One IP address often serves thousands of websites, especially behind a CDN. To present the right certificate, the server needs to know which site you want before encryption starts, so the client names it in the first TLS message, the ClientHello. That field is SNI, defined in RFC 6066.
Why it matters
- It is visible. Anyone on the path, including your network and any proxy, can read the hostname in the SNI. A proxy using CONNECT already knows it from the CONNECT line anyway. The pages, paths and headers stay encrypted.
- It is part of your fingerprint. Whether a client sends SNI, and how, feeds TLS fingerprints: the
doriin a JA4 string records whether the client named a domain or connected to a bare IP. - It must match. CDNs check that the SNI and the HTTP
Hostheader name the same site, and many refuse a mismatch.
See it
openssl lets you set the SNI explicitly and shows which certificate comes back:
openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null | grep subject=
Drop -servername against a CDN-hosted site and you may get a default certificate for a different name, or a failed handshake.
Common confusion
Encrypted Client Hello (ECH) hides the real SNI inside an encrypted extension, but it needs support from both the browser and the server, and many clients and sites do not use it yet. Until they do, assume the hostname you connect to is visible to whoever carries your traffic, even over HTTPS.