Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Jul 29, 2026 · 7 min read

Apple's Hide My Email Bug Exposed Real Addresses

Send a message to an iCloud relay alias, get it bounced, read the real address out of the rejection notice. That was the whole exploit, and it worked for 387 days after Apple was told.

No malware. No phishing page. No stolen credentials. To unmask the person behind an Apple relay alias you sent them an email, waited for a spam filter to reject it, and read the answer off the bounce. Tyler Murphy of the data removal service EasyOptOuts reported that to Apple on June 11, 2025. Apple said in March 2026 it was fixed. It was not. A working patch landed on July 3, 2026, two days after the story reached the press.

Key Takeaways

  • Tyler Murphy of EasyOptOuts reported the flaw on June 11, 2025, and Apple shipped a working fix on July 3, 2026, 387 days later.
  • A message to an alias rejected with an SMTP 550 permanent failure returned the user's real address in the rejection text, which landed in the sender's mail logs.
  • In limited volunteer testing, 100% of sampled aliases were exploitable, and one new alias was traced to its owner in roughly five minutes, per TechCrunch.
  • Any alias created before July 7, 2026 may sit in third party mail transfer logs with the real address attached, beyond Apple's reach.
  • Anthony Alvarez filed a proposed class action against Apple in the Northern District of California on July 15, 2026, citing California's false advertising law.
A laptop screen showing a blurred mail application interface with a person's silhouette faintly reflected in the glass, indigo and blue tones

What Is Hide My Email Supposed to Do?

Hide My Email generates a random address that forwards to your real inbox, so the site you hand it to never learns where the mail lands. Apple's iCloud documentation states the promise directly: addresses that forward to your account "so you don't have to share your real email address."

It is not free. Hide My Email ships with iCloud+, from about $0.99 a month, and surfaces in Safari forms, in Sign in with Apple, and in the Mail app. The design rests on one assumption: the alias to address mapping never leaves Apple's relay. Break that and the feature does not degrade. It stops existing.

What Exactly Did the Hide My Email Bug Leak?

The real address behind the alias, in plain text, handed to whoever sent a message that failed to arrive. Three steps: send a spammy message to a Hide My Email address, watch for a rejection carrying SMTP code 550, then read the real address out of the long description field of the failure notice. The Hacker News documented the mechanism after the fix shipped.

Nobody had to be malicious to trigger it. As Murphy and colleague Ben Weiner put it, "for many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message."

It also inverts the threat model you were trained on. Safety advice tells you to watch what you open and click; this fired on a message you never saw, since rejected mail never reaches your spam folder. Per 9to5Mac, every alias in limited volunteer testing came apart, and a fresh one was walked back to its owner's real Apple account address in about five minutes.

Why Did It Take Apple 387 Days?

Because two earlier fixes did not work, and Apple only shipped a working one after a reporter published.

  • June 11 and 13, 2025. Murphy reports the flaw, then submits reproduction steps. Apple says it is under investigation.
  • March 3, 2026. Apple says the issue is resolved. The researchers test it. It still works.
  • May 21, 2026. The researchers ask Apple to stop selling Hide My Email until it functions.
  • June 30, 2026. A second patch attempt fails.
  • July 1, 2026. 404 Media publishes, withholding exploit details. TechCrunch, 9to5Mac, and MacRumors follow the same day.
  • July 3, 2026. Apple patches and says it "fully resolved the vulnerability."

Sit with the arithmetic. Private reporting bought 387 days of nothing. Publication bought a fix in two. Between the claimed March 3 fix and the real one sit 122 days in which the ticket was, on Apple's side, already closed. 404 Media's account makes the causality hard to argue with.

Did the July 3 Patch Actually Hold?

Not immediately. AppleInsider reproduced the exploit on July 17, 2026, two weeks after Apple declared the vulnerability fully resolved.

Keep it proportionate. The bug exposed no passwords, granted nobody inbox access, and resisted mass harvesting, since an attacker needed a specific alias already in hand. What it destroyed was the one property the feature existed to provide.

Why the Patch Date Matters Least

A patch fixes forward. It cannot retract an address that already sat in somebody else's log file for a year. Every bounce carrying a real address wrote it into the sending server's mail transfer log, and the researchers were blunt about retention: "It's not unusual to save logs for months or years, or to have no log retention policy at all, so that logs are kept indefinitely." Copies multiply, because most businesses rent their mail infrastructure rather than run it.

The consequence is not spam. It is correlation. An email address is a join key, and people search sites make it trivial to link one to a name and an address history. Hence the researchers' advisory: treat any alias created before July 7, 2026 as compromised, because you have no way to check.

What Does the Class Action Allege?

That Apple charged for a privacy feature it knew was broken and kept selling it anyway. Anthony Alvarez filed the proposed class action in the US District Court for the Northern District of California on July 15, 2026, having subscribed to the 200GB iCloud+ tier around March 15, 2025.

The complaint cites California's false advertising law alongside other consumer protection statutes, seeks damages and repayment of subscription fees, and asks the court to order Apple to fix Hide My Email or disclose its limits clearly. Alvarez proposes four classes of US customers, two of them California subclasses. One detail cuts against him, as AppleInsider notes: the filing does not allege his own address was exposed, which is precisely where defendants attack standing.

The damages figure is the least interesting thing in it. The real question is whether a paid privacy feature that quietly stops delivering is a defect or merely a bug, because calling it a defect gives every subscription privacy control something resembling a warranty.

Why Email Users Should Care

An alias is not a secret. It is a routing trick, and it holds only as long as every system touching your mail keeps the mapping to itself. Apple's relay sat between millions of users and an unbounded number of senders: enormous leverage when it works, an enormous blast radius when one failure path hands the mapping to all of them at once.

A relay also protects exactly one thing, which is who you are at the envelope level. It does nothing about what a message does once it renders, where a remote image loading from a marketing server still reports the open, the timestamp, and the client software. That report gets filed against the alias, and for 387 days the alias resolved back to you.

This is the third Hide My Email trust problem we have covered in four months. April brought news that Apple handed the FBI a user's real identity plus 134 anonymous accounts. In June, a product change meant Hide My Email addresses became identifiable as relay addresses at a glance. Now the mapping turns out to have been leaking all along. Three failure modes, one dependency.

What Should You Do Right Now?

Five moves, in the order they matter.

  • Assume, do not investigate. If an alias predates July 7, 2026, treat it as burned. There is no log for you to audit, because the bounced mail never reached you.
  • Inventory what you have. On iPhone, open Settings, tap your name, then iCloud, then Hide My Email; Apple's guide to managing addresses covers the same list on iCloud.com. Sort by consequence, not by count.
  • Rotate the aliases that carry weight. Banking, healthcare, anything tied to your real name or home address. Deactivate the old alias, create a new one, update the service side. Know the limit: rotation stops future mail to a burned alias but retracts nothing already written into somebody's log.
  • Delete dead accounts instead of orphaning aliases. A dormant service holding an exposed alias is a permanent record with no upside to you.
  • Spread the dependency. Stop routing everything through one relay, and keep devices on current iOS and macOS releases. Our comparison of the best private email providers covers alternatives worth splitting high risk signups across.

The Bottom Line

Apple fixed the bug. That closes the leak and settles nothing else, because the addresses that escaped sit in log files owned by companies that have never heard of Tyler Murphy. Privacy delivered by vendor promise is only as good as the vendor's worst quarter, and this one ran 387 days. As MacRumors noted when the story broke, users had no way to know any of it was happening.

Sources: TechCrunch, Apple's Hide My Email feature has a bug that's been exposing real email addresses, MacRumors, Apple Patches Hide My Email Flaw More Than a Year After It Was Reported, AppleInsider, Hide My Email flaw still worked two weeks after Apple's claimed fix, The Hacker News, Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs, 9to5Mac, Apple Hide My Email bug allows 100% of real email addresses to be discovered, 404 Media, Apple Fixes Hide My Email Vulnerability After 404 Media Coverage, and Apple, Set up and use Hide My Email in iCloud+.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.