You might want to update this respond to with the fact that TLS 1.3 encrypts the SNI extension, and the most important CDN is doing just that: website.cloudflare.com/encrypted-sni Not surprisingly a packet sniffer could just do a reverse-dns lookup for the IP addresses you are connecting to. Note on the https://thomasw913zok7.wikiconversation.com/user