we_are_coded.by CODE · The world, decoded
БГ
Who's who

ECH (the hidden site name)

The BasicsUpdated on 1 October 2026we are coded

Even over HTTPS, the name of the site you open travels in the open. ECH hides it.

Checked on1 October 2026
In short: ECH (Encrypted Client Hello) is a way to hide the name of the site you open. With HTTPS the content is encrypted, but in the first message between the browser and the server the site name (SNI, Server Name Indication) goes in the clear. Your provider, the office network or the cafe network can see it. ECH encrypts that too. Since March 2026 it is an official IETF standard, RFC 9849.

You send a letter in a sealed envelope. Nobody can read what is inside. But the address is on the front, in big letters, and every postman along the way sees it. That is exactly how HTTPS works without ECH. The padlock in the browser protects the content: what you read, what you type, your password. But at the very start the browser tells the server which site it wants. It says it openly, because one server often hosts many sites and needs to know which one to show you. The standard puts it dryly: the plain name leaks the destination to anyone on the path.

Think about what that means in practice. You open a site about loans, a doctor or a job. What exactly you look at there, nobody on the path knows. But the site name shows, and often the name alone says enough.

ECH splits that first message in two. The outer part is harmless and shows a shared name, usually that of the company running the servers. The inner part carries the real name and is encrypted with the server's key. The browser gets that key from DNS, the internet's phone book. At Cloudflare, for example, every ECH site shows the same name from the outside: cloudflare-ech.com.

The padlock protects the letter. ECH protects the address on the envelope too.

Where the protection ends

The trick only works in a crowd. If one address hosts a single site, the hidden name does not help much, because the address gives it away. The standard admits it: the site can still be seen through other channels, such as plaintext DNS queries or the server's IP address. That is why ECH makes sense together with encrypted DNS.

Cloudflare announced ECH support in September 2023, when Chrome and Firefox were just starting to roll it out. Back then the standard was still a draft. Now it has a number.

ECH does not make you invisible. It makes your list of sites harder to read for anyone on the path. That is not much. It is a lot more than nothing.

The visual is generated code art. No third-party images.
Official primary sources
→RFC 9849: TLS Encrypted Client Hello (IETF, March 2026)→IETF: TLS Encrypted Client Hello (draft-ietf-tls-esni, now RFC 9849)→Cloudflare: Encrypted Client Hello - the last puzzle piece to privacy (2023)