Header Banner
Gadget Hacks Logo
Gadget Hacks
Apple
gadgethacks.mark.png
Gadget Hacks Shop Apple Guides Android Guides iPhone Guides Mac Guides Pixel Guides Samsung Guides Tweaks & Hacks Privacy & Security Productivity Hacks Movies & TV Smartphone Gaming Music & Audio Travel Tips Videography Tips Chat Apps
Home
Apple

Fake Hide My Email Header Can Expose Your Apple Account Address

"Fake Hide My Email Header Can Expose Your Apple Account Address" cover image

A forged email header can make Apple's Mail app on Mac send a reply from the email address associated with your Apple Account, even when the message arrived through another account and you have never used Hide My Email.

Developer Jeff Johnson disclosed the behavior on July 19, 2026. In his test, a message containing a crafted X-Icloud-Hme header caused Mail's compose window to show a misleading sender identity. When he sent the reply, it came from his private Apple Account email address instead.

Johnson said he does not use Hide My Email and does not have an iCloud.com mailbox. The crafted message could also arrive through an unrelated personal or work account, potentially exposing an address the recipient had kept separate.

The behavior has been demonstrated in Mail on Mac, but the affected macOS and Mail versions have not been identified. It has not been confirmed in Mail on iPhone or iPad, and there is no public evidence that the technique has been used in an actual attack.

How the fake Hide My Email header works

The central problem is a mismatch between the sending identity Mail displays and the address it transmits.

Johnson used the command-line tool curl to send himself an email containing an arbitrary X-Icloud-Hme header. Unlike a typical email app, curl allowed him to add the header and control its values.

Mail displayed "Hide My Email" in the reply window's From field and added a notice saying the original message had been forwarded through Apple's alias service. When Johnson sent the reply, however, it came from the email address associated with his Apple Account rather than the identity shown in the compose window.

The test suggests Mail trusted sender-supplied information without confirming that Apple's Hide My Email service had generated it. Johnson documented the visible behavior rather than Mail's internal validation process, so the underlying cause remains unconfirmed.

The result was a clear interface failure: Mail showed one sending identity but transmitted the reply from another address.

MacGeneration independently reproduced the behavior, including with an account that did not use iCloud for email.

You do not need to use Hide My Email

The reported behavior is not limited to Hide My Email subscribers.

A crafted message can arrive through a separate personal or business account configured in Mail. In Johnson's test, replying exposed the Apple Account email address rather than using the account that received the message.

That creates a privacy risk for people who use Mail to keep personal, professional, and public-facing identities separate. Journalists, researchers, activists, legal professionals, business owners, and anyone who keeps an Apple Account address private could reveal it by replying.

Disclosure of a private address could also make it easier for someone to connect separate online identities or tailor an Apple-themed phishing attempt. The flaw itself does not reveal a password, unlock an Apple Account, grant mailbox access, or bypass two-factor authentication.

An independent report on the forged-header issue found no identified list of affected versions or evidence of real-world exploitation. As of July 23, 2026, Apple had not publicly announced a fix or advisory specifically addressing this Mail behavior.

What to check before replying

The address was exposed only after Johnson sent the reply. Receiving or opening the crafted message alone was not shown to disclose it.

Until Apple provides more information, take these precautions when replying in Mail on Mac:

  • Watch for an unexpected Hide My Email label. If the reply window shows "Hide My Email" even though the original message was not sent to one of your aliases, close the draft without sending it. The label does not prove the header was forged, but it is a reason to inspect the message.

  • Create a new message instead of replying. Select the intended From address manually and verify it before sending. This avoided the reply behavior in the documented testing, although it does not fix the underlying Mail problem.

  • Inspect the full message headers. In Mail, choose View → Message → All Headers. An X-Icloud-Hme header is not proof of an attack, but its presence alongside an unexpected Hide My Email label warrants caution.

Checking the From field is still useful, but Johnson's demonstration shows that the identity displayed in a reply may not match the address Mail ultimately sends. Starting a new message lets the user choose the sending account instead of relying on the affected reply interface.

This is separate from the earlier Hide My Email flaw

Johnson's finding is technically separate from a previously reported Hide My Email vulnerability that could reveal the permanent address behind a genuine alias.

Apple told 404 Media that it deployed a fix for that earlier problem on July 3, 2026. AppleInsider nevertheless said it reproduced the older vulnerability on July 17. The researchers later said the issue had been fixed, leaving the exact rollout timeline unclear.

The earlier flaw involved Apple's Hide My Email forwarding service. The new finding involves a sender placing a forged header in a message and Mail exposing an Apple Account email address when the recipient replies. A person does not need to use Hide My Email for the newly disclosed behavior to occur.

A proposed class action filed against Apple on July 15 concerns the earlier alias vulnerability and the company's marketing of Hide My Email. The complaint alleges that Apple misled customers about the feature's privacy protections. The allegations have not been proven, and the lawsuit does not claim that the named plaintiff's address was exposed in an actual attack.

Apple has not identified which Mac configurations are affected by the forged-header issue or whether the same behavior can occur on an iPhone or iPad. Until that changes, create a new message instead of replying whenever Mail unexpectedly displays Hide My Email, then verify the From address before sending.

Apple's iOS 26 and iPadOS 26 updates are packed with new features, and you can try them before almost everyone else. First, check our list of supported iPhone and iPad models, then follow our step-by-step guide to install the iOS/iPadOS 26 beta — no paid developer account required.

Sponsored

Related Articles

Comments

No Comments Exist

Be the first, drop a comment!