How Apple's Hide My Email exploit worked and why you're still at risk | EasyOptOuts
How Apple's Hide My Email exploit worked and why you're still at risk
By Ben and Tyler, Co-founders
20 min read
The vulnerability has been fixed as of July 7, 2026, but the exploit was simple, and hidden email addresses may still be in third-party logs.
We've updated this guide with more details following Apple's fix. You can see our original report here.
Apple's Hide My Email service is used by iCloud+ customers to send and receive emails while keeping their personal, permanent email address private. The service generates random, unique email addresses to act as intermediaries between your actual email address and the people you're emailing. For example, you could be given the email address random.email.22@icloud.com to hide your real email address, realname@example.com. People use Hide My Email addresses to sign up for accounts and communicate while maintaining privacy and anonymity.
The vulnerability
When an email sent to a Hide My Email address was rejected as spam, the rejection error message returned by iCloud's email servers included the meant-to-be-hidden email address in 100% of our limited tests. Other types of rejections were also problematic, though probably less common. As of July 7, 2026, the vulnerabilities are fixed.
But there's still a problem: Email rejection reasons are saved in third-party logs outside of Apple's control. For example, we use Mailgun to send emails to our customers. It saves email delivery and rejection logs for troubleshooting. We happen to save logs for only a few days, but some senders maintain logs for years.
Email addresses may have leaked more than expected given typical spam rejection rates. For the emails we were sending, emails forwarded via Hide My Email bounced (i.e., were rejected with an error message) at much higher rates.
This is how the leaked email addresses showed up in our logs:
view full size
Hidden email addresses were leaked for a variety of mail hosts. We saw hidden email addresses for Gmail, Yahoo, Outlook, and Proton domains, among others.
The exploit
Coming up with a way to reliably exploit the vulnerability was straightforward after observing the issue. Here are the instructions we sent to Apple on June 13, 2025:
Send a spammy email to the Hide My Email address. Or send an email that doesn't strike you as spammy and hope that the email is rejected as spam anyway.
If the email is rejected SMTP code 550, look at the long description field and observe the real email address. For example, the message looks like the following: This is a system-generated message to inform you that your email could not<br>be delivered to one or more recipients. Details of the email and the error are as follows:
redacted hidden email@gmail.com>: host 127.0.0.1[127.0.0.1] said: 550 5.7.1 message<br>content rejected due to spam; if you feel that your email was rejected in<br>error, please forward a copy to icloudadmin@apple.com (in reply to end of<br>DATA command)
If the email wasn't rejected by the email server as spam, try again with a spammier email or different email. I think that once you've identified a message that's rejected as spam consistently, you can keep using it.
In practice, we usually didn't need to try with multiple emails to trigger the rejection. We could just open up our personal email's spam folder, and the first email we copied and sent would cause the rejection. Here's a typical example:
😈 Open this if you want her tonight
We recently learned that there are more reliable ways to trigger these kinds of bounces for most mail servers like the EICAR anti-malware test file, probably well-known to people more familiar with email handling.
We also noticed that at least one other kind of error could leak hidden email addresses: If someone deleted the hidden email address that their Hide My Email addresses forwarded to, the bounce message contained the hidden email address. We don't think it was possible to exploit widely.
There are other kinds of bounces, but we don't know if they were leaking hidden email addresses or were exploitable. Apple should be able to determine which other kinds of bounces were also leaking email addresses.
After news of the vulnerabilities was made public, some people online indicated having years-old knowledge of exploits based on other kinds of bounces:
user Alexisredwood on Reddit
YouTube channel SANS Internet Storm Center
Why we're sharing the exploit details
People are still at risk if leaked data has been retained anywhere.
Public knowledge of the exploit also helps other present and future email aliasing services avoid making the same mistake.
Why it matters
While many people use Hide My Email only for spam prevention, some rely on it for personal safety or sensitive privacy matters. Given the number of iCloud+ subscribers, there are probably people relying on Hide My Email's privacy claims to communicate with past...