Isnt' SNI based on the 'Host' header?! This is a news for me that SNI is not encrypted in TLS. Its a problem with the protocol not the ISPs then.
To send the domain securely the client needs to know the public key of the certificate the server is using.
This chicken and egg problem has gone unresolved for a long time, and only now are there efforts to fix it (see the work on esni).