Live data from Hacker News

Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

easyoptouts.com

81–90 of 105 posts

Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

#81
post #23

That timeline was exactly my experience with Apple here - https://www.grepular.com/Apples_Protect_Mail_Activity_Doesnt... They don't seem to know or care what is going on with their own email systems.

Has anyone seen Protect Mail Activity get re-enabled after you've disabled it? I wrote about that a few days ago: https://lapcatsoftware.com/articles/2026/6/6.html

Not for me. I don’t even remember when (or since how many years ago) I turned off Protect My Email and turned on both Hide IP Address and Block All Remote Content. I still have these toggles as they are, despite the fact that I use beta releases as and when they’re released (currently still on iOS 26.x).

Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

#82
post #37

Earlier quoted context omitted.

Source? I don't think this is true. Doesn't seem to be the case for me. Maybe your email provider attaches your IP address?

Seems like this is a Gmail thing: https://ylukem.com/blog/apple-mail-leaks-your-ip-address

I clearly remember many years ago that this wasn’t the case with Gmail, when looking for the source IP address in a case involving harassment of a person. I could only get Gmail’s own IP address in the headers from the multiple emails I examined at that time.

Nevertheless, as js2 said in another comment, it’s your mail provider (in this case Gmail) deciding whether to include the sender’s IP address or not.

Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

#83
post #39

Earlier quoted context omitted.

Fetching any email content is always worse than blocking it, because the typical threshold for spam is "is this inbox monitored". If that is true, then blast it with spam. And fetching anything ever proves that the inbox is monitored.

At least in Gmail, downloading content (e.g. images) is disabled by default for suspicious emails. There is no way for the sender to know if it’s monitored unless this is disabled by explicit user action.

[deleted]

Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

#84

That timeline was exactly my experience with Apple here - https://www.grepular.com/Apples_Protect_Mail_Activity_Doesnt... They don't seem to know or care what is going on with their own email systems.

Fetching any email content is always worse than blocking it, because the typical threshold for spam is "is this inbox monitored". If that is true, then blast it with spam. And fetching anything ever proves that the inbox is monitored.

[deleted]

Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

#86
post #58

Earlier quoted context omitted.

It’s in the headers. Send an email to your self from Mail and open the source in the inbox. There is your IP.

I also just tried this as well, sending an email from a Migadu-based account to one at both Gmail and MXRoute using Mail.app under macOS 15.7.7. Neither included any private IP address info I could find in either headers or raw source. That would be a good leak to know about and as sibling comment said saagarjha definitely knows their stuff, so any tips to replicate would be appreciated.

Received: from smtpclient.apple (ptr. [ip]) by smtp.gmail.com with ESMTPSA id ... for (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Thu, 02 Jul 2026 ..:..:.. -0700 (PDT)

Using Mail: Version 16.0 (3864.600.51.1.1).

Sent from a Google Apps mail.

Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

#87
post #80

Earlier quoted context omitted.

This freaked me out the first time I used Mail. It rendered a PDF about buying bitcoin on PayPal (I don't have PayPal). Looked at the same email in Gmail and Thunderbird, it's just a PDF attachment, no message, and the sender was different. No wonder people are falling for those scams, Mail makes it easy for them. Now if only I had a better client on my phone (never buying an iPhone again)

What made you prefer Mail to Gmail, given you don’t seem satisfied with Apple’s Mail app?

I prefer Thunderbird

Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

#88

Earlier quoted context omitted.

It’s in the headers. Send an email to your self from Mail and open the source in the inbox. There is your IP.

Is this from iOS? I just tested from MacOS, and the only IPs were for the transit and auth servers. I'm not actually doubting it. saagarjha knows his stuff. I just don't see it, so maybe I'm holding it wrong.

See my comment here: https://news.ycombinator.com/item?id=48758444.

Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

#89

Earlier quoted context omitted.

Is this from iOS? I just tested from MacOS, and the only IPs were for the transit and auth servers. I'm not actually doubting it. saagarjha knows his stuff. I just don't see it, so maybe I'm holding it wrong.

See my comment here: https://news.ycombinator.com/item?id=48758444 .

I saw that, in my headers, but in my case, it was not an IP in any subnet of mine.

I’ll mess around, today, and see what comes up.

Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

#90

Earlier quoted context omitted.

> then the real mail gets disclosed in the mail source. It's not just in the source, I totally overlooked the fact the real email address is shown as sender. Lol. > Does the initial sender matter? Like if it’s the HME address that sends first and receives the reply? I have around 180 of these addresses. Appears so. Here is exactly what I did: 1. Created the HME through mail, sending to other email service address (OM…

6. is a sign of bad UX but not leakage to the recipient.

That's what I thought, but I happens to coincide with the actual leakage, so....

What is bad UX is the fact there are two reply buttons in the iOS client. One "in" the mail and one for the thread. The mail one pretends to reply from HME alias, the thread one does not. This alone could expose you by accident, since anyone would expect to reply with HME in any case, but you get exposed either way.

Post reply on HN