Email
Email

A modern blog built with Payload CMS, Next.js, and shadcn/ui.

RSS FeedSitemap

Explore

  • Blog
  • News
  • Statistics
  • Authors

Categories

  • Hiring & Team Building
  • Email Campaign Strategy
  • Email Design & Templates
  • Email Compliance & Legal
  • Email Deliverability & Best Practices
  • Career Development
  • Email Strategy for Finance & Professional Services
  • Email Marketing Metrics

Latest articles

  • How to Hire an Email Marketing SpecialistJul 22, 2026
  • Email Marketing Campaigns Template: Ready-to-UseJul 22, 2026
  • Canva Email Marketing Templates: Design Fast, Convert MoreJul 22, 2026
  • Email Marketing Templates for FranchisesJul 22, 2026

Popular topics

  • #Specialist Skills
  • #Team Building
  • #Templates
  • #Canva
  • #Advanced Strategies
  • #multi-location businesses
  • #Marketing Regulations
  • #Lead Follow-Up
  • #iCloud Email
  • #Marketing Management
  • #Product Launch
  • #Electrician Marketing
  • #statistics
  • #Budget-Friendly
  • #Free Resources
  • #Miami businesses

Stay in the loop

Join 2,000+ readers. Unsubscribe anytime.

Subscribe
Email

© 2026 Email. All rights reserved.

SitemapRSS
HomeNewsApple Fixes Hide My Email Leak After 1-Year Delay
Email Deliverability

Apple Fixes Hide My Email Leak After 1-Year Delay

Apple patched a year-old Hide My Email vulnerability that exposed real addresses via spam logs. Delayed fix raises deliverability trust concerns.

R

Rachel Torres

July 22, 2026

6 min read
Share:
#Compliance#Email Security#iCloud Email#Sender Reputation
Illustration for new_technology: Apple Fixes Hide My Email Leak After 1-Year Delay

Stay in the loop

Get the latest posts delivered straight to your inbox. No spam, unsubscribe anytime.

Apple patched a significant security flaw in its iCloud+ Hide My Email feature on July 3, 2026, more than 13 months after the vulnerability was first reported. The fix only came after a tech news outlet made the bug public, raising serious questions about how one of Apple's most-marketed privacy tools handled a known exposure gap for over a year.

What the Flaw Actually Did

Hide My Email generates unique, random email addresses that forward messages to a user's personal inbox, with the purpose of safeguarding user privacy and reducing unwanted spam. The feature requires a paid iCloud+ subscription and was introduced by Apple in June 2021.

The flaw undermined that promise in a specific but serious way. Murphy discovered that sending a specially crafted email that was rejected as spam could cause the recipient's real email address to appear in mail transfer logs. If someone sent a message to a hidden address and it bounced as spam, the user's actual email address could get exposed in the sender's mail logs, and the user would have no way of knowing it happened, since a bounced message never lands in their inbox.

The vulnerability did not expose passwords, Apple Accounts, or inbox contents. Instead, it undermined Hide My Email's core privacy promise by potentially allowing an alias to be linked back to a user's permanent email address.

According to Murphy and his EasyOptOuts co-founder Ben Weiner, as reported by iClarified, "For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message."

A Year of Inaction Before a Public Disclosure Forced the Fix

404 Media reported that a fix was deployed by Apple on July 3, 2026, after more than a year since the vulnerability was disclosed to the company by Tyler Murphy, co-founder of EasyOptOuts.

The timeline tells a frustrating story. Murphy reported the flaw in June 2025, but despite Apple claiming it was resolved in March 2026, independent tests confirmed it remained exploitable at least until July 3, 2026. In the following months, Apple said it was again looking into the problem, but Murphy was unconvinced Apple would actually address it, so he contacted 404 Media to make it public.

After another unsuccessful fix attempt in late June, he contacted 404 Media, which published the story on July 1. Apple deployed the patch two days later.

The vulnerability turned out to be fairly low-tech, failing to hide the main email address in spam email logs that were bounced back to the sender after being rejected.

The Fix Is In, But Older Aliases May Still Be Exposed

Apple says it fixed the vulnerability on or around July 3, but AppleInsider successfully reproduced the flaw two weeks after the company's claimed repair date. By July 21, both Apple and Murphy confirmed the bug had been fully resolved.

Even so, the researcher's warning to users is pointed. As Engadget reports, Murphy stated: "Because non-malicious emails could bounce, revealing your hidden email address, and because mail transfer logs are often retained, we'd assume that any hidden email address linked to a Hide My Email address created before July 7, 2026, may have been exposed and could still be in third-party logs."

Users should treat real addresses attached to older aliases as potentially disclosed, and understand that deleting an alias will not erase information already retained in another provider's logs.

Legal Fallout and What It Means for Marketers

The disclosure prompted legal action. Per the class action complaint, researchers first reported the flaw in June 2025, and while Apple acknowledged the report, the company allegedly "took no action for nearly a year" while researchers finally went public in July 2026 after a year of inaction and no security update from Apple. The plaintiff states he is one of the millions of customers who paid Apple for iCloud+ and relied on Apple's representations that Hide My Email would keep his personal email address hidden.

For email marketers and growth teams, this story carries a practical implication beyond the privacy debate. Subscribers who use Hide My Email addresses ending in @privaterelay.appleid.com or @icloud.com are doing so because they want to guard their real identity from the services they sign up with. Seeing an unusual increase in iCloud addresses on your list may signal that people don't trust your brand, and as one email deliverability expert noted, "This has always been a reflection of the level of trust the recipient has with your business or org." Apple Hide My Email privacy flaw concept illustration showing a relay address icon with a warning or shield symbol, representing the security vulnerability in Apple's iCloud+ Hide My Email feature that allowed email bounces and list suppression issues

When subscribers use alias addresses, it affects suppression management, re-engagement campaigns, and list hygiene. If a relay address bounces (as this flaw demonstrated was possible), email service providers may flag or suppress that address, removing a real person from your list without any indication of what happened. Growth teams should audit bounce logs for relay-domain patterns and treat hard bounces from privaterelay.appleid.com addresses with extra care until the full scope of historical exposure is better understood.

Apple's delayed response also reinforces a broader lesson: privacy promises in your own marketing need to hold up under scrutiny. Subscribers are increasingly aware of email privacy tools, and brands that handle contact data transparently, with clear opt-in practices and respectful data use, are the ones that earn real addresses in the first place.

No comments yet. Be the first!

Leave a comment

Comments are reviewed before publishing.

Breaking

Related news

Illustration for new_technology: Gmail's New RETVec AI Boosts Spam Detection by 38%
Email DeliverabilityMay 22, 2026 6 min

Gmail's New RETVec AI Boosts Spam Detection by 38%

Google deployed RETVec, an AI spam filter that detects obfuscated spam, improving detection 38% while reducing false positives 19.4%. Here's what email marketers need to know.

RRachel Torres
Illustration for new_technology: IETF Publishes RFC 9989 DMARC Standard in May 2026
Email DeliverabilityMay 22, 2026 6 min

IETF Publishes RFC 9989 DMARC Standard in May 2026

IETF officially published RFC 9989 in May 2026, upgrading DMARC to Proposed Standard status. The update improves spoofing prevention and email authentication with clarified terminology and stronger subdomain protection.

JJames Chen
Illustration for industry_trend: Gmail Spam Filter Collapse Jams 1.8B Inboxes
Email DeliverabilityMay 22, 2026 6 min

Gmail Spam Filter Collapse Jams 1.8B Inboxes

Gmail's spam filters collapsed on Saturday, flooding 1.8 billion inboxes with promotions while blocking legitimate mail. Here's what happened.

RRachel Torres
HomeNewsApple Fixes Hide My Email Leak After 1-Year Delay
Email Deliverability

Apple Fixes Hide My Email Leak After 1-Year Delay

Apple patched a year-old Hide My Email vulnerability that exposed real addresses via spam logs. Delayed fix raises deliverability trust concerns.

R

Rachel Torres

July 22, 2026

6 min read
Share:
#Compliance#Email Security#iCloud Email#Sender Reputation
Illustration for new_technology: Apple Fixes Hide My Email Leak After 1-Year Delay

Stay in the loop

Get the latest posts delivered straight to your inbox. No spam, unsubscribe anytime.

Apple patched a significant security flaw in its iCloud+ Hide My Email feature on July 3, 2026, more than 13 months after the vulnerability was first reported. The fix only came after a tech news outlet made the bug public, raising serious questions about how one of Apple's most-marketed privacy tools handled a known exposure gap for over a year.

What the Flaw Actually Did

Hide My Email generates unique, random email addresses that forward messages to a user's personal inbox, with the purpose of safeguarding user privacy and reducing unwanted spam. The feature requires a paid iCloud+ subscription and was introduced by Apple in June 2021.

The flaw undermined that promise in a specific but serious way. Murphy discovered that sending a specially crafted email that was rejected as spam could cause the recipient's real email address to appear in mail transfer logs. If someone sent a message to a hidden address and it bounced as spam, the user's actual email address could get exposed in the sender's mail logs, and the user would have no way of knowing it happened, since a bounced message never lands in their inbox.

The vulnerability did not expose passwords, Apple Accounts, or inbox contents. Instead, it undermined Hide My Email's core privacy promise by potentially allowing an alias to be linked back to a user's permanent email address.

According to Murphy and his EasyOptOuts co-founder Ben Weiner, as reported by iClarified, "For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message."

A Year of Inaction Before a Public Disclosure Forced the Fix

404 Media reported that a fix was deployed by Apple on July 3, 2026, after more than a year since the vulnerability was disclosed to the company by Tyler Murphy, co-founder of EasyOptOuts.

The timeline tells a frustrating story. Murphy reported the flaw in June 2025, but despite Apple claiming it was resolved in March 2026, independent tests confirmed it remained exploitable at least until July 3, 2026. In the following months, Apple said it was again looking into the problem, but Murphy was unconvinced Apple would actually address it, so he contacted 404 Media to make it public.

After another unsuccessful fix attempt in late June, he contacted 404 Media, which published the story on July 1. Apple deployed the patch two days later.

The vulnerability turned out to be fairly low-tech, failing to hide the main email address in spam email logs that were bounced back to the sender after being rejected.

The Fix Is In, But Older Aliases May Still Be Exposed

Apple says it fixed the vulnerability on or around July 3, but AppleInsider successfully reproduced the flaw two weeks after the company's claimed repair date. By July 21, both Apple and Murphy confirmed the bug had been fully resolved.

Even so, the researcher's warning to users is pointed. As Engadget reports, Murphy stated: "Because non-malicious emails could bounce, revealing your hidden email address, and because mail transfer logs are often retained, we'd assume that any hidden email address linked to a Hide My Email address created before July 7, 2026, may have been exposed and could still be in third-party logs."

Users should treat real addresses attached to older aliases as potentially disclosed, and understand that deleting an alias will not erase information already retained in another provider's logs.

Legal Fallout and What It Means for Marketers

The disclosure prompted legal action. Per the class action complaint, researchers first reported the flaw in June 2025, and while Apple acknowledged the report, the company allegedly "took no action for nearly a year" while researchers finally went public in July 2026 after a year of inaction and no security update from Apple. The plaintiff states he is one of the millions of customers who paid Apple for iCloud+ and relied on Apple's representations that Hide My Email would keep his personal email address hidden.

For email marketers and growth teams, this story carries a practical implication beyond the privacy debate. Subscribers who use Hide My Email addresses ending in @privaterelay.appleid.com or @icloud.com are doing so because they want to guard their real identity from the services they sign up with. Seeing an unusual increase in iCloud addresses on your list may signal that people don't trust your brand, and as one email deliverability expert noted, "This has always been a reflection of the level of trust the recipient has with your business or org." Apple Hide My Email privacy flaw concept illustration showing a relay address icon with a warning or shield symbol, representing the security vulnerability in Apple's iCloud+ Hide My Email feature that allowed email bounces and list suppression issues

When subscribers use alias addresses, it affects suppression management, re-engagement campaigns, and list hygiene. If a relay address bounces (as this flaw demonstrated was possible), email service providers may flag or suppress that address, removing a real person from your list without any indication of what happened. Growth teams should audit bounce logs for relay-domain patterns and treat hard bounces from privaterelay.appleid.com addresses with extra care until the full scope of historical exposure is better understood.

Apple's delayed response also reinforces a broader lesson: privacy promises in your own marketing need to hold up under scrutiny. Subscribers are increasingly aware of email privacy tools, and brands that handle contact data transparently, with clear opt-in practices and respectful data use, are the ones that earn real addresses in the first place.

No comments yet. Be the first!

Leave a comment

Comments are reviewed before publishing.

Breaking

Related news

Illustration for new_technology: Gmail's New RETVec AI Boosts Spam Detection by 38%
Email DeliverabilityMay 22, 2026 6 min

Gmail's New RETVec AI Boosts Spam Detection by 38%

Google deployed RETVec, an AI spam filter that detects obfuscated spam, improving detection 38% while reducing false positives 19.4%. Here's what email marketers need to know.

RRachel Torres
Illustration for new_technology: IETF Publishes RFC 9989 DMARC Standard in May 2026
Email DeliverabilityMay 22, 2026 6 min

IETF Publishes RFC 9989 DMARC Standard in May 2026

IETF officially published RFC 9989 in May 2026, upgrading DMARC to Proposed Standard status. The update improves spoofing prevention and email authentication with clarified terminology and stronger subdomain protection.

JJames Chen
Illustration for industry_trend: Gmail Spam Filter Collapse Jams 1.8B Inboxes
Email DeliverabilityMay 22, 2026 6 min

Gmail Spam Filter Collapse Jams 1.8B Inboxes

Gmail's spam filters collapsed on Saturday, flooding 1.8 billion inboxes with promotions while blocking legitimate mail. Here's what happened.

RRachel Torres