A single domain string nearly undid the whole purpose of one of Apple's own privacy features. Hide My Email, part of the iCloud+ lineup, works on a simple principle: websites can't tell whether an email address is a user's real one or a randomly generated stand-in. That very indistinguishability is what makes the feature valuable in the first place.
Back in June, Apple said newly generated Hide My Email addresses would switch to the @private.icloud.com domain, replacing the old @icloud.com. The problem: the moment a website spots the @private.icloud.com suffix, it can instantly tell it's dealing with an anonymous relay address rather than a user's real inbox. For sites that care about tracking user identity, that gap in information is worth real money—an address tied to a specific person is far more useful than one whose owner can't be traced, and blocking or rejecting sign-ups from that domain isn't exactly a stretch of the imagination.
Apple announced on Monday that it was walking back the change, via a developer note on its site with no detailed explanation attached. According to Daring Fireball's John Gruber, staffers on the Hide My Email team internally pushed back "hard" against the change; similar complaints surfaced from users on Reddit. Perhaps the bigger question isn't why Apple changed its mind, but how this plan ever got approved in the first place.
Not every address is staying put, though. Part of Apple's email-forwarding system will still move to the new @private.icloud.com domain: new addresses generated through Sign in with Apple, which are expected to migrate later this year. That doesn't raise the same privacy concerns, since websites already know a user signed in via Sign in with Apple—there's no "unmasking" issue to worry about there.
This isn't the only time Hide My Email has come under scrutiny this year. Earlier on, Apple patched a bug that could expose the real email address hidden behind a Hide My Email alias. Reports say Apple had known about the flaw for at least a year before it finally got fixed, only after 404 Media's reporting drew attention to it.