8 ms·
An Ode to Apple’s Hide My Email
- newaccount74 4y agoI've been using yopmail for years to avoid spam, but the problem is that a lot of services have blocked yopmail and other disposable email addresses. The nice thing with "hide my email" and Fastmails "masked addresses" is that the two services use a popular domain, so sites can't easily block it.
- ratww 4y agoYep, I used to use Mailinator, sometimes others, but they eventually end up blocked in Marketing-hungry websites. Even myname+random@gmail.com and similar can get blocked from registration on some websites now. The difference here is the power of iCloud. Services can't afford to block it. This is similar to Domain Fronting [1]. Maybe we should call this email fronting? [1] https://en.wikipedia.org/wiki/Domain_fronting https://en.wikipedia.org/wiki/Domain_fronting
- Underphil 4y agoThis raised a bigger question for me- How did the system get to a point where only big players can set up a service like this?
- bb88 4y agoEmail marketing ruined communication for everyone. I once ran my own email server for several years off a domain from no-ip.org running from a local server in my home. Most places accepted email from it just fine, occasionally though some places had their mail server reject my IP because it was in a DNS black hole. Then you had the spoofers pretend to be att.com/verizon.com so they had to implement SPF and DKIM. Then you had to uphold your reputation and the security of your servers otherwise your address would get put on one of the DNS black hole blocks. Worse was if your IP address was already used to send spam -- you somehow had to get the black hole lists to remove your IP. At some point about 15 years ago, I gave up and moved to gmail, and I never really looked back on it again.
- deleted 4y ago[deleted]
- ratww 4y agoIt's not really big players per se, but "domains with a lot of users that I can't block". Which of course means "big players" for regular people. I agree with sibling that the problem is with Email marketing, but for different reasons. Companies are so addicted to spamming users and selling user data that it becomes unacceptable that users might not want to give away their email. Another problem is emails being required for signing up to accounts. Honestly IMHO we gotta get rid of email for signups. I don't know what to replace it with. Hardware keys, maybe?
- bb88 4y agoThe "+" symbol is easy to detect. The other benefit for apple is that if a generated email address for Home Depot has non Home Depot content, it's easy to block, since it's clear it got sold to a email marketing company. And then Apple can then threaten the corporations to not sell their mailing lists or risk being cut off from sending to icloud, or worse, having a header in the email from Apple saying that "Home Depot doesn't respect your privacy and sells your email address to 3rd party marketing companies. Here's a telephone number where you can complain."
- kingcharles 4y agoI still get sites from time to time that reject custom domains and want an address on yahoo.com, gmail.com etc, which is infuriating. The worst thing is that so many sites have stupid email validation rules. Even cameo.com, which is a mid-size ecommerce site, doesn't accept a lot of TLDs created in the last 8 years, including mine.
- saos 4y agoIt’s been totally amazing for me! All Apple need to do is create an dev experienced like Firefox developer edition browser and I will jump very quickly!
- pensatoio 4y agoHide My Email is an awesome product, no doubt, but why the mention of Have I Been Pwned? Security through obscurity is not worth two cents. Use a password manager and generate your passwords.
- mlapida 4y agoMy thought process was if you search your primary email, you'll quickly see all the breaches with that email. Using a different email per service reduces the surface area (lateral movement). Security through obscurity has nominal value, but the reduction in ability to correlate has a much higher value.
- FabHK 4y agoA useful feature the article doesn't mention: In macOS Mail and iOS Mail, when you reply to an email or send a new one, you can choose the "From" address: The options are the usual accounts you have set up, plus, now, a "Hide my Email" proxy generated on-the-fly. I've found it very handy on several occasions.
- mlapida 4y agoThanks for sharing! I totally missed this.
- treesknees 4y agoGreat, I didn’t realize this was an option. It feels less useful for replies but new emails I could definitely see myself using this.
- FabHK 4y agoCases where I've used it for replies: * accidental semi-spam (people sending emails to someone at one of the domains I own, mistakenly) where I wish to notify them that they got the wrong email, but don't want to divulge my main email (and name). * support emails from services that I signed up with using "Hide my email". When replying, the "From" defaults to my main email, but again, I can switch to "Hide my email".
- yonatron 4y agore: "It’s inventible" "inevitable", perhaps?
- texaslonghorn5 4y agoAs an android user I've never seen this before -- this seems way better than email+tag@gmail.com
- lapser 4y agoThere is SimpleLogin[0] and Mozilla Private Relay[1] as more generic options. I've never tried them as I struggle to figure out how trustworthy they are. At the end of the day, emails are essentially proxied by these products. [0] https://simplelogin.io https://simplelogin.io [1] https://relay.firefox.com/ https://relay.firefox.com/
- germinalphrase 4y agoI use this feature extensively. My only wish is that it were easier to send an outgoing email via a Hide My Email address (rather than only being about to reply once the other party has sent the first message).
- gnuj3 4y agoYup, this makes is unusable for me. Try AnonAddy bro, its much better. You even get iOS app to manage your aliases on the go.
- manquer 4y agoGmail used to have send-as feature that verified only with your ability to click on the link that you get from google on that inbox. Technically you can do the same with SES on AWS as well, they verify just a single email address this way (domain is with dns records), and they have SMTP gateways to connect to a mail client .
- laserdancepony 4y agoIf Apple would provide an easy and straightforward method of sending emails from that garbled and, to the layperson, "anonymous" adresses all kind of dumb shit would happen. I guess they don't want that kind of publicity, even if they can obviously trace every offender.
- kingcharles 4y agoFastmail handles this perfectly. Discussion here: https://news.ycombinator.com/item?id=30964570 https://news.ycombinator.com/item?id=30964570
- blokey 4y agoIn iOS and macOS mail.app, you can select the from name in the compose sheet and the option to autogenerate and random email address using “Hide My Email”. Not totally intuitive but pretty decent.
- germinalphrase 4y ago
- pram 4y agoHuge fan of this, started using it for practically every signup. I've already had the opportunity to shitcan an alias because it obviously got dumped to some advertisement list. Now I just need to work on untangling 15 years of other services from my main account.
- gnuj3 4y agoWhere is the ode to the likes of AnonAddy that have been about for a long time now AND are provides much better service?
- notriddle 4y agoServices that only provide disposable addresses get blocked. iCloud is too big to block.
- gnuj3 4y agoI havent come across service that would reject me, although I use my own domain with AnonAddy.
- deleted 4y ago[deleted]
- 8K832d7tNmiQ 4y agohear, hear! Anonaddy is a godsend to me, for having an additional feature to set which alias are allowed to forward (albeit limited just enough for essential services I can use) and also recently you can reply a message from your alias email
- edsimpson 4y agoDon’t forget SimpleLogin which is open source and just got bought by ProtonMail last week.
- hombre_fatal 4y agoBringing first-class support for it on Safari/iOS is interesting, and I'm surprised they did it. Even my mom is using it because, when it pops up, why not. Until this, it was just a handful of privacy-conscious folks using services like AnonAddy.
- DIVx0 4y agoI don't use Safari but I still use this feature a lot even though I have to do a few extra steps because it does not integrate with anything other than Safari, its that useful for me. Some sites have never worked properly with the email+tag@gmail.com thing and some have even become wise to it and wont accept addresses like that (car dealers are the worst). I hope someday apple allows 3rd party integration with this feature.
- deleted 4y ago[deleted]
- fiddlerwoaroof 4y agoOne workaround is that gmail ignores dots in the local part too: so you can use unusual punctuation for marketing: e.mail@gmail.com
- newaccount74 4y agoI don't get the email+tag. Spammers can just drop the plus tag and get your real email address?
- cormacrelf 4y agoIf it makes it into a leak database, you know who to blame.
- stu2b50 4y agoThey could, but they don't. Spammers cast a wide net and usually aren't concerned about the crumbs that fall through. Not to mention the people that do the plus or dot tricks are going to be extremely low value spam targets.
- stingraycharles 4y agoYup, but assuming these spammers want to keep their lists of leaked emails fresh, it’s kind of silly that they’re so unconcerned about it: they’re very much helping to expose their suppliers. I feel that they must realize that can’t be good, but maybe I overestimate them.
- yifanlu 4y agoI signed up for Comcast Xfinity using a brand new “hide my email” address and three months later I started receiving phishing emails at that address. (I’ve gotten over half a dozen so far). Made me realize that either Comcast was hacked (without disclosing it) or they’re selling people’s emails.
- redmattred 4y agoI’ve experienced the same with comcast and have contacted their support. They claim there was no data breach or they aren’t selling emails, but that obviously isn’t the case.
- cromka 4y agoSurely some attorneys would be interested in a class-action.
- sneak 4y agoAccording to https://www.xfinity.com/Corporate/Customers/Policies/SubscriberAgreement https://www.xfinity.com/Corporate/Customers/Policies/Subscri... you have to give up your rights to a class action and a jury trial to get Comcast service. Additionally, they spend a ton of money lobbying and otherwise unfairly impeding competition, so in many places in the US, they are the only option, so it's give up your civil rights to lawsuits, or stay offline (or pay a wireless carrier who does the same anticompetitive scumbag shit a heinous price per gigabyte). The state of both wireless and wireline broadband in the US is totally broken, and it's not getting fixed because it's broken by design, as part of the general attitude by large corporate interests and cooperative legislatures and regulatory bodies to treat the US population as a sort of natural resource like a flock of sheep to be fleeced rather than as legitimate customers to be serviced (or a legitimate market to be participated in on merits). They do this by ensuring that there is no meaningful competition, and ensuring that if you do "willingly" engage in service with them, you have no meaningful legal recourse if they abuse you. "We're the phone company. We don't have to care." You have no real power against them because the people who control the system have decided that you should not have any real power against them.
- egamirorrim 4y ago
- LeoPanthera 4y agoYou're angry about this but not iCloud Mail, their full hosted email product, that has existed under various names for over 20 years?
- voisin 4y agoAny evidence of this you’d like to share?
- mappu 4y agoThe poster said "be able to", not "does". Inserting themselves in the SMTP relay chain clearly gives them a new technical capability here.
- trollied 4y agoNo need for the tin foil hat nonsense.
- drivebycomment 4y agohttps://support.apple.com/en-us/HT210425 https://support.apple.com/en-us/HT210425 > Apple doesn't read or process any of the content in the email messages that pass through Hide My Email, except to perform standard spam filtering that's required to maintain our status as a trusted email provider. All email messages are deleted from our relay servers after they're delivered to you, usually within seconds. Unless you can present an evidence, your post is mostly a conspiracy theory.
- vba616 4y ago>your post is mostly a conspiracy theory. Do you frequently bet that people are doing the right thing with no oversight? How often does that prove to be true?
- muhehe 4y agoThis is nice and all, until your apple account get locked (for no good reason)
- sosborn 4y agoYou can say that about any email service that isn't self-hosted.
- drexlspivey 4y agoUsing your own domain doesn’t have this problem as you can just move to another service
- muhehe 4y agoThat's true, of course. But this is adding another layer of dependency to already fragile reliability. Edit: also with custom domain you can switch email providers.
- crossroadsguy 4y agoOr you want to send email (not a reply). People are better off not using Apple’s HideMyEmail. There are better ways that allows this on your domain - no lock-in! Or no lock-in with a device or browser (because without that it’s a bigger pain).
- tehnub 4y ago
- pueblito 4y agoYesterday I was shopping with my wife and was thrilled with how I could use Hide My Email in an irl sales situation - mattress shopping!
- devmunchies 4y agoIs this different than me just programmatically adding new email addresses on my domains, which just forward to my primary? Is it just more convenient? I ask for learning, not for skepticism.
- cmg 4y agoIt has the benefit of being at a general domain, icloud.com, instead of one that is (in theory) traceable to you for someone who cares enough to do so.
- gzer0 4y agoThe only thing really holding me back from wanting to use iCloud mailing services is the current implementation of MFA on Apple services. It would be fine if you were allowed to use normal MFA options, but no, that is not possible. Instead, you MUST confirm your logins via already signed in Apple-devices only. There is no other way. Cannot use phone number (for good reason, but that is besides the point), cannot have a secret key based TOTP.
- Kwpolska 4y agoSMS is available as a fallback 2FA method for Apple ID.
- gzer0 4y agoUnfortunately, only one phone number is allowed per Apple ID. And I do not have multiple phone numbers to expend for an SMS only 2fa option here.
- bmarquez 4y agoYou can have multiple accounts on one "trusted phone number". Trusted phone number is where Apple sends the SMS 2FA code. I have several Apple ID's on 1 phone number. This is different than "Reachable at" phone number which must be unique and is used for iMessage and Facetime, and if it's blank other people can only reach you via iCloud account email. (It makes sense if you think about it, parents setting up iCloud accounts for their children's iPads who might not have their own phone).
- JimDabell 4y agoThis is not correct. Go to https://appleid.apple.com/account/manage https://appleid.apple.com/account/manage and you will see that you can add multiple trusted phone numbers under Account Security.
- m-p-3 4y agoI only wish they'd support standard TOTP as well, like everyone else.
- binwiederhier 4y agoI have a unique email address for every single service that I sign up for, similar to this, though selfhosted. I've been doing this for years and it works wonderfully. If someone misuses my email address, or gets annoying, I can simply turn off the address. Bam! It's the easiest Postfix config in the universe, essentially just: virtual_alias_domains = domain1.com domain2.com virtual_alias_maps = hash:/etc/postfix/virtual And then /etc/postfix/virtual looks like this: phil.equifax@domain1.com firstname.lastname@gmail.com phil.experian@domain1.com firstname.lastname@gmail.com ... (hundreds of these) I also made a super simple web UI for myself to edit this file quickly. Gmail seems to be fine with this, emails do not usually end up in spam. Every full moon maybe, but usually it's alright. It's not as shiny as Apple's thing, but it's 100% selfhosted and I own the domain.
- webmobdev 4y agoAnd, if the email service is also self-hosted, it prevents Apple from collecting more data about your interests and purchases through your email, which it uses to profile you (to determine how to extract more money from you).
- KennyBlanken 4y ago> It's not as shiny as Apple's thing, but it's 100% selfhosted and I own the domain. Apple's system is "shiny" because it provides near total anonymity, whereas your setup has all the deliverabilty issues of a self-hosted domain and rather uniquely identifies you...at the domain level? I'm not sure why you are maintaining a hundreds-of-lines virtual table and a web UI, instead of just using a regex or two to capture phil.*@domain2.com or something along those lines (maybe you want to do one including a year or something to cut down on spam), or blacklisting as needed by having postfix reject during the SMTP session so the email is marked as invalid and is removed from the spammer's database. Or, I dunno, just use VERP? I don't think I've yet run across anyone smart enough to drop VERP from email addresses.
- binwiederhier 4y agoI'm maintaining hundreds of lines because I started with one. And i was too lazy to change it. Your approach it probably better ;-)
- up6w6 4y agoThe most popular open-source alternatives are SimpleLogin[1] and AnonAddy[2]. The former one was just acquired by ProtonMail[3]. [1] https://github.com/simple-login/app/ https://github.com/simple-login/app/ [2] https://github.com/anonaddy/anonaddy https://github.com/anonaddy/anonaddy [3] https://protonmail.com/blog/proton-and-simplelogin-join-forces/ https://protonmail.com/blog/proton-and-simplelogin-join-forc...
- bertman 4y agoHuh, hadn't heard about Proton buying Simple Login. I'm not sure how to feel about that. I really like SimpleLogin, but Proton always felt kind of "icky" for lack of a better word. Guess we'll see.
- Vinnl 4y agoMozilla also has Firefox Relay: https://relay.firefox.com/ https://relay.firefox.com/ (Disclosure: I'm on the Relay team.)
- sinatra 4y agoIf relay gets popular, won’t some services simply start to block relay subdomain for registration to make it ineffective? Just like 10minutesemail etc are blocked in many places.
- m-p-3 4y agoYou can flag them to the Relay team and AFAIK they'll reach out to the domain that blacklisted them with the hope to make them change their mind. A service that doesn't accept an email proxy during registration is not going to respect my privacy, so IMO not worth of using.
- Vinnl 4y agoFor an example of that, see here: https://github.com/wesbos/burner-email-providers/pull/339 https://github.com/wesbos/burner-email-providers/pull/339 But yes, definitely a concern that is constantly on our radar.
- submeta 4y agoBeen using individual email adresses for each website I signed up for by using Fastmail.com‘s email aliasses. - Previously I had a second email address just for sign ups, but whenever a platform was hacked and user data was leaked, my email address was burned. So yes, this feature is super useful, and kudos to Apple for introducing this to their customer base.
- ThePowerOfFuet 4y ago> It’s important to note that you shouldn’t use Hide My Email for everything. For example, you probably don’t want to use a random address for critical services such as online banking. If you trust the bank with your money, you can probably trust them with your email. I’d also think through those sites that may use your email to help others find you, such as social media accounts. If you’d like your contacts to find you automatically, you’ll need to use an email they know of. Social media is high on the list of use cases for such addresses to help preserve one's privacy.
- JZL003 4y agoThere are lots of ways to do this. Postfix is nice but a little heavy. The simplest and most functional way I've found is https://github.com/0xERR0R/mailcatcher https://github.com/0xERR0R/mailcatcher since all it does is forward the emails. You can even use a throwaway gmail SMTP so it doesn't get send to spam Easy to set up on a rpi/cheap VPS, as long as you have a hostname. And while you're there, look for a short domain name so it's fast to type (on credit card kiosks). You can get cheap short non-standard TLD's like .li. I got a 3 character domain for $5 a year, as short as bit.ly, but just for me
- JZL003 4y agoI guess it's harder (although not impossble) to send email from this throwaway address, but that has never come up for me, for external accounts
- nyuszika7h 4y agoTwitter is one site that I know requires you to reply to their automated email from the exact same address if you want to appeal a suspended or locked account.
- user3939382 4y agoIt's a built-in feature of Fastmail which is how I do it
- ultrasounder 4y agoThis is serendipitous. I just now signed up for the 5 day overcoming overthinking challenge by Jon Acuff and when I signed up Apple checkef with me if I wanted to hide my email and this is trending on HN!
- lowdose 4y agoI have been tinkering to use chrome auto filling form to sign up for random services with the email address of the current director of the CIA Bill Burns. Haven’t tried it though.
- yellow_postit 4y agoLove the service but nervous on the lock-in. Any guides for how to migrate off Apple after using lots of emails? I’ve been happy with the Fastmail+1Password integration as that “feels” less painful to migrate off the in the future.
- adamhearn 4y agoCurrently I forward all my iCloud mail to my protonmail. Not sure if the aliases will stick around after cancelling a subscription however.
- m0dest 4y agoThis is the million dollar question that Apple hasn't answered. What happens to these forwarding addressses if you cancel iCloud+? The result is bad either way. It's either A or B. (A) Canceling iCloud+ doesn't remove existing Hide My Email addresses - which makes it possible to abuse by creating tons of extra addresses before canceling. Or: (B) Canceling iCloud+ deletes all of your Hide My Email addresses, locking you out of dozens of services (e.g. anything that sends an email as a MFA). I suspect that it is actually (A). Someone just needs to test this and report out.
- SylvieLorxu 4y agoI see SimpleLogin mentioned in the replies several times, but I haven't seen anyone mention that you can use your own domain name with them to prevent vendor lock-in. You can also export your setup through their API so you can very easily migrate to a self-hosted instance if ever necessary: wget --header "Authentication: YOUR_API_KEY" https://app.simplelogin.io/api/export/aliases https://app.simplelogin.io/api/export/aliases -o simplelogin-export-$(date +%s).csv And given the author talks about Have I Been Pwned, I feel I should mention that SimpleLogin has built-in HIBP integration (contributed by me in https://github.com/simple-login/app/pull/472 https://github.com/simple-login/app/pull/472)
- allanrbo 4y agoMade a very similar thing, since before apple did it actually:-) mine's called https://ent.re https://ent.re
- CamelRocketFish 4y agoNice domain name!
- baxtr 4y agoThe great thing about Apple doing stuff like that is the sheer scale they reach. Sure, there were many services like that before, and many of us have used them. But making it an integral part of iOS can drive mass adoption. You have to credit Apple for that.
- Gigachad 4y agoThere is also a trust component. I do trust Apple to not abuse this product or shut it down in the future much more than I do some no name privacy company.
- earthboundkid 4y agoHow do I report Hide My Email abuse? Someone used it to send a nasty email to my company. I couldn’t figure out how to report it. My guess is there is no way to do it and there won’t be until after some reporters make it the Apple scandal of the week when there’s no other news.
- callalex 4y agoAre you sure that was the actual sender? Email allows you to write whatever you want in the From field.
- Gigachad 4y agoIf your email host is half decent it will automatically move these emails to spam and plaster huge fraud warnings all over an email which does this.
- quenix 4y agoI'm not sure how one would do that? You cannot create Hide My Email addresses purely to send mail. Your company would have to first send mail to that address, and then the person behind it may reply
- guywithabike 4y agoHave you tried emailing abuse@icloud.com?
- sneak 4y agoApple provides data on iCloud subscribers to the police without search warrants or probable cause over 20k times every year(!) (under FAA 702, aka PRISM), because the US federal government illegally demands it and Apple has no ability to really stop them without their staff going to jail (thanks to the government's secret interpretations of what FAA 702 really means). Much of the data in iCloud is not end-to-end encrypted (including the keys protecting all of your iMessages, as well as all your photos, and your device backups) so this is a huge amount of data on/about you they can be compelled to turn over at any time without probable cause. This means that you shouldn't use iCloud (even if you have nothing to hide). The fact that there is no probable cause required means that the state can demand this data as part of a fishing expedition to abuse/harass even the totally innocent. This means that features like this, which lock you in to using iCloud in the long term, should be assiduously avoided. Get your own domain name and get your own email hosting (not from Apple) and use that. You can setup a catchall to have unlimited unique email addresses. You can use multiple domains if you like. Step by step instructions on how to do this are on my website.
- hackernewds 4y agoWhy not just use phil+craigslist@gmail.com or phil+kmart@gmail.com to achieve the same effect? ends up in the same phil@gmail.com inbox
- endisneigh 4y agohow exactly is this hiding your email?
- csunbird 4y agoBecause the spammers got smart, they automatically remove the plus sign before sending emails.
- sunny3 4y agoUnfortunately, I found that Hide My Email complicates unsubscribing. I tried unsubscribing from Jumba Juice many times unsuccessfully, only to realize that the email that I entered was my actual email, and I should enter the email that was shared to Jumba Juice instead.
- dawnerd 4y agoIf an unsubscribe link makes me re-enter my email I just report as spam. Not worth the energy
- mushyhammer 4y agoThat’s true, you have to be aware of the email address you used in every service instead of blindly entering your email address. But you can also deactivate the email address and be done with it.
- 4a3f35b5a 4y ago> you probably don’t want to use a random address for critical services such as online banking. Why not?
- mushyhammer 4y agoBecause it’s a potential pain. I just used Hide my email for a non-critical but real-life situation. I had to learn my new email address and I’ll have to remember it forever. I’ll probably change it back to my regular address at some point.
- gman83 4y agoI must be the only person who doesn't receive spam. I mean I do, but it goes into the spam folder. I've never really understood why I should use something like this. I have my email address on my website anyway, so it's not like it's private information.
- Gigachad 4y agoI have been using my current domain for 3 years now and I don't receive any spam in my spam box either. Email spam seems like it was a solved problem years ago. Now its all just newsletters which go right through the spam filter..
- mushyhammer 4y agoLow-quality spam veeery rarely makes it to my inbox, but “opt-out newsletters after signup” are basically how every business operates nowadays. And that’s spam as far as I’m concerned.
- daemn 4y agoAbine Blur (https://www.abine.com/ https://www.abine.com/) was one of the first to do that however some of the domains started to get blocked. Hide My Email using iCloud negates that risk.
- zhoujianfu 4y agoIt’d be nice if there was a service like this for physical addresses and even phone numbers. Every account you sign up for could be with a made up name, email, phone, address, and single use credit card number.
- paraxion 4y agoHang on, though: doesn't this essentially hand Apple a big list of which domains you communicate with and how frequently? There's also nothing stopping them reading the emails on the way through. I know a lot of people trust Apple more than Google, but you're essentially signing up for a vendor-locked product that you're hoping Apple will continue to support, with no guarantee they won't collect - even at an aggregate level - your communication preferences. They're even slightly pre-filtered for Apple's convenience, as the times you're likely to use Hide My Email are for shopping and social media - nice, ripe marketing targets.
- ip26 4y agoIf you are already on an @icloud.com address and/or using Apple Mail, what’s the difference?
- spsful 4y agoIf you use Gmail, there's also nothing stopping them reading the emails on the way through. If you use Outlook, there's also nothing stopping them reading the emails on the way through. If you use Yahoo, there's also nothing stopping them reading the emails on the way through. If you use virtually any email provider this is true.
- onethought 4y agoThere is no lock in - you can login to "whatever app" and update your email to a new one anytime you like. It's just an email address in the end. Also, unless you're encrypting your emails, can't everyone read your emails "on the way though" anyway?
- karlzt 4y agoI use duckduckgo email protection.
- musicale 4y agoThanks for using our crappy (app or web site) and Preserve Your Privacy With Apple. Please enter your mobile number for account verification. Your number must be capable of receiving SMS messages. We need your mobile number in order to verify that we can track you, personally identify you via data brokers, and send you SMS spam and robocalls. To help us verify this, please log in using your password and the single-use code we will send you via SMS.
- makeitdouble 4y agoFor those using this feature for a long enough time, have you seen misfiring or emails that disappear, you couldn't retrieve ? When using keychain as a password manager, once in a while when creating a password for a new site, it would generate it and complete the account registration, without properly saving the generated password. I'd hunt for the site item through keychain's list and not find it, and go through the "Reset My Password" for the site, except if time passed I might not even remember which email I used to register. It was annoying enough for passwords, but not critical. For emails there's probably situations where the account is just lost and the only option is to create a fresh new one. How good is their implementation for this ?
- Jcowell 4y agoThis situation was fixed in the latest update
- asimpletune 4y agoOne thing that wasn’t included in this article but is amazing is being able to deactivate an email address. It results in a total dead end for whomever it was given to.
- mlapida 4y agoCheck point 5 on the post.
- bredren 4y agoMy pal nick and I built something called Cloaked Email for our startup Gliph back in August of 2012. [1] Apart from our early integration to send and receive Bitcoin on Coinbase, Cloaked Email was the most successful part of our privacy focused startup, not only in its ability to attract press coverage but in generating revenue as well. We believe our work contributed to forcing criagslist to introduce their email relay service. Craigslist went so far as to block email from cloaked email users. [2] Doing this well and to take on the responsibility of maintaining ~forever is a huge thing. It is great Apple has recognized the importance of this matter and brought it into their platform in such a straightforward way. One of the most engaging actions we had was people re-rolling for a different random email address. People just loved seeing what they might land on next. [1] https://blog.gli.ph/2012/08/14/delivering-privacy-gliph-cloaked-email/ https://blog.gli.ph/2012/08/14/delivering-privacy-gliph-cloa... [2] https://blog.gli.ph/2013/07/22/cloaked-email-and-craigslist-its-complicated/ https://blog.gli.ph/2013/07/22/cloaked-email-and-craigslist-...
- pSYoniK 4y agoA bit of a plug, but I have written a small piece with some suggestions for services that could be used to hide and not share your main account as well as some pros and cons to them here - https://psyonik.tech/posts/keep-your-email-private/ https://psyonik.tech/posts/keep-your-email-private/ TL;DR - Cloudflare email works great if you have your domain on Cloudflare, Firefox Relay is cheap and will work with emails up to 150KB and a number of email providers give you the ability to create aliases (Runbox allows up to 100 aliases).
- Vinnl 4y agoFirefox Relay now works with emails up to 10MB: https://blog.mozilla.org/en/mozilla/latest-firefox-relay-includes-bigger-attachment-size-and-filters-for-promotional-emails/ https://blog.mozilla.org/en/mozilla/latest-firefox-relay-inc... (Disclosure: Relay engineer.)
- pSYoniK 4y agoI might switch back to it as I had some delivery issues with Cloudflare on some messages, but the issue was the email size, as emails with attachments wouldn't come through. +1 for the change!
- CryDeTaan 4y agoI built a similar service. The benefits include; 1. Custom domain , 2. unique email addresses, 3. don't have to be a Apple user. https://mailphantom.io https://mailphantom.io
- infologics 4y ago[dead]
- spookyuser 4y agoHide my email is great but I've also really been enjoying the new duck email service that does the same thing just because it's quicker to use on windows, where you have to open icloud, create a new email and paste it in. In fact the duck email service is nearly perfect, except for the fact that the extension forces you to use duck as a search engine and so you literally have to modify the chrome extension and store it locally if you just want the email service.
- tao_oat 4y agoI made something similar that I've been using for several months now: https://shroud.email/ https://shroud.email/ The concept is fundamentally the same as Hide My Email or DuckDuckGo's service, but it's libre software and has (IMO) a better UI to manage addresses. It also stops tracking pixels, which Hide My Email doesn't do unless you also use Mail.app. It's hosted in the EU and runs entirely on renewable energy.
- nicky0 4y agoSeems great, but the same question I have with most email add-on services, how do I know you aren't reading my email? Seems a risk to introduce additional 3rd parties into the email system.
- tao_oat 4y agoI agree that this is a challenge! If you want to use the hosted version, it's impossible to avoid the need for that trust. I'm working on making self-hosting easier for this reason. Some other services (like Firefox Relay) will use AWS' Simple Email Service for everything. I opted to go for [MailPace](https://mailpace.com/ https://mailpace.com/), an independent, privacy-focused provider instead, which is an improvement but still not ideal. I believe that SimpleLogin lets you self-host your email, which is best from a privacy perspective, but I'm slightly concerned about the UX of having to think about email deliverability. Still experimenting with that!
- nicky0 4y agoThat's a good answer, appreicated.
- chrizel 4y agoAnother advantage not mentioned is that '@icloud.com' is a generic domain that has been (and still is) used for a lot of real e-mail addresses for years. That means that most registration forms cannot just simply block '@icloud.com' because that would lock out a lot of real '@icloud.com' addresses. Hide My Email is very good and I'm using it a lot.
- Ikatza 4y agoNow that Google is insisting on kicking me out of legacy Gsuite, I may give icloud a try. It's a pity it's such a PITA to set something workable on Android.
- trizuz 4y ago
- trizuz 4y ago
- Hippocrates 4y agoThis feature is indeed amazing, but my biggest complaint is that it's not easier to access. Roughly speaking, the worse the website, the less I trust it with my email, the less likely their HTML is well formed and will trigger iOS to prompt me to use Hide My Email. Way too frequently I have to dig this feature out of the settings menu, copy the address to the site, copy the site back to Hide My Email as a label, and then usually do the same hoop-jumping with my password manager. I would welcome this feature to be more front-and-center on the keyboard somehow.
- jerryzh 4y agoFirefox had this earlier actually