This doesn't follow. The bounce message used to (effectively) say,
> [email protected] forwards to [email protected]
If they switched the new domain and did nothing else, it would say:
> [email protected] forwards to [email protected]
That's no better. Fixing that privacy leak is unrelated to whatever the destination domain is.
No, using a different domain makes it easy to across the board add a rule: don’t treat as Apple ID.