> Very limited with TLS. With webhosts, the PTR record means little.
TLS+SNI sends the `Host` you are connecting to in plain text. eSNI is not yet widely deployed.
Centralizing DNS without centralizing HTTP (e.g. domain fronting) does not solve the leak of connection metadata.