This doesn't follow. The bounce message used to (effectively) say,
> abc@icloud.com forwards to real@gmail.com
If they switched the new domain and did nothing else, it would say:
> abc@privaterelay.appleid.com forwards to real@gmail.com
That's no better. Fixing that privacy leak is unrelated to whatever the destination domain is.
No, using a different domain makes it easy to across the board add a rule: don’t treat as Apple ID.
I'm not sure if I'm following. Apple is capable of creating a lookup table, or an atomic database read query.