You may want to update this response with The truth that TLS 1.3 encrypts the SNI extension, and the biggest CDN is executing just that: site.cloudflare.com/encrypted-sni Obviously a packet sniffer could just do a reverse-dns lookup for that IP addresses you're connecting to. You can utilize OpenDNS with It can https://rudyardg370apa2.azzablog.com/profile