Apple reversed one of its more quietly alarming privacy decisions: the June 2026 plan to migrate iCloud+ Hide My Email addresses from icloud.com to a new private.icloud.com domain. The reversal was announced August 24 after months of community pressure — but there’s a catch that most coverage is glossing over. Apple only partially backed down. Sign in with Apple is still moving to private.icloud.com, and developers who haven’t updated their allowlists are going to break login flows for new users when that rollout begins.
Why Moving the Domain Would Have Killed the Feature
Hide My Email generates random alias addresses — something like xk9p.abc@icloud.com — that forward to your real inbox. The entire privacy model depends on one thing: those aliases live on @icloud.com, the same domain used by hundreds of millions of real Apple users. A service that wants to block Hide My Email aliases would have to block all of icloud.com, which means blocking real customers. That’s the protection.
Move to @private.icloud.com, and you’ve just created a dedicated, easily-blockable domain. Any service can add a single rule — “reject @private.icloud.com” — and the feature becomes useless overnight. This is exactly what happened to SimpleLogin, Firefox Relay, and AnonAddy: all excellent alias services, all trivially blocked because their domains are known and separate. Apple was about to hand sites and apps a single-line email filter that would neuter a legitimate privacy tool. The community noticed, and apparently Apple heard.
What Actually Changed (And What Didn’t)
Here’s the nuance that most headlines are missing: Apple reversed on Hide My Email specifically. Those addresses stay on @icloud.com. But Sign in with Apple — the OAuth-style login service — is still moving to private.icloud.com for new relay addresses. Existing Sign in with Apple accounts on privaterelay.appleid.com continue to work. Only new accounts, after the rollout begins, get the new domain.
The timeline is frustratingly vague: Apple’s updated developer notice says the change happens “later in 2026.” No specific date. Which means developers who use Sign in with Apple need to act now, not when the rollout date becomes clearer.
What Developers Need to Update
If your app or website supports Sign in with Apple with the “hide my email” option, you need to update your email handling to accept both domains:
privaterelay.appleid.com— existing users, unchangedprivate.icloud.com— new users after rollout
That means updating email validation regex, allowlists, and any email service provider suppression rules that pattern-match on domain names. The failure mode is silent and bad: new users who sign up with Sign in with Apple after the rollout begins will get rejected at account creation with no clear explanation.
The Question Apple Still Hasn’t Answered
What’s still unexplained is why Apple proposed this change at all. The June 2026 announcement came with no rationale — no infrastructure explanation, no user benefit framing, nothing. TechCrunch noted Apple’s unusual silence at the time, and the Hacker News thread (390 points) filled the void with speculation: regulatory pressure, government data access requirements, internal consolidation. None of it confirmed, all of it plausible.
The reversal on Hide My Email is a genuine win — community feedback moved a major tech company to pull back a bad decision. But the original motivation is still opaque, which means this conversation probably isn’t over. If the reason was regulatory, a domain change won’t be the last attempt to make privacy relay addresses identifiable.
The Bottom Line
Hide My Email users: your aliases stay on @icloud.com. The feature works the same way it always has. Developers: you’re not off the hook. Update your Sign in with Apple integrations before “later in 2026” arrives unannounced and breaks new user signups. The partial reversal is worth celebrating — just don’t let it distract from the action item buried in Apple’s own developer notice.













