Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
World desk5 min

Cloudflare Encrypts SNI Across Its Network: What ECH Protects—and What It Doesn’t

Cloudflare replaced experimental ESNI with Encrypted Client Hello (ECH), which hides the requested hostname inside TLS but cannot conceal DNS leaks, destination IPs or every traffic signal.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cloudflare’s original Encrypted SNI (ESNI) deployment hid the hostname sent in a TLS handshake, but the mechanism evolved into Encrypted Client Hello (ECH). ECH now encrypts the inner ClientHello—including SNI and other handshake details—while leaving some information, such as DNS activity and destination IP addresses, potentially visible. Cloudflare documents ECH as enabled by default for Free zones, with controls for other plans.

What is encrypted SNI?

Server Name Indication (SNI) is the hostname a browser places in the TLS ClientHello. Shared hosting providers use it to select the correct website configuration and certificate when many sites use one IP address. In earlier TLS handshakes, this hostname was sent in cleartext before the rest of the session was protected, so an on-path observer such as an ISP, Wi-Fi operator or intermediary could read it.

Cloudflare announced an experimental, standards-based ESNI deployment in 2018. ESNI encrypted the SNI extension with a public key published through DNS and was described as requiring TLS 1.3 or later. Cloudflare’s announcement was a deployment milestone, not a guarantee that every browser, site or connection used ESNI.

Cloudflare’s historical explainer said its ESNI keys were rotated hourly while recent keys were retained to accommodate DNS caching and replication delays. That describes the implementation in that article; it should not be treated as a current Cloudflare setting.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
TP-Link ER605, Wired Gigabit VPN Router
  • 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
  • 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
  • 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
  • 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
  • Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q

Read the original announcement at Cloudflare’s ESNI announcement and the technical explanation at Cloudflare’s encrypted-SNI explainer.

Does Cloudflare encrypt SNI today?

Cloudflare’s current mechanism is ECH, the successor to ESNI. ECH encrypts an entire inner ClientHello under a server public key advertised to the client. The encrypted inner message contains SNI plus other potentially sensitive handshake fields; a visible outer ClientHello remains for routing and compatibility.

In Cloudflare’s deployment, the outer SNI commonly uses cloudflare-ech.com. An observer can therefore identify Cloudflare as the service provider, but cannot necessarily read the participating customer hostname inside the encrypted ClientHello. Cloudflare announced broad ECH availability in 2023, while its current documentation says ECH is on by default for Free zones. Other plans can expose an enable/disable control in the Edge Certificates dashboard. Settings and plan behavior can change, so consult the current Cloudflare ECH documentation.

Rank #2
GL.iNet GL-SFT1200 Opal Travel Router, AC1200 Dual-Band Wi-Fi
  • 【AC1200 Dual-band Wireless Router】Simultaneous dual-band with wireless speed up to 300 Mbps (2.4GHz) + 867 Mbps (5GHz). 2.4GHz band can handles some simple tasks like emails or web browsing while bandwidth intensive tasks such as gaming or 4K video streaming can be handled by the 5GHz band.*Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
  • 【Easy Setup】Please refer to the User Manual and the Unboxing & Setup video guide on Amazon for detailed setup instructions and methods for connecting to the Internet.
  • 【Pocket-friendly】Lightweight design(145g) which designed for your next trip or adventure. Alongside its portable, compact design makes it easy to take with you on the go.
  • 【Full Gigabit Ports】Gigabit Wireless Internet Router with 2 Gigabit LAN ports and 1 Gigabit WAN ports, ideal for lots of internet plan and allow you to connect your wired devices directly.
  • 【Keep your Internet Safe】IPv6 supported. OpenVPN & WireGuard pre-installed, compatible with 30+ VPN service providers. Cloudflare encryption supported to protect the privacy.

What is the difference between ESNI and ECH?

Characteristic ESNI ECH
Encrypted scope Encrypts the SNI extension. Encrypts an inner ClientHello containing SNI and additional handshake fields.
Protocol status Described as an IETF draft in Cloudflare’s 2018 announcement. Specified by RFC 9849 as an IETF Standards Track document, published March 2026.
Visible information Other ClientHello metadata remained visible; DNS and the destination IP could still disclose the destination. An outer ClientHello remains visible. DNS and the destination IP can still disclose or narrow the destination, and Cloudflare’s outer name reveals the provider.
Cloudflare context Historical 2018 network deployment. Current Cloudflare deployment, documented as default for Free zones and configurable for other plans.

The IETF defines ECH succinctly: “This document describes a mechanism in Transport Layer Security (TLS) for encrypting a ClientHello message under a server public key.” See RFC 9849.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cloudflare explained the transition from ESNI to ECH in its 2020 technical overview. Encrypting only SNI left other ClientHello fields available for fingerprinting or policy decisions, so the broader inner-ClientHello design became the practical successor.

Can my ISP see what websites I visit if ECH is enabled?

ECH can prevent the ISP from reading the website hostname in the TLS ClientHello, but it does not make browsing anonymous. The remaining signals matter:

Rank #3
Sale
ASUS RT-AX1800S Dual Band WiFi 6 Extendable Router, Subscription-Free Network Security, Parental Control, Built-in VPN, AiMesh Compatible, Gaming & Streaming, Smart Home
  • New-Gen WiFi Standard – WiFi 6(802.11ax) standard supporting MU-MIMO and OFDMA technology for better efficiency and throughput.Antenna : External antenna x 4. Processor : Dual-core (4 VPE). Power Supply : AC Input : 110V~240V(50~60Hz), DC Output : 12 V with max. 1.5A current.
  • Ultra-fast WiFi Speed – RT-AX1800S supports 1024-QAM for dramatically faster wireless connections
  • Increase Capacity and Efficiency – Supporting not only MU-MIMO but also OFDMA technique to efficiently allocate channels, communicate with multiple devices simultaneously
  • 5 Gigabit ports – One Gigabit WAN port and four Gigabit LAN ports, 10X faster than 100–Base T Ethernet.
  • Commercial-grade Security Anywhere – Protect your home network with AiProtection Classic, powered by Trend Micro. And when away from home, ASUS Instant Guard gives you a one-click secure VPN.
  • DNS queries: Plaintext DNS can expose the hostname before the TLS connection starts. Encrypted DNS such as DNS over HTTPS (DoH) or DNS over TLS (DoT) protects the query in transit to the chosen resolver, but it is separate from ECH.
  • Destination IP address: The connected IP remains visible to a network observer. If an address is dedicated to one site, it may identify that site; shared hosting makes attribution less certain.
  • Provider identity: With Cloudflare’s deployment, the outer name cloudflare-ech.com can show that the connection is going to Cloudflare.
  • Traffic metadata: Timing, volume and connection patterns are not automatically hidden by ECH.

RFC 9849 explicitly cautions that ECH alone cannot conceal a target when plaintext DNS or a visible server IP reveals it. ECH is therefore one layer in a privacy design, not a replacement for encrypted DNS, careful network architecture or anonymity tools.

How ECH is deployed

Shared mode

In shared mode, the provider is the origin-facing service and terminates TLS for the protected sites. Consistent externally visible TLS behavior across co-located sites can create an anonymity set: an observer sees the shared outer connection rather than the specific inner hostname.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Split mode

In split mode, the fronting provider relays traffic to a separate backend TLS terminator. This separates the public-facing ECH service from the system that handles the origin’s TLS session. The topology affects which provider or intermediary can observe connection details, so ECH should be evaluated alongside the operator’s trust model.

Rank #4
Sale
GL.iNet GL-BE3600 Slate 7 Wi-Fi 7 Travel Router Touchscreen 2.5G
  • 【DUAL BAND WIFI 7 TRAVEL ROUTER】Products with US, UK, EU, AU Plug; Dual band network with wireless speed 688Mbps (2.4G)+2882Mbps (5G); Dual 2.5G Ethernet Ports (1x WAN and 1x LAN Port); USB 3.0 port.
  • 【NETWORK CONTROL WITH TOUCHSCREEN SIMPLICITY】Slate 7’s touchscreen interface lets you scan QR codes for quick Wi-Fi, monitor speed in real time, toggle VPN on/off, and switch providers directly on the display. Color-coded indicators provide instant network status updates for Ethernet, Tethering, Repeater, and Cellular modes, offering a seamless, user-friendly experience.
  • 【OpenWrt 23.05 FIRMWARE】The Slate 7 (GL-BE3600) is a high-performance Wi-Fi 7 travel router, built with OpenWrt 23.05 (Kernel 5.4.213) for maximum customization and advanced networking capabilities. With 512MB storage, total customization with open-source freedom and flexible installation of OpenWrt plugins.
  • 【VPN CLIENT & SERVER】OpenVPN and WireGuard are pre-installed, compatible with 30+ VPN service providers (active subscription required). Simply log in to your existing VPN account with our portable wifi device, and Slate 7 automatically encrypts all network traffic within the connected network. Max. VPN speed of 100 Mbps (OpenVPN); 540 Mbps (WireGuard). *Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
  • 【PERFECT PORTABLE WIFI ROUTER FOR TRAVEL】The Slate 7 is an ideal portable internet device perfect for international travel. With its mini size and travel-friendly features, the pocket Wi-Fi router is the perfect companion for travelers in need of a secure internet connectivity on the go in which includes hotels or cruise ships.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How do I enable ECH on Cloudflare?

For a Cloudflare zone, use the current dashboard behavior documented by Cloudflare:

  1. Sign in to the Cloudflare dashboard and select the account and zone.
  2. Open SSL/TLS, then Edge Certificates.
  3. Locate the ECH setting. Cloudflare documents ECH as enabled by default for Free zones; on other plans, use the available toggle to enable or disable it.
  4. Allow DNS and HTTPS-record changes to propagate, then test with an ECH-capable browser and resolver. A client without ECH support will use the ordinary TLS path.

Because Cloudflare changes dashboard labels and plan behavior, verify the exact control in the live documentation rather than relying on an old screenshot or tutorial.

Can administrators suppress ECH?

Enterprise and regional network operators that need domain-based filtering can control whether clients receive ECH configuration through their local or recursive DNS resolver. Cloudflare documents approaches that omit ECH parameters from HTTPS resource records or answer HTTPS queries so clients cannot obtain them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
TP-Link Dual-Band AX3000 Wi-Fi 6 Wireless Gigabit Internet Router for Home
  • Next-Gen Gigabit Wi-Fi 6 Speeds: 2402 Mbps on 5 GHz and 574 Mbps on 2.4 GHz bands ensure smoother streaming and faster downloads; support VPN server and VPN client¹
  • A More Responsive Experience: Enjoy smooth gaming, video streaming, and live feeds simultaneously. OFDMA makes your Wi-Fi stronger by allowing multiple clients to share one band at the same time, cutting latency and jitter.²
  • Expanded Wi-Fi Coverage: 4 high-gain external antennas and Beamforming technology combine to extend strong, reliable, Wi-Fi throughout your home.
  • Improved Battery Life: Target Wake Time helps your devices to communicate efficiently while consuming less power.
  • Improved Cooling Design: No heat ups, no throttles. A larger heat sink and redefined case design cools the WiFi 6 system and enables your network to stay at top speeds in more versatile environments.

Those interventions are policy controls, not general privacy recommendations. Cloudflare warns that modifying HTTPS records can break DNSSEC-validating clients. Its documentation also describes a canary-domain approach for dealing with browser behavior in some environments. Test changes on the organization’s clients and DNSSEC path before broad deployment.

What ECH does—and does not—promise

  • It does: encrypt the inner ClientHello, including the requested hostname, when the client, resolver and server successfully negotiate ECH.
  • It does not: hide plaintext DNS queries, the destination IP, Cloudflare’s provider identity in its deployment, or all traffic-analysis signals.
  • It does: reduce hostname disclosure on shared infrastructure, where many sites can present the same externally visible behavior.
  • It does not: ensure protection on every connection; unsupported clients, blocked ECH configuration and incompatible network policies can force a fallback path.

Bottom line

Cloudflare’s 2018 encrypted-SNI work was the early step; ECH is the current, broader design. It materially reduces hostname exposure in the TLS handshake, and Cloudflare now documents it as a default for Free zones. Pair ECH with encrypted DNS and remember that IP addresses, provider identity and traffic patterns can still reveal useful information.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.