Even over HTTPS, the name of the site you open travels in the open. ECH hides it.
You send a letter in a sealed envelope. Nobody can read what is inside. But the address is on the front, in big letters, and every postman along the way sees it. That is exactly how HTTPS works without ECH. The padlock in the browser protects the content: what you read, what you type, your password. But at the very start the browser tells the server which site it wants. It says it openly, because one server often hosts many sites and needs to know which one to show you. The standard puts it dryly: the plain name leaks the destination to anyone on the path.
Think about what that means in practice. You open a site about loans, a doctor or a job. What exactly you look at there, nobody on the path knows. But the site name shows, and often the name alone says enough.
ECH splits that first message in two. The outer part is harmless and shows a shared name, usually that of the company running the servers. The inner part carries the real name and is encrypted with the server's key. The browser gets that key from DNS, the internet's phone book. At Cloudflare, for example, every ECH site shows the same name from the outside: cloudflare-ech.com.
Where the protection ends
The trick only works in a crowd. If one address hosts a single site, the hidden name does not help much, because the address gives it away. The standard admits it: the site can still be seen through other channels, such as plaintext DNS queries or the server's IP address. That is why ECH makes sense together with encrypted DNS.
Cloudflare announced ECH support in September 2023, when Chrome and Firefox were just starting to roll it out. Back then the standard was still a draft. Now it has a number.
ECH does not make you invisible. It makes your list of sites harder to read for anyone on the path. That is not much. It is a lot more than nothing.