Encrypted Client Hello (ECH) is now supported on Vercel CDN
Vercel CDN has introduced support for Encrypted Client Hello (ECH), encrypting the Server Name Indication (SNI) in TLS handshakes to enhance privacy for domains using Vercel DNS.
Vercel CDN now supports Encrypted Client Hello (ECH), a feature that encrypts the Server Name Indication (SNI) during the TLS handshake process. This encryption obscures the hostname a client is connecting to, replacing it with a shared ECH hostname, vercel-ech.com, for network observers. The implementation is managed at the platform level and is automatically enabled where supported, beginning in the US for a limited set of top-level domains (TLDs).
The rollout of ECH is gradual, with expansion planned to additional TLDs and regions over time. Vercel has not specified a timeline for broader availability but notes that support will grow as compatibility increases. The feature is designed to enhance privacy by preventing third parties from identifying the specific domain a user is accessing during the initial connection phase.
ECH is compatible with recent versions of major browsers, including Chrome, Edge, and Firefox. Users accessing domains managed by Vercel DNS will benefit from this privacy enhancement without requiring manual configuration. The encryption occurs transparently, ensuring that the TLS handshake remains secure while protecting the hostname from exposure.
Vercel DNS customers can expect ECH to be enabled automatically where supported, starting with a limited set of TLDs in the US. The company has indicated that broader adoption will follow as more regions and TLDs are included in the rollout. This update aligns with ongoing efforts to improve privacy and security for web traffic managed through Vercel's infrastructure.