Encrypted Client Hello (ECH / ESNI)
Embed This Widget
Add the script tag and a data attribute to embed this widget.
Embed via iframe for maximum compatibility.
<iframe src="https://tldfyi.com/iframe/glossary/encrypted-sni/" width="420" height="400" frameborder="0" style="border:0;border-radius:10px;max-width:100%" loading="lazy"></iframe>
Paste this URL in WordPress, Medium, or any oEmbed-compatible platform.
https://tldfyi.com/glossary/encrypted-sni/
Add a dynamic SVG badge to your README or docs.
[](https://tldfyi.com/glossary/encrypted-sni/)
Use the native HTML custom element.
Encrypted Client Hello (ECH), anteriormente conocido como ESNI (Encrypted SNI), es una extensión TLS que cifra el campo Server Name Indication (SNI) en el handshake TLS. El campo SNI revela tradicionalmente a qué dominio se está conectando un cliente, incluso cuando el tráfico en sí está cifrado. ECH cierra esta brecha de privacidad usando una clave pública publicada en el [[dns|DNS]] del dominio para cifrar el SNI. ECH requiere [[dns-privacy|privacidad DNS]] (ej., [[dns-over-https-browser|DoH]]) para ser completamente efectivo.
Ejemplo
Without ECH, a passive observer on a CDN-hosted IP sees 'TLS ClientHello → target: example.com' even over HTTPS. With ECH, the SNI field is encrypted, revealing only the CDN's outer hostname.