Thanks for the pointers.
The coverage is calculated by DNS servers and web proxies and can only be incorrect if circumvented. The web proxies are almost all in corporate environments where they cannot be circumvented. Only a tiny fraction of HTTPS uses a TLS1.3 extension to encrypt the FQDN of the web server - the rest of the HTTPS traffic can be monitored.