Twitch: *.ttvnw.net
Netflix: *.nflxvideo.net
Hulu: *.hulustream.com
YouTube: *.googlevideo.com
Amazon Prime: *.aiv-cdn.net
Edit: This is by no means the only way to do it, just a potential way to do it.
Twitch: *.ttvnw.net
Netflix: *.nflxvideo.net
Hulu: *.hulustream.com
YouTube: *.googlevideo.com
Amazon Prime: *.aiv-cdn.net
Edit: This is by no means the only way to do it, just a potential way to do it.
For mobile ISP's like T-Mobile, they cannot tell that video content is streamed through a VPN protocol like wireguard (but they could add large public providers to the list).
As a good rule of thumb I tell people to run speedtests from both speedtest.net (which is usually whitelisted by every provider) and fast.com (which usually shows up as Netflix video traffic) to see if 'video shaping' rules are in effect.
Oh, wait, they've already been doing that for <insert Gary Oldman> EVERYONE!</insert>
I think its just network analysis or possibly even those caching servers that are run by ISPs which hold onto content network's most heavily used files.
1. during the TLS handshake, the domain name itself might be sent in the clear if the SNI extension is used, and if the SNI extension isn't encrypted[1]
2. if the carrier knows the IP, then they can do a reverse DNS lookup to find the domain name
[1] https://stackoverflow.com/questions/499591/are-https-urls-en...