You may want to update this solution with The reality that TLS 1.3 encrypts the SNI extension, and the most significant CDN is carrying out just that: web site.cloudflare.com/encrypted-sni Needless to say a packet sniffer could just do a reverse-dns lookup with the IP addresses you're connecting to. Observe even https://fionai057miw2.bloggazzo.com/profile