Because it can't be privacy, any ISP or router along the way can see the source/destination IP which is "naked" and basically has to always be?
Because it can't be privacy, any ISP or router along the way can see the source/destination IP which is "naked" and basically has to always be?
(also just getting rid of the name is effective at getting the info away from low tech surveillance like schools where someone on the route is mildly interested in seeing/blocking connections but won't bother if it's annoying to do)
If the source device then connects to whatever IP was in the answer, and you have that IP mapped, then you can reveal what they might be connecting to, but that requires more data and processing compared to plaintext DNS and still won't reveal the actual encrypted traffic.
With shared IPs from CDNs, hosting providers, and VPNs, it provides far more obfuscation for the average user.
The next standard is ECH (encrypted client-hello) which secures the entire handshake: https://blog.cloudflare.com/encrypted-client-hello/