I just realized that when sending Gmail messages through third‑party email clients (e.g., Thunderbird, Apple Mail), Gmail adds a Received: header which includes the sender’s public IP address. After checking my own message headers, my IP was indeed exposed.
This behavior isn’t new. There’s an older write‑up explaining how Apple Mail leaks both public and private IPs when using Gmail’s SMTP:
To compare, I tested Outlook and iCloud Mail as well. In both cases, IP address was not exposed. Instead, the mail appears to be relayed through Microsoft’s or Apple’s infrastructure, so the Received: headers only show the server IPs.
It seems worth adding a warning about this in PG email client guide, since it affects anyone using Gmail with non‑Google clients and isn’t immediately obvious. In this specific case, sticking to Gmail’s webmail/apps may actually be the more privacy‑preserving option.
As far as I can trace back from googling, this has been around for well over a decade: