Mullvad VPN and Wireshark SNI

Hello, After watching David Bombals video titled How your ISP tracks you (even with encrypted DNS) It got me wondering and curious to check my SNI to see if it was visible with my VPN. Now I’m not knowledgeable enough in networking to know all my results I’m looking at so I’m here to ask you guys why do I still see my domains visited when I filter using tls.handshake.extension.type == "server_name"

I enabled my Mullvad VPN on my PC and started the wire shark capture on the Mullvad connection and the attached image is what I saw visiting apple , Amazon, YouTube. Any comments appreciated. Thanks.

Isn’t this just Wireshark looking at the requests prior to going into the VPN tunnel?

With agentic AI, even you could will handle this task. I’d recommend flashing an x86 machine/an old router with openWRT and doing your test there. It’s easier to emulate ISP’s behavior and you won’t have to deal with setting up software for every device you own.

Regarding your Wireshark results - you’re capturing traffic from the wrong interface.