Apple quietly fixed a bug in its Hide My Email service that could turn your disposable address back into your actual inbox identity — awkward. The flaw let mail systems sometimes reveal a user’s real addresses in server records when certain messages were rejected, meaning the whole point of the disposable alias could be defeated.
What happened
Hide My Email was designed to give you little one-off email masks that forward mail to your real inbox so you can dodge spam and keep your main address private. But researchers who reported the problem discovered that if someone sent a message that got auto-rejected as spam, the forwarding process could leak the underlying address into system traces — stuff like SMTP logs and other delivery records.
The bug was flagged to Apple in mid-2025. Apple attempted fixes earlier in 2026 and finally deployed a working patch in early July 2026. Because the leak happened at the transport/logging level, emails that were bounced or filtered out often never reached a visible spam folder, so victims might never know they were exposed.
Important note: any Hide My Email alias created before early July 2026 could potentially have its linked inbox captured in delivery records. In plain speak: if you made an alias before the patch, there’s a chance your real address briefly showed up in backend logs when certain messages were dropped.
Why this matters — and what you can do
Privacy promises are only useful if they work. When a paid feature meant to hide your address leaks it in server-side logs, that undermines trust — and prompted a legal challenge alleging customers were misled about the protection they paid for.
If you’re thinking “now what?” here are a few practical moves that aren’t too annoying:
- Rotate any Hide My Email aliases you created before July 2026 — retire the old ones and make fresh ones.
- Watch accounts tied to those aliases for odd activity and consider changing the primary address on high-value accounts (banking, recovery email, etc.).
- Don’t rely on your spam folder to check for leaks — the problem showed up in backend mail logs that users can’t see.
- Contact Apple Support if you want direct confirmation or help decommissioning vulnerable aliases.
It’s a good reminder: even features designed to be stealthy can trip over boring infrastructure details like logging and spam filtering. Keep calm, rotate the aliases you’re worried about, and maybe enjoy the little victory of having survived another tiny internet privacy meltdown.