An iPhone inbox with a Hide My Email forwarding alias visible, the kind of address Apple is about to move to a blockable subdomain
Photo via Unsplash

TL;DR: Apple told developers in a note on Monday June 15, 2026 that it will move every iCloud+ Hide My Email alias from @icloud.com to a new @private.icloud.com subdomain.[1] The reason Hide My Email works today is that aliases share the @icloud.com domain with regular Apple users and cannot be told apart from them. Moving the aliases to a distinct subdomain removes that cover. Any service that wants to block the feature can now do it with a single string match. The move is Apple's third privacy-product change in two weeks. iCloud+ subscribers get no compensation, no opt-out, and no advance notice beyond the developer note. Earlier in 2026, TechCrunch reported that Apple had already turned over the real account of a Hide My Email user to a subpoena tied to the girlfriend of FBI director Kash Patel.[1]

  • What the change is: every new Hide My Email alias will resolve under @private.icloud.com instead of @icloud.com. Existing aliases continue to forward mail without interruption, but new aliases will be on the new subdomain going forward.[1]
  • Why it matters: the @icloud.com domain is shared by tens of millions of regular Apple Mail users. Banning @icloud.com wholesale would cost the service real customers. The @private.icloud.com subdomain has no such cost. A single line in a blocklist, a single regex in a signup form, and every Hide My Email alias is rejected at the door.[1][2]
  • The Apple "plausible deniability" angle: developer Arseniy Shestakov, who flagged the change in a widely-shared developer post on June 16, framed the loss in the original terms. Some plausible deniability, together with Apple's backing, made banning iCloud aliases costly. The subdomain move removes the deniability. The aliases go from "indistinguishable from real Apple users" to "labeled."[2]
  • The unmasking precedent: the privacy guarantee of Hide My Email was already partial. Earlier in 2026, Apple complied with a subpoena and turned over the real account information of a Hide My Email user who had sent an allegedly threatening email to the girlfriend of FBI director Kash Patel. The Trump administration has been using subpoenas to demand that tech companies unmask anonymous accounts, including those of political critics. The subdomain change makes the unmasking cheaper at the same time it makes the alias more visible.[1]
  • The compensation question: iCloud+ is a paid subscription tier. The marketing for the tier has long leaned on the privacy features. Apple is degrading one of those features with no notice, no opt-out, and no refund. The TechCrunch piece is direct: Apple did not respond to a request for comment, and did not explain why the change was made.[1]
  • The third Apple privacy-product move in two weeks: the Apple Private Cloud Compute developer page was restricted to first-party Apple Intelligence features and a narrow App Store Small Business Program lane on June 14, 2026. The UK Apple ADP "secret order" story continued to develop in the same window. The Hide My Email subdomain move on June 15 is the third instance of the same pattern. Apple ships a privacy-marketed feature, then quietly narrows the privacy guarantee.[3][4]
  • What you can do right now: Shestakov's developer post is direct. If you use iCloud+ and Hide My Email, there is still time to generate more aliases on @icloud.com before the change lands, because the rate limit for creating aliases is at least 30 per hour. The aliases generated now stay on the old domain.[2]
  • Watch in the next 7 days: an Apple explanation for the change, the first major site that starts rejecting @private.icloud.com aliases at signup, the first iCloud+ subscriber refund request and Apple's response, and the first EFF or privacy-coalition public statement on the privacy-product-erosion pattern.

The Change: Aliases Move From @icloud.com to @private.icloud.com

TechCrunch security editor Zack Whittaker reported the change on June 16, 2026 at 3:09 PM PDT, citing an Apple note to developers sent the previous day.[1] The note told developers that "in the coming weeks" Apple will move all anonymously generated Hide My Email addresses to @private.icloud.com. The change applies to both Sign in with Apple and Hide My Email. Existing addresses will continue to function and forward mail without interruption. App and email providers will have to update their filtering to ensure that emails to customers who rely on the feature continue to go through. Apple did not respond to TechCrunch's request for comment on the change, or explain why the change was made.[1]

Hide My Email is an iCloud+ feature that generates anonymous email addresses under the @icloud.com domain, which then forward messages to a person's real email address. The reason these privately generated email addresses work is that they cannot be distinguished from regular Apple users, whose email addresses also use the @icloud.com domain. The change to @private.icloud.com is the reason the cover disappears. A new subdomain is a fingerprint. Every alias issued on the new subdomain is a single string match away from being blocked.[1]

The Hacker News thread for the Shestakov developer post landed 404 points and 254 comments at the 19:45 UTC scan on June 16, and crossed 350 points by the morning of June 17. The comment thread is dominated by the practical friction the change introduces: parking apps in Italy, public-services signup in Australia, and the long tail of services that already block temporary-mailbox domains and will add @private.icloud.com to the same list the day Apple flips the switch. The post-comment volume, not just the post-point count, is the public-concern signal. The commenters are not just developers. They are end users of services that already have a long history of refusing signups from privacy-domain email addresses.[5]

The Developer Take: Plausible Deniability Is the Whole Point of the Feature

Arseniy Shestakov, the developer who published the analysis, is the clearest voice on what the change actually does. His framing, in the developer post, is direct. The reason iCloud aliases have been harder to ban than a normal temporary-mailbox service is the cover. Plausible deniability, combined with Apple's backing, made banning iCloud aliases a costly move for any service that did it, because the blocklist would also hit real Apple users. With the move to @private.icloud.com, the cost goes away. The aliases are now labeled. Services that want to reject them can do it the same way they already reject mailinator.com, guerrillamail.com, and the rest of the temporary-mailbox blocklist.[2]

Shestakov also published a workaround. The change has not yet landed. The rate limit for creating aliases on @icloud.com is at least 30 per hour. If you use iCloud+ and Hide My Email, the window to bank @icloud.com aliases for the future is open right now. The aliases created before the switch stay on the old domain and keep forwarding mail after the switch.[2]

The structural critique is sharper than the workaround. Hide My Email was Apple's most visible privacy subscription feature. It was marketed as a way to keep a person's real email out of the databases that follow every signup, every breach, and every spam-list sale. The marketing was always partial. Apple has always been able to map a Hide My Email alias back to the real account, because the alias is just a forwarding rule on Apple's servers. The unmasking case from earlier in 2026 is the proof. The subdomain change does not make the mapping more powerful than it already was. It makes the alias itself more visible to the services that receive the mail, which is a different layer of the privacy problem and a different group of actors.[1]

The Unmasking Precedent: Apple Already Turned Over a Hide My Email User to the FBI

The unmasking risk was not theoretical. Earlier in 2026, TechCrunch reported that Apple had turned over the real account information of a user who generated an anonymized email address using Hide My Email to send an allegedly threatening email to the girlfriend of FBI director Kash Patel. The subpoena path is the structural risk of any server-side aliasing system. Apple holds the map from alias to real account. A subpoena gets the map.[1]

The Trump administration has been using subpoenas to demand that tech companies turn over information about their users, including critics of the administration. The unmasking effort is the policy backdrop to the Apple compliance pattern. The TechCrunch cybersecurity newsletter, which has covered the unmasking story in multiple issues, has been the public record.[1]

The subdomain change and the unmasking risk are not the same attack. The unmasking case was a server-side data request that went to Apple, which had the alias-to-account map. The subdomain change is a client-side fingerprint that any service can use to refuse the alias at signup, without ever contacting Apple. The two attacks compound. A service that would have accepted an @icloud.com alias in 2025 can refuse an @private.icloud.com alias in 2026, and a government that wants the real account behind an alias can serve Apple a subpoena and get it, with or without the subdomain change. Apple is degrading the front of the privacy stack at the same time the back of the privacy stack is the documented unmasking path. The combination is the privacy-product-erosion story, and it is the third instance in two weeks.[1]

The Subscriber Side: iCloud+ Costs Money. The Compensation Is Nothing.

iCloud+ is a paid subscription tier. The price starts at $0.99 per month for the entry tier and goes up from there. The marketing for the tier has, for years, leaned on the privacy features: Hide My Email, iCloud Private Relay, Advanced Data Protection, the lot. The marketing pitch is that you pay Apple for the privacy layer you cannot get from a free email provider or a free VPN.[1]

The subdomain move ships with no notice to subscribers, no opt-out, and no refund. The Apple developer note was the only public statement. TechCrunch asked Apple for comment on the change, and Apple did not respond. The TechCrunch piece does not describe a support article, a settings-page notice, an email to iCloud+ subscribers, or a refund mechanism. The pattern is the same one the Apple Private Cloud Compute developer-page restriction followed two days earlier: the change is announced in a developer channel, the marketing site keeps selling the feature, and the user is the last to know.[1][3]

The Apple Support guide for Hide My Email describes the feature in terms that the subdomain change directly undercuts. The guide frames Hide My Email as a way to keep a person's personal email address private, generate a unique, random address for each signup, and forward mail to the personal inbox. The guide does not warn that the alias may be refused at signup because of the subdomain. The guide does not warn that the alias can be unmasked via a subpoena. The guide does not warn that the feature is being quietly narrowed. The user who reads the support page today is being told a different story than the user who reads the developer note, and the developer note is the one that describes what is actually shipping.[6]

The Pattern: Apple's Third Privacy-Product Move in Two Weeks

The Hide My Email subdomain move is the third Apple privacy-product change in the two-week window between June 4 and June 17, 2026. The first was the Apple Private Cloud Compute developer-page restriction, published June 14, 2026. The PCC page now says the server-side foundation models are only available to first-party Apple Intelligence features and a narrow App Store Small Business Program lane. The marketing copy on the 2024 architecture announcement still calls PCC "the most advanced security architecture ever deployed for cloud AI compute at scale." The marketing and the developer page no longer describe the same product.[3]

The second was the continuation of the UK Apple Advanced Data Protection "secret order" coverage. The UK government invoked its investigatory-powers technical capability notice against Apple, demanding global backdoor access to iCloud Advanced Data Protection. Apple removed ADP for UK users rather than comply, then the order was quietly reissued. The pattern is the same one the Hide My Email subdomain move follows: Apple ships a privacy-marketed feature, then quietly narrows the privacy guarantee, and the user is the last to know.[4][7]

The third is the Hide My Email subdomain move. The three changes are not the same kind of change. The PCC restriction is a developer-channel change to access rules. The UK ADP story is a state compulsion story. The Hide My Email change is a product-marketing change to a default feature. The through-line is the same. Apple sells privacy as a subscription product. The subscription product is the thing being quietly narrowed. The user who is paying for the subscription is the last to find out. The pattern is what the Financial Times op-ed "Is Privacy the Latest Luxury?" was getting at, even if the FT piece is the cultural-side framing rather than the product-side one.[1][3]

What It Means for You

If you are an iCloud+ subscriber who uses Hide My Email, the most concrete action is the one Shestakov published: generate more aliases on @icloud.com now, before the switch lands. The rate limit is at least 30 per hour, and the aliases generated before the switch stay on the old domain and keep forwarding mail. The longer you wait, the fewer old-domain aliases you can bank. There is no published deadline from Apple for when the switch will happen, and there is no published transition period for existing aliases. Apple told TechCrunch only "in the coming weeks."[1][2]

If you are an iCloud+ subscriber who is paying for the privacy layer, the broader question is the one TechCrunch did not address and Apple did not answer. Is the subscription still worth the price? The marketing for the tier has not changed. The features being marketed are the same ones. The features themselves are being quietly narrowed. The compensation is nothing. The notice is a developer note. The refund mechanism, if it exists, has not been published.[1]

If you are a developer or a service operator, the operational question is the one Shestakov's post opens. The day Apple flips the switch, you can block every new Hide My Email alias at signup with a single regex match on @private.icloud.com. The block will not hit real Apple users, because the new subdomain is unique to the feature. The block will hit every user who took the Apple privacy marketing at face value. The decision to add the block is yours. The decision to make the block possible was Apple's.[2]

If you care about the privacy-as-subscription argument more broadly, the next twelve months are when the operational shape of the new regime gets set. The first major site to refuse @private.icloud.com aliases will set the precedent. The first iCloud+ subscriber refund request and Apple's response will set the compensation precedent. The first EFF or privacy-coalition statement on the privacy-product-erosion pattern will set the civil-society precedent. The pattern is not new. The cadence is.[3][4]

Sources

  1. TechCrunch: "Apple plans to change its Hide My Email privacy feature that could make it less effective" (Zack Whittaker, June 16, 2026, 3:09 PM PDT, the primary outlet reporting the Apple developer note of June 15, 2026, the @private.icloud.com subdomain move, the existing-aliases-continue-to-forward detail, the no-Apple-comment detail, the prior 2026 TechCrunch report on Apple turning over the real account of a Hide My Email user tied to the FBI director's girlfriend subpoena case, the Trump-administration subpoena effort to unmask anonymous accounts, and the TechCrunch cybersecurity newsletter context)
  2. Arseniy Shestakov: "Apple is about to make Hide My Email useless" (arseniyshestakov.com, June 16, 2026, the developer-side analysis that surfaced the Apple developer note of June 15, the plausible-deniability framing, the @private.icloud.com fingerprint, the comparison to free temporary mailboxes, the 30-per-hour rate limit for generating @icloud.com aliases, and the "still time to generate more aliases on @icloud.com" workaround)
  3. State of Surveillance: "Apple's Private Cloud Compute Is Severely Limited for Apps" (June 15, 2026, the Apple PCC developer-page restriction, the App Store Small Business Program lane, the Apple-Intelligence-only first-party access, the 2024 marketing copy that no longer matches the developer page, the same privacy-product-erosion pattern, and the same no-subscriber-compensation posture from two days earlier)
  4. State of Surveillance: "UK Apple ADP Secret Order: Inside the Global Encryption Fight" (the UK Apple Advanced Data Protection coverage, the investigatory-powers technical-capability-notice invocation, the Apple-removed-ADP-for-UK posture, and the same privacy-product-narrowing pattern from the same two-week window)
  5. Hacker News: "Apple is about to make Hide My Email useless" (news.ycombinator.com, HN id 48559935, June 16, 2026, 404 points and 254 comments at 19:45 UTC scan on June 16, the parking-app-in-Italy comment thread, the Australia app-only-services thread, the temporary-mailbox-blocklist comparison thread, and the public-concern signal in the comment volume)
  6. Apple Support: "Use Hide My Email in Mail" (support.apple.com, the live Apple Support user guide for Hide My Email, the keep-personal-email-private framing, the unique-random-address framing, the forward-to-inbox framing, and the absence of any warning about subdomain rejection or subpoena unmasking)
  7. State of Surveillance: "UK Apple Encryption Order Dropped, Then Reissued: A Pattern of Covert Legal Pressure" (the UK Apple encryption order dropped-then-reissued coverage, the same covert-legal-pressure pattern, and the same user-as-last-to-know posture)