Apple has abandoned the part of its email-alias shake-up that users objected to most: iCloud+ Hide My Email addresses will stay on icloud.com rather than moving to a new, dedicated relay domain. The reversal was published on 24 August in an update to Apple’s developer news feed, two months after the original plan went out.

What Apple is still changing, and what it is not
It is worth separating the two halves, because most of the plan survives. Apple’s 15 June announcement said it would unify both of its email-relay features under one shared domain, private.icloud.com: Sign in with Apple addresses would move off privaterelay.appleid.com, and Hide My Email addresses would move off icloud.com.
Only the second half has been dropped. Per Apple’s update:
- Sign in with Apple — new addresses still move to private.icloud.com. Apple’s June post described that as happening later in the summer; the August update says it starts later this year.
- iCloud+ Hide My Email — stays on icloud.com. No migration.
- Existing addresses — old privaterelay.appleid.com addresses keep working and keep forwarding mail, with no interruption.
Apple’s stated reason is short and unusually direct for a developer bulletin:
“After further consideration and reviewing community feedback, iCloud+ Hide My Email addresses will remain on icloud.com.”
— Apple, developer news update, 24 August 2026
Why the domain a privacy feature lives on actually matters
Hide My Email exists so you can hand a website a throwaway address that forwards to your real inbox, then kill it if the site starts spamming you or leaks your data. That only works if the site accepts the address in the first place.
A dedicated relay domain is trivially easy for a service to blocklist. If every alias ends in private.icloud.com, one regular-expression rule at signup can refuse the lot — and plenty of sites already do exactly that to disposable-mail providers, because a customer they cannot email a marketing blast to is a customer they would rather not have. Keeping the aliases on icloud.com makes that rule far more expensive: a company that blocks the domain also locks out every ordinary iCloud mail user it has.
That is the whole argument, and it is a good one. It is also a reminder of how fragile consumer privacy tools are when they depend on the other side’s cooperation. The feature is a paid one — Hide My Email is part of iCloud+ — and a change made for Apple’s internal tidiness would have quietly degraded what subscribers pay for. Reversing it is the right call; that it took public pushback to get there is the less flattering half of the story.
What developers need to do
The developer-facing work has not gone away, it has just narrowed. Apple’s instruction is that apps and websites using Sign in with Apple should make sure their account systems, email validation logic and allowlists accept addresses on the new private.icloud.com domain as well as the existing privaterelay.appleid.com one. Email service providers were separately told in June to update domain-based filtering, suppression lists and routing rules that enumerate relay domains by hand.
For anyone who has ever hit “this email address is not allowed” on a signup form while using an alias, that sentence is the one to hope gets read. As of 25 August, no other official statement on the reversal has surfaced.




