You might want to update this respond to with The reality that TLS 1.three encrypts the SNI extension, and the largest CDN is performing just that: blog site.cloudflare.com/encrypted-sni Not surprisingly a packet sniffer could just do a reverse-dns lookup with the IP addresses you're connecting to. This may transform in https://derrickg368vup9.blogsvirals.com/profile