CloudProxy
← Back to Blog

Can Your ISP See What You Browse? DNS, HTTPS and SNI Explained

Published October 1, 2026 · Bipul Ranjan
indiaprivacynetworking

“It’s HTTPS, so my ISP can’t see anything” is only half true. Your ISP can’t read your messages or see which page you’re on, but it can still see quite a lot. Knowing where the line is helps you make sense of both privacy advice and the way websites get blocked in India.

What your ISP can see

Every connection your device makes leaves several traces on the network, and your ISP carries all of it.

  • Your DNS queries. Before connecting to a site, your device asks a DNS server for its address. By default that question is sent unencrypted to your ISP’s DNS server, so the domain names you look up are visible.
  • The destination IP address. Even without DNS, the address you connect to often identifies the site or the company hosting it.
  • The server name in the TLS handshake (SNI). When your browser starts an HTTPS connection, it says in plain text which hostname it wants, so the server can present the right certificate. This field is called the Server Name Indication, and by default it isn’t encrypted.
  • Timing and volume. When you’re online and roughly how much data moves. This can hint at what you’re doing, like streaming versus browsing.
  • Everything on plain HTTP. Sites without HTTPS expose the full page and any form data.

What your ISP can’t see

With HTTPS, the actual content is encrypted between your browser and the site: the page you’re reading, the specific URL path after the domain, your searches on that site, and anything you type into forms, including passwords.

What encrypted DNS changes, and what it doesn’t

Encrypted DNS (DNS-over-HTTPS, or Android’s Private DNS) wraps your DNS queries so your ISP can’t read them. That closes one of the leaks above, but it moves that visibility to whichever DNS provider you chose, so you’re changing who sees your queries, not eliminating it. It also leaves the others in place: your ISP still sees the destination IP address and, by default, the SNI. A newer feature called Encrypted Client Hello (ECH) is designed to encrypt the SNI as well, but it only works when both your browser and the website support it, so it isn’t something you can rely on everywhere yet. If you want to set up encrypted DNS, we have a step-by-step guide for Android, Windows and routers.

Why this matters for website blocking in India

The fields above are exactly what blocking systems look at. A March 2026 study of six major Indian ISPs, reported by MediaNama, identified four techniques in use: HTTP-based blocking, DNS poisoning or injection, SNI-based TLS blocking, and IP/TCP-level blocking. Earlier research by the Centre for Internet and Society found Jio inspecting the SNI field to decide which HTTPS connections to reset. In other words, the parts of your traffic that stay visible to the network are the parts that get used to filter it. The same study found ISPs don’t apply identical block lists, which is why a site can work on one network and fail on another.

Where a VPN fits

A VPN encrypts everything between your device and the VPN server, so your ISP sees only that you’re connected to the VPN, not the sites behind it. But the VPN provider now sees what your ISP used to see, so you’re choosing whom to trust. Our Proxy vs VPN guide covers how each works, and our Privacy & Browser Leak Checker shows what your browser exposes regardless of the network.