Is there a way to force SNI by blocking ECH requests?
... and even if it wasn't, ECH works by reading public keys from DNS, so the domain owner has claimed "you can send ECH" and it's pretty easy to know "therefore you shouldn't downgrade if you are capable, it's probably an attacker". Though unencrypted DNS renders this all a bit moot of course.
---
tl;dr, with the caveat that IANAWebSecuritySpecialist and I haven't found anything I'd call actually conclusive yet:
I believe "no". Unless you are setting up client-side CAs, at which point you can MITM everything so it hardly matters.
https://datatracker.ietf.org/doc/html/draft-ietf-tls-esni-22...