One of the hazards of is that a deployment could end up leaking as much information as a non-ECH TLS connection if the ECH Config in DNS is only associated with a given domain.

