You may want to update this answer with the fact that TLS 1.3 encrypts the SNI extension, and the largest CDN is executing just that: website.cloudflare.com/encrypted-sni Needless to say a packet sniffer could just do a reverse-dns lookup for that IP addresses you happen to be connecting to. This will https://assisim343tjy1.losblogos.com/profile