This doesn't follow. The bounce message used to (effectively) say,

> abc@icloud.com forwards to real@gmail.com

If they switched the new domain and did nothing else, it would say:

> abc@privaterelay.appleid.com forwards to real@gmail.com

That's no better. Fixing that privacy leak is unrelated to whatever the destination domain is.

No, using a different domain makes it easy to across the board add a rule: don’t treat as Apple ID.

I'm not sure if I'm following. Apple is capable of creating a lookup table, or an atomic database read query.