That timeline was exactly my experience with Apple here - https://www.grepular.com/Apples_Protect_Mail_Activity_Doesnt... They don't seem to know or care what is going on with their own email systems.
Has anyone seen Protect Mail Activity get re-enabled after you've disabled it? I wrote about that a few days ago: https://lapcatsoftware.com/articles/2026/6/6.html
Apple 'Hide My Email' vulnerability reveals peoples' real email addresses
81–90 of 105 posts
Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses
#82Earlier quoted context omitted.
Source? I don't think this is true. Doesn't seem to be the case for me. Maybe your email provider attaches your IP address?
Seems like this is a Gmail thing: https://ylukem.com/blog/apple-mail-leaks-your-ip-address
Nevertheless, as js2 said in another comment, it’s your mail provider (in this case Gmail) deciding whether to include the sender’s IP address or not.
Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses
#83Earlier quoted context omitted.
Fetching any email content is always worse than blocking it, because the typical threshold for spam is "is this inbox monitored". If that is true, then blast it with spam. And fetching anything ever proves that the inbox is monitored.
At least in Gmail, downloading content (e.g. images) is disabled by default for suspicious emails. There is no way for the sender to know if it’s monitored unless this is disabled by explicit user action.
Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses
#84That timeline was exactly my experience with Apple here - https://www.grepular.com/Apples_Protect_Mail_Activity_Doesnt... They don't seem to know or care what is going on with their own email systems.
Fetching any email content is always worse than blocking it, because the typical threshold for spam is "is this inbox monitored". If that is true, then blast it with spam. And fetching anything ever proves that the inbox is monitored.
Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses
#85Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses
#86Earlier quoted context omitted.
It’s in the headers. Send an email to your self from Mail and open the source in the inbox. There is your IP.
I also just tried this as well, sending an email from a Migadu-based account to one at both Gmail and MXRoute using Mail.app under macOS 15.7.7. Neither included any private IP address info I could find in either headers or raw source. That would be a good leak to know about and as sibling comment said saagarjha definitely knows their stuff, so any tips to replicate would be appreciated.
Using Mail: Version 16.0 (3864.600.51.1.1).
Sent from a Google Apps mail.
Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses
#87Earlier quoted context omitted.
This freaked me out the first time I used Mail. It rendered a PDF about buying bitcoin on PayPal (I don't have PayPal). Looked at the same email in Gmail and Thunderbird, it's just a PDF attachment, no message, and the sender was different. No wonder people are falling for those scams, Mail makes it easy for them. Now if only I had a better client on my phone (never buying an iPhone again)
What made you prefer Mail to Gmail, given you don’t seem satisfied with Apple’s Mail app?
Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses
#88Earlier quoted context omitted.
It’s in the headers. Send an email to your self from Mail and open the source in the inbox. There is your IP.
Is this from iOS? I just tested from MacOS, and the only IPs were for the transit and auth servers. I'm not actually doubting it. saagarjha knows his stuff. I just don't see it, so maybe I'm holding it wrong.
Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses
#89Earlier quoted context omitted.
Is this from iOS? I just tested from MacOS, and the only IPs were for the transit and auth servers. I'm not actually doubting it. saagarjha knows his stuff. I just don't see it, so maybe I'm holding it wrong.
See my comment here: https://news.ycombinator.com/item?id=48758444 .
I’ll mess around, today, and see what comes up.
Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses
#90Earlier quoted context omitted.
> then the real mail gets disclosed in the mail source. It's not just in the source, I totally overlooked the fact the real email address is shown as sender. Lol. > Does the initial sender matter? Like if it’s the HME address that sends first and receives the reply? I have around 180 of these addresses. Appears so. Here is exactly what I did: 1. Created the HME through mail, sending to other email service address (OM…
6. is a sign of bad UX but not leakage to the recipient.
What is bad UX is the fact there are two reply buttons in the iOS client. One "in" the mail and one for the thread. The mail one pretends to reply from HME alias, the thread one does not. This alone could expose you by accident, since anyone would expect to reply with HME in any case, but you get exposed either way.