FINDING · EVALUATION

Only 1.5–2.25% of domains from TLD zone files have a valid ESNI key, with 15.4K of the top 100K and 143.3K of the top 1M popular domains supporting ESNI. All ESNI-supported domains are hosted by Cloudflare, making ESNI-enabled connections trivially distinguishable from the vast majority of TLS traffic and a low-collateral-damage blocking target for censors.

From 2022-hoang-measuringMeasuring the Accessibility of Domain Name Encryption and Its Impact on Internet Filtering · §4.2 · 2022 · Passive and Active Measurement Conference

Implications

Tags

censors
cnru
techniques
esni-eh-blockingsni-blocking
defenses
ech-esni

Extracted by claude-sonnet-4-6 — review before relying.