You might want to update this response with The truth that TLS 1.three encrypts the SNI extension, and the biggest CDN is doing just that: blog site.cloudflare.com/encrypted-sni Obviously a packet sniffer could just do a reverse-dns lookup for that IP addresses you're connecting to.This will improve in potential with encrypted SNI and DNS but as of