You may want to update this answer with The point that TLS one.3 encrypts the SNI extension, and the largest CDN is executing just that: blog.cloudflare.com/encrypted-sni Certainly a packet sniffer could just do a reverse-dns lookup to the IP addresses you might be connecting to. Note on the other hand https://joycey727gwm0.thechapblog.com/profile