Mail cannot function in IOS 18.2 if iCloud Private Relay is blocked at a network level

Hi Team,


As many of you are aware there are many use cases for blocking iCloud Private Relay at a network level. Most notably if using a DNS Filter like NextDNS, Pi-hole etc, or if on an enterprise network performing traffic inspection - as having private relay on bypasses these security controls.


According to Apple's own documentation the best way to force devices to disable private relay is as follows:

The fastest and most reliable way to alert users is to return either a "no error no answer" response or an NXDOMAIN response from your network’s DNS resolver, preventing DNS resolution for the following hostnames used by Private Relay traffic. Avoid causing DNS resolution timeouts or silently dropping IP packets sent to the Private Relay server, as this can lead to delays on client devices.


On these two addresses:

mask.icloud.com
mask-h2.icloud.com


However there is an issue. Ever since IOS 18.2 if you block these addresses the Mail App will not connect properly or download messages. Whitelisting these restores mail functionality but enables devices to use private relay / bypass security controls.


It's a poor experience for Apple Mail users, especially those who aren't aware of this, who just assume Mail is working poorly.


Apple - can you fix in a software update? I assume some recent change is loading part of mail through these - but it's painful for those of us trying to run a secure network!

Posted on Jan 5, 2025 2:27 PM

Reply
Question marked as Top-ranking reply

Posted on Jan 6, 2025 9:13 PM

We experience the same issue. Mail is using the domains even with everything related to private relay and hiding IPs turned off.


Mail seems to try downloading categories per sender domain. Thus we turned categories and showing contact photo's off (contact photo's is also showing category by icon). To no avail.


For every email received or sender domain Apple services are contacted in order to lookup this information. If this fails mail because the aforementioned domains are blocked Mail gets stuck downloading x messages.


Apple has tied itself this decentralized communication channel in inacceptabel way to make something like categorizing possible. It puzzles me how this idea has become reality.

20 replies
Question marked as Top-ranking reply

Jan 6, 2025 9:13 PM in response to Lammiwinks

We experience the same issue. Mail is using the domains even with everything related to private relay and hiding IPs turned off.


Mail seems to try downloading categories per sender domain. Thus we turned categories and showing contact photo's off (contact photo's is also showing category by icon). To no avail.


For every email received or sender domain Apple services are contacted in order to lookup this information. If this fails mail because the aforementioned domains are blocked Mail gets stuck downloading x messages.


Apple has tied itself this decentralized communication channel in inacceptabel way to make something like categorizing possible. It puzzles me how this idea has become reality.

Jan 13, 2025 11:00 AM in response to howellrj

Ah, that would explain it!


I'm seeing exactly the same issue - Mail is unusable on iOS 18.2.1 attempting to read mail from an iCloud account with a custom address when using Sky broadband in the UK, when we got a message saying private relay was incompatible.


The mail app on macOS is fine with the same account.

Outlook on iOS is fine when reading from the same account.

Turn off the wifi and use data for the Mail app - it's fine.


This needs addressing!

Jan 12, 2025 5:12 PM in response to Lammiwinks

I've experienced the same issue, but I've also found that when using Safari on my iPads or iPhones that webpage links intermittently get delayed in opening, by between 10-15 seconds. Allowing mask.icloud.com and mask-h2.icloud.com stops this issue, so I don't think it's only related to mail, but certainly it's more pronounced on the mail client.

For testing I moved my mail accounts to the Office365 App and I don't experience this on it.

The iOS mail client is affected with both IMAP, icloud and Office365 mail retrieval.


What are the chances Apple will respond to us?

Jan 13, 2025 1:27 PM in response to Lammiwinks

I have the same issue. The problem started when I upgraded to 18.2. I had few additional issues with email after upgrading to 18.2.1 which sort of confused the whole picture. But at the moment if I turn off WiFi on my iPhone, mail works as expected on mobile data. On WiFi it just stops working. I have turned off private relay and disabled pi-hole but the problem still persist if I’m on WiFi. So I’m lost as to what could be the issue. So I can only speculate that it must be something with the mail app itself on iOS since my Mac works as expected even with pi-hole.


tom

Jan 15, 2025 1:29 AM in response to pagzie

I fixed the issue by adding

mask.icloud.com
mask-h2.icloud.com


to the whitelist on my pi-hole as already mentioned before on this thread by Lammiwinks. I don't believe this is pi-hole issue since mail on MacOS works mail on my Fedora works. Android mail works as well and it all worked before the upgrade. My current LAN setup with WiFI has been in operation at least 3 years without any changes and I haven't had any issues until now.



Jan 15, 2025 2:34 PM in response to 3JB

3JB wrote:

This allows the iPhone to bypass your pi-hole entirely by using private relay. This fix breaks your pi-hole setup.

(Wow, the reply feature really does a sub-optimal job at displaying replies)


There's no threading on these boards and for some unfathomable reason they default to sorting by rank, not date order. You can save the sort order as a preference if you're logged in, but the boards will log you out a couple of times a day and revert back to rank order. The only way to keep track of what's going on is to use the quotes button at the bottom of the editing box.

Jan 28, 2025 2:25 PM in response to Lammiwinks

It depends how you look at it. Mail now comes in with 10-20 second delay instead of hours. iOS still creeps in between my private mail server and iPhone. Mail is a decentralized protocol. Apple shouldn't make it depend on its own infrastructure. The mail client/OS should have a feature to disable this behavior completely. And I would like it to be off by default.

Mail cannot function in IOS 18.2 if iCloud Private Relay is blocked at a network level

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.