About

Background

ECH encrypts the TLS Client Hello with a public key the client fetches from DNS ahead of time, so an on-path observer can no longer read which hostname (i.e., SNI) a connection is for.

This site is a web front end for echtool, a tool for measuring how servers deploy ECH. It connects to a single domain, offers an ECH configuration, and reports how the server answered. These commands are available here:

The test command runs experiments against one or more domains at once. Its modes are only available in the CLI:

A probe against a domain (over TCP or QUIC) is classified as one of:

StatusMeaning
acceptedthe server completed the handshake using the offered configuration
rejectedthe server understood ECH but rejected the offered configuration, optionally returning fresh retry configurations
not acceptedthe handshake completed, but without ECH
failedthe connection failed or never started, so the target said nothing about ECH either way

Project team

Jonas Mücke, TU Dresden

Contact

For questions about ECH handshakes, this tool, or anything it reports, reach out at jonas.muecke@tu-dresden.de.

Partners