Let's say the system is running two web server daemons: a multi-tenant blog hosting platform listening on 2001:db8::1, and a multi-tenant bug tracker listening on 2001:db8::2. snid is on 192.0.2.1. Your DNS records would look like this:
blogs.example.com. A 192.0.2.1
blogs.example.com. AAAA 2001:db8::1
bugs.example.com. A 192.0.2.1
bugs.example.com. AAAA 2001:db8::2
The various tenants would be CNAMEd to one of these hostnames like: blog.domain1.example. CNAME blogs.example.com.
bugs.domain2.example. CNAME bugs.example.com.
The "decoy" hostnames (the "public_name" in ECH parlance) would be blogs.example.com or bugs.example.com. Thus, ECH would hide which tenant the client is connecting to, but would not hide the service. Note that if the client were connecting over IPv6, an eavesdropper would be able to determine the service anyways by looking at the destination IP address, which is unencrypted.