@smallcircles @benpate I studied this last year, and @mallory worked on RFC 9505.
https://datatracker.ietf.org/doc/rfc9505/
I think the hardware requirements for doing deep packet stuff are hard but not impossible. Don't forget, we use HTTPS.
If it were me, I'd download a list of the top 1000 fediverse servers from fedidb and block their DNS names and IP addresses. That'd probably cover 99% of user accounts.