You may want to update this reply with The truth that TLS 1.3 encrypts the SNI extension, and the most important CDN is doing just that: weblog.cloudflare.com/encrypted-sni Certainly a packet sniffer could just do a reverse-dns lookup to the IP addresses you are connecting to.You may use OpenDNS with It is encrypted DNS support. I use it on my Mac,