{"id":199087,"date":"2022-08-24T04:20:56","date_gmt":"2022-08-24T02:20:56","guid":{"rendered":"http:\/\/sftarticles.wpenginepowered.com\/en\/?p=199087"},"modified":"2025-07-01T20:30:33","modified_gmt":"2025-07-02T03:30:33","slug":"how-to-make-ms-edge-safer-encrypted-client-hello","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/how-to-make-ms-edge-safer-encrypted-client-hello\/","title":{"rendered":"How to make MS Edge safer by turning on Encrypted Client Hello"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Most information you send or receive on today\u2019s internet passes through a layer of encryption to make sure it can only be read by the sender and receiver. This task is generally done via an <strong>automatic encryption key exchange<\/strong> through a cryptographic protocol in your browser. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The current most popular key exchange protocol is a handshake called <strong>Transport Layer Security (TLS)<\/strong>. By following just a few steps, you can enable the latest TLS extension \u2014 known as <strong>Encrypted Client Hello (ECH)<\/strong> \u2014 in your Microsoft Edge browser to <strong>make your information even safer<\/strong>.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Microsoft Edge\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-logo-xl,f_auto\/p\/449d6486-96d2-11e6-b4e2-00163ec9f5fa\/2182742371\/microsoft-edge-Icon.jpg\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Microsoft Edge<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/microsoft-edge.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">Download<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/microsoft-edge.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n<div class=\"howto_container schema-howto-acf-block\"><ol><li><div class=\"howto_item\"><h2>Open MS Edge properties<\/h2><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2022\/08\/02.ech_.properties.jpg\" alt=\"Microsoft Edge Properties\" width=\"798\" height=\"720\"><p>Find the shortcut you use to access MS Edge in your Start menu, taskbar, or desktop. Right-click on the shortcut, and select <i>Properties<\/i> from the popup menu.<\/p>\n<p>Go to the <i>Shortcut<\/i> tab in the <i>Properties<\/i> box. In the <i>Target<\/i> text box, third from the top, you\u2019ll see the path to the location of your msedge.exe file. It should look something like \u201cC:\\..\\msedge.exe.\u201d<\/p>\n<\/div><\/li><li><div class=\"howto_item\"><h2>Update path location and launch<\/h2><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2022\/08\/03.ech_.target.jpg\" alt=\"The Target text box in MS Edge\u2019s Properties dialogue\" width=\"480\" height=\"720\"><p>Don\u2019t change the path itself. Directly after it, add a space followed by <i>&#8211;enable-features=EncryptedClientHello<\/i>.<\/p>\n<p>Click <i>OK<\/i> at the bottom of the Properties box.<\/p>\n<p>Use the shortcut you just modified to launch MS Edge.<\/p>\n<\/div><\/li><li><div class=\"howto_item\"><h2>Enable support for HTTPS records in DNS<\/h2><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2022\/08\/04.ech_.flag1_.jpg\" alt=\"Enable the first flag\" width=\"1200\" height=\"363\"><p>Before you start browsing, click on Edge\u2019s address bar, and paste <i>edge:\/\/flags\/#dns-https-svcb<\/i>.<\/p>\n<p>Edge will display a list of services you can turn on or off. The first one is titled <i>Support for HTTPS records in DNS<\/i>. Click on the drop-down list to the right of that service, and select <i>Enabled<\/i>.<\/p>\n<\/div><\/li><li><div class=\"howto_item\"><h2>Enable use DNS https alpn<\/h2><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2022\/08\/05.ech_.flag2_.jpg\" alt=\"Enable the second flag\" width=\"1200\" height=\"343\"><p>Click on the address bar again, and type in <i>edge:\/\/flags\/#use-dns-https-svcb-alpn<\/i>. Select <i>Enabled<\/i> next to the option labeled <i>Use DNS https alpn<\/i>.<\/p>\n<p>Next, press Alt + F to open Edge\u2019s menu. Click on <i>Settings<\/i> and then <i>Privacy, search, and services<\/i>.<\/p>\n<p>Under the <i>Security<\/i> subheading, find the option labeled <i>Use secure DNS to specify how to lookup the network address for websites<\/i>. Click on the toggle switch on the right to enable this. The switch will turn blue.<\/p>\n<\/div><\/li><li><div class=\"howto_item\"><h2>Select Cloudfare as service provider and relaunch Edge<\/h2><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2022\/08\/06.ech_.security.jpg\" alt=\"Enable secure DNS\" width=\"1200\" height=\"603\"><p>Directly below, click the option labeled <i>Choose a service provider<\/i>. In the list of available providers below that, choose <i>Cloudflare<\/i>.<\/p>\n<p>Restart the Edge browser. The ECH update is now enabled.<\/p>\n<\/div><\/li><li><div class=\"howto_item\"><h2>Use an Encrypted Client Hello checker<\/h2><p>You can check that ECH is working properly in your <a href=\"https:\/\/microsoft-edge.en.softonic.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Edge browser<\/a> by visiting the defo.ie ECH check page at: <i>https:\/\/defo.ie\/ech-check.php<\/i>. Check the status of the SSL ECH parameter. It should read <i>success!<\/i><\/p>\n<\/div><\/li><\/ol><\/div><style type=\"text\/css\">\n\t.howto_container {\n\t  margin: 0 auto;\n\t}\n\t.howto_container img {\n\t\theight: 100%;\n\t\tmargin-bottom: 30px;\n\t}\n\t\n\t\t  .howto_container h2 {\n\t\t\t  clear: none !important;\n\t\t  }\n\t\t  .howto_container ol {\n\t\t\t  list-style: none !important;\n\t\t  }\t\n\t.howto_container ol li::before {\n\t\tcolor: #ffffff !important;\n\t\tbackground:#0073aa !important;\n\t}\n<\/style>\n\n\t\t\n\n\n<h2 class=\"wp-block-heading\">Why should you enable ECH in Microsoft Edge?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The TLS protocol was designed to protect data streams flowing between a web app like your browser and an external server. Since it was first created in 1999, TLS developers have released various updates to the protocol, the latest of which is TLS 1.3. Encrypted Client Hello is an add-on to TLS 1.3, <strong>extending its protection to include the full handshake<\/strong> between the sender and the receiver. This includes the initial introduction between endpoints, finally closing a privacy leak that had persisted since the beginning of the protocol.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Online servers often use the same IP address to host a number of websites, such as in shared and virtual hosting services. Server Name Indication (SNI) is a previous TLS extension released in 2003 to fix <strong>common name mismatch errors<\/strong> caused by multiple websites using duplicate IP addresses. These used to result in browser error messages that read <em>Your connection is not private<\/em>. SNI allows the handshake process to specify a website\u2019s exact domain name in the certificate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SNI data is sent in what used to be an <strong>unencrypted <em>client hello<\/em> message<\/strong>, in which your browser initiates contact with a server, requesting its security certificate. Before this ECH update, the SNI data was not included in the encryption protocol. That meant eavesdroppers could see which servers and websites your network had requested access to. <strong>ECH prevents server name interception<\/strong> by using a public key to <strong>encrypt the entire payload, including the client hello<\/strong>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Using ECH in other browsers<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Encrypted Client Hello is currently <strong>in the process of being standardized for the final release<\/strong> to the wider browser ecosystem. You can also enable the experimental version in Firefox as well as the developer versions of various Chromium browsers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019re interested in keeping your web browsing as safe as possible, check out our list of the most <a href=\"https:\/\/en.softonic.com\/downloads\/secure-browser\" target=\"_blank\" rel=\"noreferrer noopener\">secure browsers for Windows and Android<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Most information you send or receive on today\u2019s internet passes through a layer of encryption to make sure it can only be read by the sender and receiver. This task is generally done via an automatic encryption key exchange through a cryptographic protocol in your browser. The current most popular key exchange protocol is a &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/how-to-make-ms-edge-safer-encrypted-client-hello\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;How to make MS Edge safer by turning on Encrypted Client Hello&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9244,"featured_media":199089,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[2441],"tags":[2379],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-199087","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-how-to","tag-app-subdomain-redirectionmicrosoft-edge"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/199087","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9244"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=199087"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/199087\/revisions"}],"predecessor-version":[{"id":323328,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/199087\/revisions\/323328"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/199089"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=199087"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=199087"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=199087"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=199087"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=199087"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=199087"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}