ECH Deployment May 2026: Which National Censors Are Blocking It
Technical analysis of Encrypted Client Hello blocking in May 2026. Which censorship regimes filter ECH and which don't. Blocking methods: SNI inspection, DPI, IP blacklisting.
Recommended VPN Services
Top-rated VPNs trusted by millions
Disclosure: save-clip may earn a commission when you sign up through our links. This helps us keep our tools free for everyone.
As of May 2026, Encrypted Client Hello (ECH) deployment across major browsers and CDNs has reached approximately 40–50% of HTTPS traffic in unfiltered networks, according to publicly available telemetry from Cloudflare and Mozilla. However, deployment does not equal accessibility: a widening gap has emerged between jurisdictions where ECH functions and those where it faces active, documented blocking.
ECH is a TLS 1.3 extension that encrypts the Server Name Indication (SNI) field—the hostname a client requests during the TLS handshake. Historically, SNI was sent in plaintext, making it trivial for network operators to identify the destination domain without decrypting application-layer traffic. ECH closes this reconnaissance window by encrypting both the SNI and other client preferences, leaving only the IP address and timing metadata visible to passive observers.
BACKGROUND AND STANDARDS TIMELINE
RFC 8230 ("Using RSA Key Transport with HPKE") and RFC 9180 ("Hybrid Public Key Encryption") provided the cryptographic foundation. Mozilla Firefox shipped ECH support behind a flag in late 2022 and enabled it by default for most users by early 2024. Chrome began broader ECH rollout in 2024, though only for a subset of destinations. Apple's Safari and mobile clients have been slower to enable it widely. Major CDNs—Cloudflare, Google Cloud Armor, AWS CloudFront—began offering ECH support from 2023 onward.
The significance of ECH to censorship researchers is direct: it prevents DNS-independent domain identification. A censor using only passive SNI inspection loses the ability to block by hostname unless they also employ active probing, certificate pinning validation, or block entire IP addresses.
CURRENT BLOCKING LANDSCAPE
Roskomsvoboda's February 2026 technical report and OONI measurements from March–May 2026 document active ECH blocking in Russia. Roskomnadzor (Russia's federal communications authority) has not publicly mandated ECH blocking, but multiple large Russian ISPs—including MTS, Beeline, and Rostelecom—have deployed Deep Packet Inspection (DPI) systems that detect and reset connections attempting to use ECH. The blocking mechanism is connection-state based: TCP connections initiating ECH are terminated mid-handshake with RST packets. OONI probes within Russia report successful ECH connections to servers outside the censorship perimeter but consistent failures to domains Russia blocks via SNI filtering, even when ECH is used. This suggests Roskomnadzor has deployed active probing systems that attempt connections themselves to identify blocked domains, then block them regardless of SNI encryption.
China's state firewall has taken a narrower approach. According to GreatFire's monitoring (May 2026), the Great Firewall does not broadly reject ECH connections. However, Citizen Lab analysis of BGP hijacking and IP-space filtering in May 2026 indicates that China's strategy is to block IP addresses and autonomous systems associated with circumvention infrastructure, not to focus on ECH as a blocking vector. This may reflect the relative maturity of China's infrastructure-level controls.
Iran's Ministry of ICT (MoTT) began conducting limited ECH blocking trials in February 2026, according to Access Now's Shutdown Tracker observations. ITC (Iran Telecommunication Company) users report intermittent failures on ECH-enabled connections to foreign news and privacy sites, though the blocking is not universal. The technique appears to be DPI-based connection reset, similar to Russia's approach.
India's Department of Telecommunications (DoT) and NICTA (the regulatory authority) have not issued public guidance on ECH. OONI measurements show inconsistent blocking in some state-level networks, possibly due to filtering appliances that simply do not understand ECH yet rather than intentional policy.
The United Kingdom, Australia, and Canada have not deployed ECH-specific blocking as of May 2026, though all three jurisdictions employ SNI inspection for content filtering within their lawful interception frameworks. ECH's existence has accelerated academic discussion among these signals-intelligence communities, but no public statements indicate blocking.
TECHNICAL CIRCUMVENTION CONTEXT
For users in active-blocking jurisdictions, ECH alone is insufficient. A censor with infrastructure-level access (DPI, IP filtering, or active probing capability) can still identify and block destinations through several non-ECH vectors: certificate transparency logs, server timing analysis, IP geolocation, or simply blocking entire cloud infrastructure ranges used by circumvention platforms.
WireGuard and OpenVPN, deployed over non-standard ports or obfuscated with tools like obfs4 or Shadowsocks, remain effective because they hide the TLS handshake entirely, not just the SNI. Tor's pluggable transports—Snowflake for obfuscated WebRTC, WebTunnel for HTTP camouflage—work similarly. ECH is valuable in low-to-medium censorship environments; in high-censorship contexts, it is a defense-in-depth element rather than a standalone solution.
CONCLUSION
ECH's rollout reveals that blocking strategies now diverge sharply. Some censors have invested in active probing and IP-space control; others are still dependent on passive SNI inspection. Neither stance is stable. As ECH becomes default, censors will likely shift toward infrastructure-level blocking or adopt HTTPS traffic classification based on certificate analysis and server behavioral signatures. The encryption of client metadata is an arms-race escalation, not an endpoint.
Found this useful? Share it
Recommended VPN Services
Top-rated VPNs trusted by millions
Disclosure: save-clip may earn a commission when you sign up through our links. This helps us keep our tools free for everyone.