You can't read HTTPS traffic — but you can still see exactly where it goes.

The short version

  • When everything ran over HTTP, a proxy log told you almost everything: user, timestamp, full URL, bytes transferred.
  • A practical monitoring stack for web and cloud-app visibility doesn't need to be elaborate.
  • The practical payoff is that shadow IT is hard to hide from DNS.

01What the HTTPS wall does (and doesn't) hide

When everything ran over HTTP, a proxy log told you almost everything: user, timestamp, full URL, bytes transferred. That's precisely what Red Line Software's Internet Access Monitor parsed — raw proxy logs turned into ranked tables of who visited what, how often, and how much bandwidth they consumed. Clean, comprehensive, done.

HTTPS encrypted the content and most of the URL. But here's the thing: it didn't encrypt the destination. Two signals survive the encryption wall and together they reconstruct a surprisingly complete picture of web and cloud-app usage.

The first is DNS. Before any device opens a connection to slack.com, drive.google.com, or some shadow-IT file-sharing tool, it asks your DNS resolver for the IP address. That lookup happens in the clear, and your DNS resolver logs it — timestamp, querying host, domain name requested. No decryption required. At scale, DNS logs are among the cheapest and most revealing usage data you can collect.

The second is SNI (Server Name Indication). When a browser or app opens a TLS connection, it sends the target hostname in the clear as part of the handshake — before encryption kicks in. A firewall or inline sensor reading SNI can see *.atlassian.net or dropbox.com without touching the encrypted payload. Combine SNI-derived hostnames with flow byte counts and you have destination and volume.

DNS query log or resolver dashboard showing ranked domain names
Resolver dashboard ranking queried domain names from highest to lowest frequency

02Building the usage picture

A practical monitoring stack for web and cloud-app visibility doesn't need to be elaborate. The key is layering the two signals — DNS for breadth, flows for depth.

DNS logging is the cheapest starting point. If your network already routes through Pi-hole, pfSense with Unbound, or a recursive resolver you control, query logging is usually one checkbox. In larger environments, Cisco Umbrella and NextDNS sit in the resolver path and maintain per-device, per-category query histories without any on-path decryption. You learn which SaaS categories are in use — video conferencing, code repositories, AI tools, personal cloud storage — purely from resolver telemetry.

Flow records add the volume dimension. NetFlow, sFlow, or IPFIX exported from your router or firewall feeds a collector — ntopng, ElastiFlow, or even a lightweight pfSense dashboard — and surfaces top-talker domains ranked by bytes. This is where you find out that one workstation is pushing gigabytes to a personal Google Drive, or that a newly adopted AI coding assistant is consuming an outsized share of the uplink. Flow data carries no payload; it's metadata about conversations, not their contents.

SNI-aware firewalls tie it together. OPNsense, pfSense with Suricata, and most enterprise next-generation firewalls can log the SNI field alongside connection byte counts, giving you a per-session record that closely resembles the old proxy log — minus the URL path, which stays encrypted, and the payload, which you neither need nor want for usage reporting.

For organisations that need to go further — governing which SaaS apps are actually authorised, not just seen — a Cloud Access Security Broker (CASB) like Netskope operates at a deeper level, identifying specific app instances and data movement. That's the right tool once you know shadow IT exists and want to act on it; DNS and flow monitoring is the right tool for discovering it cheaply in the first place.

03Shadow IT surfaces itself

The practical payoff is that shadow IT is hard to hide from DNS. Staff using unauthorised file-sharing, personal AI subscriptions, or unapproved collaboration tools will generate DNS queries regardless of the app's transport encryption. A weekly report sorted by domain category — pulled from your resolver logs and cross-referenced against your approved-software list — makes the gap between sanctioned and actual usage visible with no endpoint agents and no decryption.

This is, in essence, the same job Internet Access Monitor did with proxy logs in the early 2000s: turn raw records of outbound connections into an intelligible ranked report of where your network actually goes. The records changed — from HTTP proxy entries to DNS queries and SNI-tagged flow rows — but the purpose is identical. You need to know what your network is doing. In 2026, you still can.

Network flow dashboard showing top traffic destinations by bytes transferred
ntopng top-talkers view listing destination hosts ranked by bytes transferred
Side-by-side concept graphic: old proxy log entry vs. modern DNS+SNI+flow row
Old proxy log entry alongside a modern combined DNS, SNI, and flow record row

04Tools & references mentioned