I’ll try to add more later, but it is believed that multiple times, a bug in some random API has allowed for the “hidden” Apple account to be revealed because they resolve hide my emails to the original internally. Using a separate namespace would be the universal fix.
A mitigation for the cause of https://www.404media.co/apple-hide-my-email-vulnerability-re...
This doesn't follow. The bounce message used to (effectively) say,
> [email protected] forwards to [email protected]
If they switched the new domain and did nothing else, it would say:
> [email protected] forwards to [email protected]
That's no better. Fixing that privacy leak is unrelated to whatever the destination domain is.