Skip to content

Server Name Indication (SNI)

Definition

A TLS extension sent in plaintext in the Client Hello message that identifies the hostname the client intends to reach. SNI is visible to any network observer and is a primary source of destination intelligence in encrypted traffic analysis. Encrypted Client Hello (ECH), not yet widely deployed, would hide the SNI field.

Protocol
TLS extension
Sent in
Client Hello message
Encryption status
Plaintext, visible to network observers
Mitigation
Encrypted Client Hello (ECH), not yet widely deployed
Sub-field
Network forensics, encrypted traffic analysis

Common questions

Why is SNI valuable to a network investigator even when the rest of the traffic is encrypted?+

Because SNI names the destination hostname before encryption is established, it lets an investigator reconstruct which services or domains a device connected to, even though the actual content of the session stays hidden by TLS.

Does the presence of SNI mean HTTPS traffic is not truly encrypted?+

No, the session payload itself remains encrypted, only the destination hostname in the initial handshake is exposed, which is a metadata leak rather than a break in content confidentiality.

How would widespread ECH deployment change encrypted traffic analysis?+

If Encrypted Client Hello becomes standard, the hostname field would no longer be visible in plaintext, forcing investigators to rely more heavily on IP address, timing, and traffic-shape analysis to infer destination rather than reading it directly.

Related terms

DNS Query Log
A record maintained by a DNS resolver listing each domain name query, the requesting IP address, the response, and the timestamp. DNS...
Encapsulation
The process by which each OSI layer wraps the payload from the layer above it inside its own header (and sometimes trailer)....
Flow Record
A summary record of a network conversation, typically recording source and destination IP addresses and ports, protocol, start time, duration, byte count...
JA3 Fingerprint
An MD5 hash computed from selected fields of the TLS Client Hello: the TLS version, cipher suites, extensions, elliptic curves, and elliptic-curve...
PCAP (Packet Capture File)
A binary file format that stores raw network traffic captured from a network interface. Tools such as Wireshark, tcpdump, and Zeek read...
Protocol Data Unit (PDU)
The named unit of data at each OSI layer: a frame at Layer 2, a packet at Layer 3, a segment at...
SSL Inspection (TLS Interception)
A technique in which an intermediary device terminates an incoming TLS session, inspects the decrypted content, then re-encrypts and forwards it using...
SSLKEYLOGFILE
A file format, originally implemented in Mozilla Firefox and later adopted by Chrome and other browsers, that logs TLS session keys as...
TCP Three-Way Handshake
The connection establishment sequence in TCP: the client sends SYN, the server responds SYN-ACK, and the client completes with ACK. The timestamps...
Traffic Fingerprinting
The process of identifying an application, protocol, or user action from statistical properties of an encrypted flow, such as packet size distributions,...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.