should ensure that their account systems, email validation logic, and allowlists accept addresses on the new \",(0,i.jsx)(e.code,{children:\"private.icloud.com\"}),\" domain in addition to the existing \",(0,i.jsx)(e.code,{children:\"privaterelay.appleid.com\"}),\" domain.\"]}),`\n`]}),`\n`,(0,i.jsx)(e.p,{children:\"Specifically:\"}),`\n`,(0,i.jsxs)(e.ol,{children:[`\n`,(0,i.jsxs)(e.li,{children:[(0,i.jsx)(e.strong,{children:\"Accept both domains.\"}),\" Not a replacement \\u2014 both. Existing addresses on \",(0,i.jsx)(e.code,{children:\"privaterelay.appleid.com\"}),\" remain valid indefinitely.\"]}),`\n`,(0,i.jsxs)(e.li,{children:[(0,i.jsx)(e.strong,{children:\"Find the hardcoded strings.\"}),\" Grep your codebase and your configuration for \",(0,i.jsx)(e.code,{children:\"privaterelay.appleid.com\"}),\". It turns up in validation regexes, anti-fraud rules, analytics segmentation, deliverability allowlists, and support tooling.\"]}),`\n`,(0,i.jsxs)(e.li,{children:[(0,i.jsx)(e.strong,{children:\"Check your email service provider's rules.\"}),\" Domain-based routing, suppression lists, and reputation rules live outside your repository and are the easiest place for this to be missed.\"]}),`\n`,(0,i.jsxs)(e.li,{children:[(0,i.jsxs)(e.strong,{children:[\"Do not build new blocking on \",(0,i.jsx)(e.code,{children:\"private.icloud.com\"}),\".\"]}),\" Beyond being hostile to your own users, an address you reject at signup is a customer you did not acquire, and Sign in with Apple is an authentication method your app chose to offer.\"]}),`\n`,(0,i.jsxs)(e.li,{children:[(0,i.jsx)(e.strong,{children:\"Test the whole flow.\"}),\" Signup, verification email, password reset, and account recovery. A validation rule that accepts the address at registration but rejects it at password reset is a genuinely painful bug, and it is the common shape of this failure.\"]}),`\n`]}),`\n`,(0,i.jsxs)(e.p,{children:[\"For administrators: if you filter inbound mail by domain, add \",(0,i.jsx)(e.code,{children:\"private.icloud.com\"}),\" to whatever list \",(0,i.jsx)(e.code,{children:\"privaterelay.appleid.com\"}),\" is already on, before your users start reporting missing messages rather than after.\"]}),`\n`,(0,i.jsx)(e.h2,{id:\"what-the-relay-actually-hides\",children:\"What the Relay Actually Hides\"}),`\n`,(0,i.jsx)(e.p,{children:\"Worth being precise about, because people extend their trust in these features further than the features go.\"}),`\n`,(0,i.jsxs)(e.p,{children:[(0,i.jsx)(e.strong,{children:\"What the developer does not get:\"}),\" your real email address. They get a relay address and can send mail to it, which Apple forwards. If you revoke access, the relay stops and their address for you becomes dead.\"]}),`\n`,(0,i.jsx)(e.p,{children:(0,i.jsx)(e.strong,{children:\"What the developer does get:\"})}),`\n`,(0,i.jsxs)(e.ul,{children:[`\n`,(0,i.jsx)(e.li,{children:\"A stable identifier for you within their app. Sign in with Apple issues a per-developer user identifier that persists across sessions and devices, which is what lets them recognize you as a returning user. It is scoped to that developer \\u2014 the same Apple Account produces a different identifier at a different developer, so two apps cannot join their records on it.\"}),`\n`,(0,i.jsx)(e.li,{children:\"Your name, if you chose to share it, and you can edit it at the point of sign-in.\"}),`\n`,(0,i.jsx)(e.li,{children:\"Everything you subsequently tell them. The relay covers your address, not your behavior. If you type your real name into a profile field, you have handed it over.\"}),`\n`,(0,i.jsx)(e.li,{children:\"Whatever their analytics collect. Device fingerprinting, IP address, and advertising identifiers are entirely outside this feature's scope.\"}),`\n`]}),`\n`,(0,i.jsxs)(e.p,{children:[(0,i.jsx)(e.strong,{children:\"What Apple gets:\"}),\" the mail passes through Apple's servers to be forwarded. Apple states it does not read or retain the contents beyond what is needed to deliver, but the relay is by construction a path through Apple, not around it.\"]}),`\n`,(0,i.jsxs)(e.p,{children:[\"The clean way to think about it: \",(0,i.jsx)(e.strong,{children:\"a relay address is a revocable channel, not anonymity.\"}),' It solves \"this company sold my address to a data broker and now I cannot stop the mail.\" It does not solve \"this company knows who I am.\"']}),`\n`,(0,i.jsx)(e.p,{children:\"That is a genuinely valuable thing to solve, and the revocability is the underrated half \\u2014 being able to cut off one company's ability to reach you, without changing your address anywhere else, is something an ordinary mailbox has never offered.\"}),`\n`,(0,i.jsx)(e.h2,{id:\"how-this-compares-to-third-party-alias-services\",children:\"How This Compares to Third-Party Alias Services\"}),`\n`,(0,i.jsx)(e.p,{children:\"Apple is not the only option, and the comparison illuminates the blockability argument.\"}),`\n`,(0,i.jsxs)(e.p,{children:[(0,i.jsx)(e.strong,{children:\"Dedicated alias services\"}),\" \\u2014 SimpleLogin, AnonAddy, and similar \\u2014 give you unlimited aliases, usually on domains shared with all their other users. That shared domain is exactly the blocklist target the June plan would have created for Hide My Email, and it is why these services are widely rejected by signup forms. The better ones let you bring your own domain, which restores unblockability at the cost of registering and paying for a domain, and of that domain being uniquely yours if anyone correlates it.\"]}),`\n`,(0,i.jsxs)(e.p,{children:[(0,i.jsx)(e.strong,{children:\"Fastmail and similar providers\"}),\" offer masked addresses on your own domain or theirs, with the same trade-off.\"]}),`\n`,(0,i.jsxs)(e.p,{children:[(0,i.jsx)(e.strong,{children:\"Apple's iCloud+ Hide My Email\"}),\" is unusual precisely because of what just got preserved: its aliases live on \",(0,i.jsx)(e.code,{children:\"icloud.com\"}),\", alongside hundreds of millions of ordinary users. It is the only major alias service whose addresses are not distinguishable from real ones. That is a structural advantage no competitor can replicate, because no competitor operates a consumer mail domain at that scale.\"]}),`\n`,(0,i.jsx)(e.p,{children:\"The limitations are real. Apple's aliases forward to one address, there is no send-as from an alias outside Apple Mail on Apple devices, and you cannot use your own domain. If you want fine-grained routing and replies from arbitrary clients, a dedicated service does more. If you want an alias that simply gets accepted everywhere, Apple's is the strongest option available \\u2014 and it just stayed that way.\"}),`\n`,(0,i.jsx)(e.h2,{id:\"a-short-history-and-why-the-old-domain-was-always-odd\",children:\"A Short History, and Why the Old Domain Was Always Odd\"}),`\n`,(0,i.jsx)(e.p,{children:\"Sign in with Apple launched in 2019, and Apple's App Store review guidelines required apps offering third-party sign-in options to offer it as well \\u2014 which is why it appeared nearly everywhere at once rather than gradually. The private email relay was its most distinctive feature: other sign-in providers hand the developer your address, and Apple offered not to.\"}),`\n`,(0,i.jsxs)(e.p,{children:[\"The address it handed out instead was \",(0,i.jsx)(e.code,{children:\"@privaterelay.appleid.com\"}),\". That is a mouthful, it is on a domain most users have never otherwise encountered, and it announces its own nature. It made sense from Apple's side \\u2014 \",(0,i.jsx)(e.code,{children:\"appleid.com\"}),\" was where account infrastructure lived \\u2014 and from a user's side it has always looked slightly like something a phishing kit would invent.\"]}),`\n`,(0,i.jsxs)(e.p,{children:[\"Consolidating onto \",(0,i.jsx)(e.code,{children:\"private.icloud.com\"}),\" fixes that. \",(0,i.jsx)(e.code,{children:\"icloud.com\"}),\" is a domain ordinary people recognize, and a subdomain of it reads as legitimate in a way that \",(0,i.jsx)(e.code,{children:\"privaterelay.appleid.com\"}),\" never quite managed. For the sign-in relay, that is a straightforward improvement, and it is presumably the reasoning behind the whole exercise.\"]}),`\n`,(0,i.jsx)(e.p,{children:\"The June plan then over-applied it. Consolidation is good for the address that was already conspicuous. It was actively harmful for the one whose value came from being inconspicuous. That the fix took ten weeks and required public pushback is a small case study in how a change that improves one product can quietly degrade another that shares a name and a button.\"}),`\n`,(0,i.jsx)(e.h2,{id:\"troubleshooting-common-issues\",children:\"Troubleshooting Common Issues\"}),`\n`,(0,i.jsx)(e.h3,{id:\"a-website-rejects-my-new-apple-relay-address-as-invalid\",children:\"A website rejects my new Apple relay address as invalid\"}),`\n`,(0,i.jsxs)(e.p,{children:[(0,i.jsx)(e.strong,{children:\"Problem\"}),\": The site's email validation does not recognize \",(0,i.jsx)(e.code,{children:\"private.icloud.com\"}),\" yet.\"]}),`\n`,(0,i.jsxs)(e.p,{children:[(0,i.jsx)(e.strong,{children:\"Solution\"}),\": Report it to the site \\u2014 it is their bug and Apple has published the fix. In the meantime, an iCloud+ Hide My Email alias on \",(0,i.jsx)(e.code,{children:\"icloud.com\"}),\" will be accepted, since that domain is not changing and is indistinguishable from any ordinary iCloud address. That is precisely the property Apple preserved.\"]}),`\n`,(0,i.jsx)(e.h3,{id:\"mail-from-a-service-i-signed-into-with-apple-stopped-arriving\",children:\"Mail from a service I signed into with Apple stopped arriving\"}),`\n`,(0,i.jsxs)(e.p,{children:[(0,i.jsx)(e.strong,{children:\"Problem\"}),\": Several possibilities: the forwarding address on your Apple Account is one you no longer read, you revoked Sign in with Apple for that app, or your mail provider is filtering an unfamiliar domain.\"]}),`\n`,(0,i.jsxs)(e.p,{children:[(0,i.jsx)(e.strong,{children:\"Solution\"}),\": Check \",(0,i.jsx)(e.strong,{children:\"System Settings \\u2192 [your name] \\u2192 Sign in with Apple\"}),\" to confirm the app is still active, then verify your forwarding address under Hide My Email. Then check your spam and quarantine folders for the new domain.\"]}),`\n`,(0,i.jsx)(e.h3,{id:\"i-revoked-sign-in-with-apple-and-now-cannot-log-in\",children:\"I revoked Sign in with Apple and now cannot log in\"}),`\n`,(0,i.jsxs)(e.p,{children:[(0,i.jsx)(e.strong,{children:\"Problem\"}),\": Revoking access invalidates the relay address, and if that address was the account's only contact method, password reset has nowhere to go.\"]}),`\n`,(0,i.jsxs)(e.p,{children:[(0,i.jsx)(e.strong,{children:\"Solution\"}),\": Contact the service's support directly and explain \\u2014 this is a known situation and most have a manual path. To avoid it, register an alternative sign-in method \",(0,i.jsx)(e.em,{children:\"before\"}),\" revoking anything.\"]}),`\n`,(0,i.jsx)(e.h3,{id:\"i-received-an-email-about-my-apple-relay-address-changing\",children:\"I received an email about my Apple relay address changing\"}),`\n`,(0,i.jsxs)(e.p,{children:[(0,i.jsx)(e.strong,{children:\"Problem\"}),\": Apple is not sending users email about this. The migration requires nothing from you.\"]}),`\n`,(0,i.jsxs)(e.p,{children:[(0,i.jsx)(e.strong,{children:\"Solution\"}),\": Treat it as phishing. Do not click. Verify anything you are worried about by opening System Settings yourself.\"]}),`\n`,(0,i.jsx)(e.h3,{id:\"i-cannot-find-hide-my-email-in-settings\",children:\"I cannot find Hide My Email in Settings\"}),`\n`,(0,i.jsxs)(e.p,{children:[(0,i.jsx)(e.strong,{children:\"Problem\"}),\": It is an iCloud+ feature and requires a paid iCloud+ or Apple One subscription. Without one, only the free Sign in with Apple relay is available.\"]}),`\n`,(0,i.jsxs)(e.p,{children:[(0,i.jsx)(e.strong,{children:\"Solution\"}),\": Confirm your subscription under \",(0,i.jsx)(e.strong,{children:\"System Settings \\u2192 [your name] \\u2192 iCloud\"}),\". If you are not subscribed, Sign in with Apple's hide-address option still works, at no cost \\u2014 it is just scoped to sign-in flows rather than usable anywhere.\"]}),`\n`,(0,i.jsx)(e.h2,{id:\"faq\",children:\"FAQ\"}),`\n`,(0,i.jsx)(e.h3,{id:\"do-i-need-to-do-anything\",children:\"Do I need to do anything?\"}),`\n`,(0,i.jsx)(e.p,{children:\"No. Existing addresses keep working, and the change applies only to newly issued Sign in with Apple addresses. There is no user-facing migration step, which is exactly why any message claiming otherwise is fraudulent.\"}),`\n`,(0,i.jsx)(e.h3,{id:\"will-my-old-privaterelayappleidcom-addresses-stop-working\",children:\"Will my old privaterelay.appleid.com addresses stop working?\"}),`\n`,(0,i.jsx)(e.p,{children:\"No. Apple states in both announcements that existing addresses continue to work and forward without interruption. Apple has announced no end date for them.\"}),`\n`,(0,i.jsx)(e.h3,{id:\"why-did-apple-change-its-mind-about-hide-my-email\",children:\"Why did Apple change its mind about Hide My Email?\"}),`\n`,(0,i.jsxs)(e.p,{children:[`Apple's own wording is \"after further consideration and reviewing community feedback.\" The substance of that feedback was that a dedicated domain makes alias addresses trivially blockable, which defeats the feature. Keeping them on `,(0,i.jsx)(e.code,{children:\"icloud.com\"}),\" means they are indistinguishable from ordinary iCloud addresses.\"]}),`\n`,(0,i.jsx)(e.h3,{id:\"is-hide-my-email-the-same-as-sign-in-with-apples-hidden-address\",children:\"Is Hide My Email the same as Sign in with Apple's hidden address?\"}),`\n`,(0,i.jsxs)(e.p,{children:[\"No, though both present a button with that name. Hide My Email is a paid iCloud+ feature producing \",(0,i.jsx)(e.code,{children:\"icloud.com\"}),\" aliases you create for any purpose. Sign in with Apple's relay is free, tied to a specific app, and is the one moving to \",(0,i.jsx)(e.code,{children:\"private.icloud.com\"}),\".\"]}),`\n`,(0,i.jsx)(e.h3,{id:\"when-exactly-does-the-change-happen\",children:\"When exactly does the change happen?\"}),`\n`,(0,i.jsx)(e.p,{children:'Apple says \"starting later this year.\" The June announcement said \"later this summer,\" so the schedule has already moved once. No specific date has been published.'}),`\n`,(0,i.jsx)(e.h3,{id:\"does-this-affect-icloud-private-relay\",children:\"Does this affect iCloud Private Relay?\"}),`\n`,(0,i.jsx)(e.p,{children:\"No. iCloud Private Relay is a network privacy feature for Safari browsing and has nothing to do with email addresses, despite the shared word.\"}),`\n`,(0,i.jsx)(e.h3,{id:\"should-i-switch-my-important-accounts-to-hide-my-email-instead\",children:\"Should I switch my important accounts to Hide My Email instead?\"}),`\n`,(0,i.jsx)(e.p,{children:\"For accounts that matter, the more useful question is whether your recovery path survives the alias being turned off. Both systems are solid. The risk in both is the same: if an alias is an account's only contact method and you later deactivate it, recovery becomes difficult. Keep a second path on anything you cannot afford to lose.\"}),`\n`,(0,i.jsx)(e.h2,{id:\"conclusion\",children:\"Conclusion\"}),`\n`,(0,i.jsxs)(e.p,{children:[\"The headline change is small and needs nothing from you: new Sign in with Apple addresses will arrive on \",(0,i.jsx)(e.code,{children:\"private.icloud.com\"}),\", old ones keep working, and the only people with real work to do are developers who hardcoded a domain string somewhere.\"]}),`\n`,(0,i.jsx)(e.p,{children:`The part worth remembering is the part Apple undid. A privacy feature that everyone can identify is not a privacy feature \\u2014 and Apple's June plan, which looked like sensible consolidation, would have taken an alias system whose entire protection is that it blends in with ordinary mail and given it a label anyone could filter on. That got caught, publicly, and reversed in ten weeks. Which is both a good outcome and a reminder that \"unify these two things that share a button\" is a design instinct that deserves a second look when one of them depends on being unremarkable.`}),`\n`,(0,i.jsx)(e.p,{children:\"Meanwhile: Apple will not email you about this. Anyone who does is not Apple.\"}),`\n`,(0,i.jsx)(e.p,{children:(0,i.jsxs)(e.em,{children:[\"Related reading: \",(0,i.jsx)(e.a,{href:\"/blog/icloud-private-relay-leaking-real-ip-address-passkeys-webkit-mac-2026\",children:\"iCloud Private Relay leaking your real IP address\"}),\", \",(0,i.jsx)(e.a,{href:\"/blog/mac-security-privacy-guide-2026\",children:\"the Mac security and privacy guide\"}),\", and \",(0,i.jsx)(e.a,{href:\"/blog/fake-mac-crash-report-password-prompt-crashstealer-malware-protection-2026\",children:\"fake Mac password prompts and how to spot them\"}),\".\"]})})]})}function c(n={}){let{wrapper:e}=n.components||{};return e?(0,i.jsx)(e,{...n,children:(0,i.jsx)(h,{...n})}):h(n)}return b(A);})();\n;return Component;","toc":[{"title":"Key Takeaways","url":"#key-takeaways","depth":2},{"title":"Three Different Things, All Called \"Private\"","url":"#three-different-things-all-called-private","depth":2},{"title":"1. Sign in with Apple's private email relay","url":"#1-sign-in-with-apples-private-email-relay","depth":3},{"title":"2. iCloud+ Hide My Email","url":"#2-icloud-hide-my-email","depth":3},{"title":"3. iCloud Private Relay","url":"#3-icloud-private-relay","depth":3},{"title":"What Apple Said, in Both Versions","url":"#what-apple-said-in-both-versions","depth":2},{"title":"Why Keeping Hide My Email on icloud.com Is the Right Call","url":"#why-keeping-hide-my-email-on-icloudcom-is-the-right-call","depth":2},{"title":"And Why Sign in with Apple Moving Is Not the Same Problem","url":"#and-why-sign-in-with-apple-moving-is-not-the-same-problem","depth":2},{"title":"What Actually Changes For You","url":"#what-actually-changes-for-you","depth":2},{"title":"The Phishing Window","url":"#the-phishing-window","depth":2},{"title":"Auditing What You Actually Have","url":"#auditing-what-you-actually-have","depth":2},{"title":"Two things worth doing while you are in there","url":"#two-things-worth-doing-while-you-are-in-there","depth":3},{"title":"For Developers and Administrators","url":"#for-developers-and-administrators","depth":2},{"title":"What the Relay Actually Hides","url":"#what-the-relay-actually-hides","depth":2},{"title":"How This Compares to Third-Party Alias Services","url":"#how-this-compares-to-third-party-alias-services","depth":2},{"title":"A Short History, and Why the Old Domain Was Always Odd","url":"#a-short-history-and-why-the-old-domain-was-always-odd","depth":2},{"title":"Troubleshooting Common Issues","url":"#troubleshooting-common-issues","depth":2},{"title":"A website rejects my new Apple relay address as invalid","url":"#a-website-rejects-my-new-apple-relay-address-as-invalid","depth":3},{"title":"Mail from a service I signed into with Apple stopped arriving","url":"#mail-from-a-service-i-signed-into-with-apple-stopped-arriving","depth":3},{"title":"I revoked Sign in with Apple and now cannot log in","url":"#i-revoked-sign-in-with-apple-and-now-cannot-log-in","depth":3},{"title":"I received an email about my Apple relay address changing","url":"#i-received-an-email-about-my-apple-relay-address-changing","depth":3},{"title":"I cannot find Hide My Email in Settings","url":"#i-cannot-find-hide-my-email-in-settings","depth":3},{"title":"FAQ","url":"#faq","depth":2},{"title":"Do I need to do anything?","url":"#do-i-need-to-do-anything","depth":3},{"title":"Will my old privaterelay.appleid.com addresses stop working?","url":"#will-my-old-privaterelayappleidcom-addresses-stop-working","depth":3},{"title":"Why did Apple change its mind about Hide My Email?","url":"#why-did-apple-change-its-mind-about-hide-my-email","depth":3},{"title":"Is Hide My Email the same as Sign in with Apple's hidden address?","url":"#is-hide-my-email-the-same-as-sign-in-with-apples-hidden-address","depth":3},{"title":"When exactly does the change happen?","url":"#when-exactly-does-the-change-happen","depth":3},{"title":"Does this affect iCloud Private Relay?","url":"#does-this-affect-icloud-private-relay","depth":3},{"title":"Should I switch my important accounts to Hide My Email instead?","url":"#should-i-switch-my-important-accounts-to-hide-my-email-instead","depth":3},{"title":"Conclusion","url":"#conclusion","depth":2}],"estimatedTime":20}