methods / ech-explained

ECH - the setting that hides which site you visit

Short answer

ECH encrypts the Client Hello in HTTPS, hiding site names from censors.

Introduction to ECH

Encrypted Client Hello (ECH) is a technology that encrypts the Client Hello message in HTTPS connections, making it difficult for censors to block websites based on their names [1]. This is achieved by encrypting the Server Name Indication (SNI) field, which contains the name of the website being accessed. ECH is an improvement over the earlier Encrypted SNI (ESNI) technology and is now a standard, as described in the IETF TLS Encrypted Client Hello draft [2].

How to enable ECH

To enable ECH, you need to configure your browser to use it. The process varies depending on the browser you are using.

Chromium browsers (Chrome, Edge, Brave): Open chrome://flags/#encrypted-client-hello, set Encrypted ClientHello to Enabled, and relaunch your browser. ECH only activates together with secure DNS, so also enable "Use secure DNS" with a supported provider in your settings [1].

Firefox: Open about:config, set network.dns.echconfig.enabled and network.dns.http3_echconfig.enabled to true, with DoH set to a supported provider. Note that Firefox has toggled ECH on and off during server-side rollouts [3], so if it does not engage, you may need to try the Chromium route.

Verifying ECH

To verify that ECH is working, you can use a tool like Crypto Check. However, since external links are not provided in the sources, you can search for "ECH test page" to find a suitable testing tool. Look for sni=encrypted in the response text. If the field says encrypted, your handshake hides the site name; if it shows the plain host, either the browser setting is off or the site's edge does not support ECH.

Where ECH works and where it does not

ECH works when the site is behind an ECH-capable edge, such as Cloudflare. This means that a huge share of the web, including most long-tail sites, can be accessed using ECH. Your browser asks Cloudflare's edge for the handshake key via secure DNS and encrypts the SNI against it.

However, ECH fails when the site hosts directly on its own servers with no ECH support. In such cases, there is nothing to encrypt the name against, and alternative solutions like packet tricks or tunnels may be necessary.

ECH also fails on networks that block the key distribution. Some censors have noticed ECH and now block the HTTPS/DNS records that carry the handshake keys or drop connections to Cloudflare's key endpoint entirely. If ECH silently stops working on a censored network, it does not mean it is broken; rather, it is being resisted.

Failure modes and workarounds

If ECH is not working, there are several possible reasons. One common issue is that the site's edge does not support ECH. In such cases, you may need to use alternative solutions like packet-level tools or a real tunnel.

Another issue could be that the network is blocking the key distribution. In such cases, you may need to use a different DNS provider or a VPN to bypass the censorship.

Platform differences

ECH works differently on different platforms. For example, on Chromium browsers, ECH is enabled by default when secure DNS is enabled. On Firefox, ECH is enabled by default when DoH is enabled.

However, the exact behavior may vary depending on the specific browser and platform you are using. It is essential to check the documentation for your specific browser and platform to understand how ECH works and how to enable it.

Why ECH beats VPNs for some cases

ECH is free, has no app to install, no account, and no speed loss. When it works, it is the cheapest possible fix. Unlike VPNs, which can introduce latency and require subscription, ECH is a built-in feature that can be enabled with a few clicks.

Moreover, ECH is more private than VPNs because it does not require trusting a third-party provider with your internet traffic. With ECH, your traffic is still encrypted end-to-end, but the SNI field is encrypted as well, making it difficult for censors to block websites based on their names.

However, ECH is not a replacement for VPNs in all cases. If you need to access a website that is blocked by a censor that can detect and block ECH, a VPN may be a better solution. Additionally, if you need to protect your identity and location, a VPN may be a better choice.

Conclusion

ECH is a powerful technology that can help you bypass censorship and access blocked websites. By encrypting the SNI field, ECH makes it difficult for censors to block websites based on their names. While it is not a replacement for VPNs in all cases, ECH is a free, built-in feature that can be enabled with a few clicks, making it an attractive solution for many users. You can learn more about how to unblock any website using different methods, including ECH, VPNs, and more.

What ECH hides: the site name inside the TLS handshake without ECH ClientHello ... server_name: example.com (readable by the censor) with ECH ClientHello ... outer: public-edge-name [inner record sealed] the censor sees only the shared edge (cloudflare-class), not which site you asked for
ECH wraps the site name inside a second record

FAQ

What is ECH?

ECH is a technology that encrypts the Client Hello message in HTTPS connections.

How do I enable ECH?

Enable ECH in your browser settings, usually found in the flags or config section.

Does ECH work on all websites?

No, ECH only works on websites behind an ECH-capable edge, such as Cloudflare.

Is ECH better than a VPN?

ECH is free and has no speed loss, but it may not work in all cases, especially if the censor can detect and block ECH.

Can I use ECH with other censorship circumvention tools?

Yes, you can use ECH with other tools, such as packet-level tools or a real tunnel.

Sources

  1. Cloudflare - Encrypting SNI (ECH) overview - accessed 2026-09-30
  2. IETF TLS Encrypted Client Hello draft - accessed 2026-09-30
  3. Mozilla bug tracker - ECH rollout - accessed 2026-09-30

Related