ECH is an industry wrap for more of ClientHello. It is uneven. The IP hop remains. Klox does not toggle it.

ECH in Plain English: Encrypting More of ClientHello

Encrypted Client Hello tries to hide more of the TLS first flight, not only the leftover hostname. Browsers, CDNs, and origins have to agree. Deployment is uneven. A VPN still moves the hop. Klox has no ECH toggle.

KloxVPN Team
22 min readPublished 2021-09-15Updated 2026-05-07
ECH in Plain English: Encrypting More of ClientHello
ECH is an industry wrap for more of ClientHello. It is uneven. The IP hop remains. Klox does not toggle it.

Encrypted Client Hello is an industry attempt to encrypt more of the TLS first flight. Not a leftover nickname. Not a padlock. Not a tunnel. The ClientHello is the packet that starts TLS. Historically a lot of it rode in the clear, including the server name, so a shared host could pick a certificate. ECH tries to put the sensitive bits of that first flight in an inner envelope only the intended edge can open. The path still sees an outer hello. The path still sees an IP. Do not claim the cafe sees nothing.

A VPN still wraps the path from your device to a server you picked. Wikipedia's VPN page is the noun. RFC 8446 is TLS 1.3 on the website. It is not ECH. Cloudflare's Good-bye ESNI, hello ECH post is the follow link for the wrap itself. Read it as their engineering story. It is not a Klox Connect setting.

This is not SNI in Plain English: The Name TLS Still Sends. That URL is the leftover hostname: why the letters exist, what a capture still shows when they are clear. ECH shows up there as a cape people over-buy. This page is the cape: who has to ship it, why shipping is uneven, what still leaks when it works, why a hop still earns rent. I will not rewrite the name essay. This is not VPN vs HTTPS in Plain English: Two Locks, Two Hops. Two locks. ECH is a third object: handshake metadata, not page body and not a truck. This is not What DNS Does on a VPN (Plain English). A DNS question is earlier. ECH is later, during TLS start. This is not the VPN on Cafe Wi-Fi: A Habit, Not a Superpower. Splash pages live there. ECH is one row in that shop, not the ritual.

KloxVPN is WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, 7-day money-back on first purchase. Features lists DNS through the tunnel, IPv6 leak protection, WebRTC leak blocking. There is no ECH toggle. There is no consumer custom-DNS picker. There is no city count. Download is the apps. Pricing is the live number. Cookies on this site live at /cookie. ECH is not a cookie, and a cookie page is not a handshake.

I have a bias. Treat ECH as real where browser, CDN, and origin actually agree. Treat it as missing everywhere else. Add a tunnel when the local map is a problem you have. Do not wait for the industry to finish hiding first flights. Do not skip the padlock because a blog said ClientHello is solved.

Related reading: DNSSEC vs a VPN in Plain English: Signatures Are Not a Hop and Cmpsxadd: Not a Mitigation Toggle. Cmpxchg: Not a Mitigation Toggle and What is a VPN?. VPN kill switch and DNS leak explained.

Looking for a reliable VPN?

KloxVPN — from $2.83/month. Apps for every device.

View Plans

ClientHello is a first flight

TLS starts with a ClientHello. That message is how your device and a server agree how to lock the rest of the session. RFC 8446 already encrypts a lot of what used to sit in the open after the first flight. The first flight itself still had leftovers: the server name, and other parameters people with a capture could read. Encrypted Client Hello is the attempt to hide more of that first flight, not only the name field. ESNI tried to hide the name and stalled. ECH is the later design: inner hello encrypted, outer hello still visible so the edge can talk at all.

You do not need the inner-versus-outer diagram memorized to use a website. You need the split. Page body is the padlock. First-flight metadata is ECH's job where it runs. Destination IP is neither. Farms mash all three because all three sound like 'they can see me.' Split them. The SNI in Plain English: The Name TLS Still Sends owns the leftover name as a noun. This page owns the wrap that tries to swallow more of that first packet.

The wrap exists for a privacy reason, not because virtual hosting vanished. Shared hosts still need a name. ECH moves the real name into the inner envelope and puts a public name on the outer one so a CDN can still terminate. Cloudflare's explainer walks that P.O. box metaphor. I will not clone their diagram. I will say: the cafe may see 'talking to a public ECH name' instead of 'talking to your bank.' That is quieter. It is not idle. It is not a VPN.

If you already live in packet captures, you know the extension. If you do not, you do not need to start now. Trust the split: inner parameters versus outer hop versus page body. ECH, when it actually runs, quiets inner parameters on the path. A VPN moves the outer hop. HTTPS locks the page. I will not stand behind 'the cafe sees nothing.' Volume, timing, and the fact you used their AP remain. The first flight is what this page exists to name.

Join Wi-Fi, finish the login page, then connect the VPN
On guest Wi-Fi: join the network, finish the sign-in page, then connect.

    How to read this page

  1. 1Skim the seating / order diagram.
  2. 2Do the numbered steps once on your real network.
  3. 3Use the FAQ if a sentence was too long.
  4. 4Follow one related article — not ten tabs.
What ECH changes on a clear path. Not a Klox SLA. Not an ECH toggle. Not a city count.
ObserverPage body on HTTPSClientHello if ECH actually runsIP hopWith Klox connected
Cafe LANNo, if TLS is real and the host is the one you meantQuieter inner fields; outer hello still thereYesSees a blob to a VPN; not the inner hello
Home ISPNo on TLS sitesQuieter where ECH shipped; clear where it did notYesSees a blob to a VPN
CDN edge that decrypted ECHIt is on the path to the siteIt opened the inner hello; that is the designSees a session to itselfSees the VPN exit as the client
Path where ECH failed openStill TLS if the retry workedName and first flight may be clear againStill yesTunnel still moves the outer hop
Cookie on klox.appUnrelatedUnrelatedUnrelatedSee /cookie; neither is a handshake

ECH hides more of ClientHello where it actually runs. The cafe still sees an IP and a session. A VPN still moves that hop.

— KloxVPN consumer notes

Cloudflare Learning: What is a VPN?

Wikipedia: Virtual private network

IETF RFC 8446 (TLS 1.3)

Cloudflare: Good-bye ESNI, hello ECH

NordVPN: HTTPS vs VPN (competitor specimen)

More than the leftover name

ESNI tried to hide SNI and stopped. ECH encrypts a larger inner ClientHello. The leftover-name essay is next door. This URL is the wrap that tried to finish the first flight.

What this post is not

Not the hostname noun. Not two locks. Not cafe splash timing. Not a DNS leak procedure. Those URLs exist. This URL is who has to ship ECH until you can say it without mixing it with Connect.

Three parties have to ship it

ECH is not a website checkbox you forgot. The browser has to speak it. The CDN or client-facing edge has to advertise a public key, usually via HTTPS records in DNS. The origin stack behind that edge has to be in a config that actually offers ECH. Miss any chair and the first flight stays the old first flight. That is why 'ECH shipped in 2023' and 'my bank still shows a name on cafe Wi-Fi' can both be true before lunch.

Browsers disagree. A nightly build is not your aunt's Chrome. A corporate-managed browser may disable the experiment. A phone WebView may not match the desktop story. I will not publish a compatibility matrix that goes stale on Tuesday. Assume the client in your hand might not be the client in a press release.

CDNs disagree. One edge network has been loud about ECH. Other hosts still terminate TLS the old way. A site on a cheap shared box with a single certificate may not have an ECHConfig to publish. A site behind a middlebox that wants to read names will not help you hide them. You do not pick the stack when you tap a link. The stack picks you.

Origins disagree. Turning ECH on at a CDN dashboard does not rewrite every origin on earth. A marketing domain on Cloudflare and an API on a regional load balancer are two deployments. Farms write as if the internet is one vendor. It is not. Three parties. Three failure modes. That is the product state, not a temporary bug you wait out while skipping a tunnel.

DNS has to carry the key

The client usually learns ECHConfig from HTTPS records. If DNS never got those records, or an on-path resolver stripped them, the wrap cannot start. Encrypted DNS and ECH are cousins, not substitutes. The DoH essay owns the question envelope.

You do not configure the origin

Tapping Connect does not publish an ECH key for Gmail. The site's operator does, or does not. Klox is not that operator. Do not open a ticket asking us to enable ECH on someone else's host.

Uneven is the 2026 state

Some paths have ECH. Some do not. Some have it in one browser and not another. Some have it until a hotel middlebox, a school filter, or a 'security appliance' that still wants names. Do not write 'SNI is dead' because a CDN blog said the last puzzle piece shipped. Do not write 'ECH never works' as if the IETF work was fiction. Uneven means uneven. Plan as if the first flight might still be readable on the clear path you actually use this afternoon.

I will not perform handshake theater. No screenshots of extension lists. No draft numbers you have to memorize to use Klox. If you want to see a ClientHello on your own LAN, you already know Wireshark. If you do not, you do not need to. The consumer fact is: assume the wrap might be missing. Assume a tunnel still earns its keep when the wrap is present, because IPs remain.

Retry is part of the design. If the edge cannot decrypt the inner hello, it may complete on the outer hello and hand back a key so the client can try again. That retry can look like 'ECH' in a lab and still spend a moment looking like a clear name to a capture. GREASE exists so ECH-shaped hellos are not a rare fingerprint. Those are protocol details. They are not a promise that your cafe path is quiet.

NordVPN's HTTPS-versus-VPN post is a specimen of the mash: padlock versus tunnel as a winner. ECH farms mash the wrap versus invisibility the same way. Use the specimen. Do not import a winner. There is no winner. There is a first flight, an IP, a padlock, and a hop you can turn on.

HTTPS versus a VPN tunnel
HTTPS locks the page. A VPN wraps the path to a server you chose.

Press releases are not your path

A CDN can enable ECH on a large share of its names and still leave your doctor's portal on a stack from 2019. Test the path you care about, or skip the test and tunnel.

Middleboxes still want names

Corporate TLS inspection, some parental filters, some 'next-gen' firewalls: they break or disable ECH on purpose. That is a policy. It is not a Klox bug. If work owns the network, this essay is background.

What still shows when ECH runs

Hide the inner ClientHello and you still have numbers. You opened a connection to some address for some number of minutes. An observer who already knows who lives at that address does not need the inner name. A small site on a dedicated IP is a doorbell. A huge CDN anycast IP is a neighborhood. Do not pretend every IP is a neighborhood. Do not pretend every IP is a doorbell. Reality is mixed. ECH does not delete the mix.

Volume remains. Timing remains. A four-hour fat blob is still a four-hour fat blob. The wrap changes which letters sit in the first flight. It does not make you look idle. A VPN changes who the cafe thinks you talked to. It also does not make you look idle. Both sentences can be true. Farms omit the second one because idle sells.

SNI quieter is not DNS quieter. If the resolver question still left in the clear before TLS started, the shopping list already shipped. ECH does not time-travel. Tunnel DNS is a different leftover. Encrypted DNS to a public resolver is another. Stacking them as vitamins is how tickets start. One owner for names while a tunnel is up. Klox is that owner on our apps. We are not selling a picker.

I will not invent city counts so the map sounds fancier. You pick a server in the app. Nearby is usually enough when the job is 'hide this hop from the shop,' not 'pretend I live in a catalog.' Catalogs are a different article. This one is numbers that survive a wrapped first flight.

The IP is the leftover ECH cannot eat

Inner fields can be wrapped. The later connect is still a connect to an address. Cafe Wi-Fi still sees that connect unless a tunnel ate the hop.

Volume is still metadata

Encrypting a hello does not shrink a 4K stream into a blink. If your threat watches sizes, plan for that. Most cafe threats do not. Most ISP graphs still like names and IPs more than byte counts.

Klox does not ship an ECH toggle

ECH is a browser-and-CDN story. The tunnel is a device-to-node story. Keep them in separate drawers. Mixing them is how you get a ticket that says 'why is the first flight still a thing if I paid for a VPN.' Because ECH lives in the TLS stack of the client talking to the site. A VPN encrypts a hop to a node you chose. After that node, you still speak HTTPS like everyone else. The inner handshake still exists. The cafe does not sit on it when the tunnel is up. The hop operator is not the website.

I will not pretend our Connect button ships ECH for you. There is no row. There is no 'encrypt ClientHello' switch. Features lists DNS through the tunnel, IPv6 leak protection, WebRTC leak blocking. Quote those for Connect. Do not quote them for a Firefox flag. Do not quote them for a CDN dashboard you do not run.

WireGuard first. OpenVPN when the AP hates UDP. Same ECH story on both protocols: we do not implement the wrap, and we do not need to for the cafe hop to move. Protocol hopping is not extra ECH. Five devices: phone plus laptop is two seats if both tunnels are up. A tunneled phone does not wrap the laptop's clear first flight. Count.

Smart Connect, if the app shows the row, is connect on untrusted Wi-Fi. It starts the hop that moves the interesting packet off the cafe path. It does not enable ECH. If the row is missing, you have a Connect button. Use the button. I will not invent an always-on handshake wrap so this article matches another vendor's screenshot.

Inner TLS still has a hello

The VPN node is not the website. After the tunnel, you still speak HTTPS to the site. That inner handshake still has parameters. The cafe does not sit on that inner hop when you are connected.

No SKU, no ticket

Do not ask support which ECH mode to pick. There is not one. If a farm screenshot shows 'Handshake protection,' that is their product. Ours is a hop.

A tunnel sits in a different drawer

With Klox up, the interesting hop for the cafe and the ISP becomes the VPN server. They still know you used the AP. They still see volume. They see a destination you chose when you picked a node. They do not get the inner map of sites unless something leaked around the tunnel: DNS, IPv6, WebRTC, an excepted app, a second NIC. Features lists tunnel DNS, IPv6 leak protection, WebRTC leak blocking. Confirm after connect if you like labs. Then stop collecting testers.

ECH on the inner path still depends on the three parties. The cafe does not care. The cafe sees a blob. That is the hop job. It is true whether the site you later open has ECH, lacks ECH, or has it only on Tuesdays. 'ECH shipped, so I uninstalled the VPN' is a bad slogan for the same reason 'HTTPS shipped, so I uninstalled the VPN' was a bad slogan. Different leftover. Same mistake.

The website still sees you logged in. A tunnel is not a new identity. It is a new first hop. Inner TLS still ends at the site. RFC 8446 still applies. People ask whether the VPN can read the page. On a normal HTTPS site, the inner lock still faces the site. The hop operator sees a tunnel. The resolver, if it is ours, sees names. That is a shopping list at a hop, not an inbox.

I will not crown ECH versus VPN. You can have both. You can have neither. You can have ECH in one tab and a clear first flight in an app that is not a browser. Per process. Per device. A tunneled Pixel does not wrap a laptop that never connected. Download from /download so you are not configuring a cousin app's 'Secure Handshake' screen from memory.

Per device, not per press release

Each gadget that joins the shop SSID needs its own tunnel if you care about that gadget's hop. ECH will be there or not per client. The hop lock is per NIC.

WireGuard, then OpenVPN

Same leftover physics. WireGuard is the default I want. OpenVPN is the spare tire when a rude AP blocks UDP. Switching protocols will not wrap a ClientHello you never tunneled.

Fallback, filters, and the clear path

When ECH cannot run, the client falls back to the old first flight. That is how the web keeps loading. It is also how a capture on cafe Wi-Fi still gets a name. Filters that break ECH on purpose count on that fallback. A school that inspects TLS will not thank you for a GREASE hello. A cafe captive portal does not speak ECH. Complete the splash on a boring site. Then Connect. The habit post owns the timing. Here: do not treat a failed wrap as a Klox outage.

Certificate warnings are still your job. A tunnel encrypts a mistake as happily as a real bank. The padlock on a host you did not intend is not the padlock you wanted. ECH on a lookalike domain is still a wrap to a liar. Phishing is a lie you believed. Encryption of a lie is still a lie. I will not turn this into a PKI course. Trust the browser's name match. Do not install a cafe's extra root because a PDF said Wi-Fi required it.

Hiding a first flight, whether by ECH or by a tunnel, cannot scan the attachment. It cannot make the AP honest. An evil twin still gets your traffic. Encrypted, if the tunnel is up. The twin can still captive-portal you, still annoy you, still see that you spoke to a VPN. Encryption is not authentication of the coffee shop. Ask the staff the SSID.

It cannot replace unique passwords. It cannot replace updates. It cannot replace 2FA. The What a VPN Cannot Do catalog owns that list. I will not paste it. I will say: a quieter ClientHello on a phone full of reused passwords is a nicer hop for the same account takeover. It cannot unlock a streaming catalog I did not promise. ECH trivia plus a VPN is not a Netflix product.

Fallback is how the web survives

If the wrap fails, the page should still load. That success is also a clear first flight on that path. Plan for the success you did not want.

The shop is not a certificate authority

The cafe does not issue Gmail's cert. A VPN node does not either. Trust the browser. Ask humans for the SSID. Those are different trust problems.

After connect, the hop still pays

If you want proof the hop moved, use the leak-test after connect article. IP, DNS, WebRTC, IPv6 as a procedure. This page will not become that procedure. ECH is not a row on most consumer leak sites. Those sites show an IP and a resolver. They do not print your last ClientHello. Do not demand they do. If the IP is the VPN and DNS is the tunnel, the cafe's interesting hop moved. That is the check that pays rent. It pays even when ECH is perfect on the inner site, because the cafe was never supposed to sit on that inner hello.

Do it once on a network you control. Then stop. Daily labs are how people forget to live. If a test fails, fix the leftover: IPv6, WebRTC, a browser DoH override, an excepted app. Then test once more. Then drink the coffee.

Yearly from $2.83 a month is not a reason to skip the padlock. It is a reason you can afford the hop without a farm's lifetime coupon. Seven days on first purchase if the product is not the hop you wanted. Refunds live on /refund. Store purchases follow the store. This page will not turn into a billing sermon. It will also not turn into an ECH roadmap. Absence of a toggle is the product.

If you only needed the English, stop here. If you needed the leftover name as a noun, the SNI essay is next door. If you needed two locks as a pair, that URL exists. If you needed cafe timing, that habit post exists. If you needed the shopping list, DNS on a VPN owns it. If you needed a cape, you wanted a farm. If you needed a hop that still moves the first flight off the LAN, you wanted Klox. Practice once on a guest SSID. Then use it.

Leak sites do not print ClientHello

They print IP and DNS. That is enough to know whether the outer hop moved. Wireshark is how you see a first flight. Most people do not need Wireshark. Most people need Connect.

One afternoon, then stop

Download the apps. Connect on a guest SSID at home. Run one leak test. Notice that the cafe will not get your inner hello. Then use the habit. Do not collect extension screenshots as a personality.

Key Takeaways

Encrypted Client Hello tries to hide more of the TLS first flight. Browsers, CDNs, and origins have to agree. Deployment is uneven. Do not claim the cafe sees nothing. The IP hop remains. Volume remains. A path without ECH still shows a clear leftover name. That leftover has its own essay.

A VPN moves the interesting hop to a node you chose. Klox is WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, seven-day first purchase. DNS through the tunnel. No ECH toggle. No city count. No custom DNS picker. Cookies on this site live at /cookie.

If you wanted the hostname noun, that essay is next door. If you wanted two locks, that URL exists. If you wanted cafe timing, that habit post exists. If you wanted the wrap, you have it. Download the apps. Connect on networks you do not run. Leave the padlock on. The first flight was never the page.

Move the hop. ECH will not do that job.

KloxVPN is WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, 7-day first-purchase money-back. ECH is uneven and is not a Connect toggle. HTTPS already locked the page. The IP hop can still leak on the LAN. Download the apps if you want that hop to be a VPN.

Download KloxVPN

Frequently Asked Questions

An industry TLS wrap that encrypts more of the ClientHello, the first flight that starts a session, including the real server name in an inner envelope. The path still sees an outer hello and an IP. It is not the page body and not a VPN.

KloxVPN Team

Experts in VPN infrastructure, network security, and online privacy. The KloxVPN team has been building and operating VPN services since 2019, providing consumer and white-label VPN solutions to thousands of users worldwide.