If you rely on iCloud+ Hide My Email to protect your inbox, you may have noticed a frustrating change being widely reported: newly generated Hide My Email addresses are landing on the @icloud.com domain and staying there, even when you have a custom domain configured. Users in the Apple Support Community have flagged this as a widespread issue, with aliases refusing to switch over to personal domains, forwarding behaving inconsistently, and settings appearing to save without actually taking effect.
This guide walks through why it happens, what actually resolves it, and what to do if the fix doesn’t stick. Everything here applies to iCloud+ on iOS 18, iPadOS 18, macOS Sequoia, and the current iCloud web experience as of August 2026.
What Causes This Issue
Hide My Email operates as a relay: Apple generates a randomized address, receives mail sent to it, and forwards messages to your primary iCloud email. When you add a custom email domain to iCloud+, Apple is supposed to let you create Hide My Email aliases on that domain instead of the default @icloud.com relay. The problem is that this pipeline has several failure points:
- Domain verification state: If your MX, TXT, or SPF records aren’t fully propagated or verified by Apple’s mail servers, new aliases default back to @icloud.com.
- Account-level cache issues: The iCloud settings interface can display a domain as “active” even when the backend hasn’t finished registering it against your Apple Account.
- Multi-device sync lag: Changes made in Settings on iPhone don’t always propagate to iCloud.com or macOS System Settings in real time, causing the alias generator to fall back to defaults.
- Region and Apple Account mismatch: Users in the Apple Support Community have observed that recently migrated Apple Accounts, or accounts where the primary region was changed, sometimes lose the custom domain association silently.
- Subscription tier confusion: Custom domains require an active iCloud+ plan. If your subscription lapsed or was downgraded briefly, the domain permission can revoke without a clear notification.
- Server-side rollout bugs: Apple has quietly adjusted Hide My Email routing multiple times in 2026, and some accounts appear to be stuck on an older backend behavior.
Step-by-Step Fixes
Work through these in order. The first several steps address the most common cause — a broken link between your custom domain and the Hide My Email generator.
- Confirm your iCloud+ subscription is active. Open Settings, tap your name, then Subscriptions. Verify iCloud+ shows a current renewal date. If it’s expired or on the free 5 GB tier, custom domains and Hide My Email routing to personal domains will not work.
- Re-verify your custom domain. Go to iCloud.com, sign in, open Account Settings, and select Custom Email Domain. If any DNS record shows a warning or a yellow indicator, click Re-check. If verification fails, log into your domain registrar and confirm the MX, TXT (SPF), and DKIM records match exactly what Apple provides — including trailing dots where required.
- Remove and re-add the custom domain. This is the fix most frequently cited by users in the Apple Support Community as the one that finally worked. Delete the domain from iCloud.com’s Custom Email Domain panel, wait 10 minutes, then add it again and complete verification. Existing aliases will remain intact during this process.
- Sign out of iCloud on one device and back in. On a Mac or iPad you don’t use as your primary device, sign out of iCloud completely, restart, then sign back in. This forces the token that controls Hide My Email routing to refresh across Apple’s servers.
- Generate a new alias from iCloud.com, not from Settings. The web interface tends to reflect the most current server state. Go to iCloud.com, open Hide My Email, click the plus icon, and confirm the domain dropdown shows your custom domain. Create the alias there.
- Toggle Hide My Email off and on in Safari AutoFill. In Settings, go to Passwords, then AutoFill Passwords, and toggle iCloud off and on. This clears a local cache that can cause Safari to reuse older alias routing.
- Force-sync your Apple Account. Open Settings, tap your name, scroll to the bottom, and tap Sign Out — but choose only “Keep on This iPhone” for data. Sign back in immediately. Aliases and domain associations should refresh within a minute.
Additional Solutions
If the primary steps didn’t fix routing, these deeper fixes address less common causes.
Check DNS propagation from Apple’s perspective. Use a public DNS lookup tool to verify that your MX and SPF records resolve globally. Apple’s mail servers sometimes cache stale DNS for up to 72 hours after any change. If you recently modified records, wait a full three days before assuming the fix failed.
Disable and re-enable Hide My Email at the feature level. Go to Settings, tap your name, then iCloud, then Hide My Email. Toggle the feature off, wait 30 seconds, and toggle it back on. Any aliases you’ve created will not be deleted, but the routing table gets rebuilt.
Review forwarding addresses. Under Hide My Email settings, check the “Forward To” address. If it points to an outdated email or an alias that no longer exists, Apple’s backend may fall back to @icloud.com defaults for new aliases. Set it explicitly to your primary Apple Account email.
Look for a pending Terms and Conditions prompt. Occasionally, an unaccepted iCloud Terms update silently disables premium features including custom domain routing. Open Settings and look for any banner or notification badge on your Apple Account name.
Try a different network. Some corporate and public networks block or throttle Apple’s account-management endpoints. Switch to cellular data or a different Wi-Fi network and retry the domain verification.
When to Contact Apple Support
If you’ve completed every step above and new aliases still generate on @icloud.com, this is likely a server-side flag on your account that only Apple can clear. Contact Apple Support and specifically ask for the iCloud engineering escalation team — front-line advisors often don’t have visibility into Hide My Email backend routing. Have this information ready: your Apple Account email, the custom domain in question, screenshots of the domain verification page, and the exact date the issue started. Reference that you’ve already re-verified DNS and re-added the domain, so the case gets escalated faster.
If your business depends on the custom domain aliases, mention that as well. Apple prioritizes iCloud+ cases where custom domains are being used for professional correspondence.
FAQ
Will my existing Hide My Email aliases stop working if I remove and re-add the domain? No. Aliases created before removal continue to forward. Only the ability to create new aliases on that domain is affected during re-verification.
Can I use Hide My Email with a domain I don’t own? No. Apple requires DNS-level verification, which means you need registrar access to the domain.
Why does the iCloud.com interface show my domain as active but iPhone Settings doesn’t? This is a sync delay. Force-quit the Settings app, wait five minutes, and reopen. If it persists beyond an hour, sign out and back into iCloud on that device.
Does this issue affect Family Sharing members? Yes. Custom domains shared through Family Sharing can experience the same routing fallback. The Family organizer should perform the re-verification steps.
Is there a way to bulk-migrate existing @icloud.com aliases to my custom domain? Not currently. Each alias is tied to the domain it was created on and cannot be transferred.







































