appliedbits
FIELD NOTES PUBLISHED
PUBLISHED 2026-07-04

A Hide My Email flaw exposes the real address it's meant to mask

Michael Tsai  ·  Michael Tsai  ·  source ↗

Michael Tsai rounds up reporting (via Joseph Cox and 404 Media) on a flaw in Apple’s Hide My Email: the feature that’s supposed to hand out a disposable alias will, under the right conditions, let almost anyone recover the person’s real underlying address — and it has reportedly gone unfixed for more than a year.

The whole value of a masking primitive is that the mask holds. A relay address that leaks the thing it’s relaying isn’t a privacy convenience with a bug; it’s a false sense of security — arguably worse than none, because people share more freely behind a shield they assume is solid.

What stuck with me is that this is the email cousin of something telecom has had for years — anonymous calling, caller-ID blocking, the ability to reach someone without handing over a persistent identifier. Good for Apple for building it; consumers should have that option on every channel. But it’s a reminder that anonymous communication is a category we still haven’t gotten right as an industry. A common privacy framework has to do two hard things at once: actually hold — a mask that silently leaks for a year is a broken promise — and not become the pathway bad actors use to hide. The hard part was never concealing the address; it’s anonymity that honest people can rely on without giving abusers a place to disappear, working the same way across email, voice, and text.

Tagsappleprivacyidentitymichael-tsai