Earlier quoted context omitted.
Absolutely not. Full MITM proxies are required to inspect traffic. Inspecting SNI is ineffective against the majority of threats including blocking botnet traffic.
How so? If I as the MITM (non-decrypting) proxy intercept the request, look at the SNI to ensure it’s on my whitelist, and then do my own DNS lookup and open my own TCP connection to that IP and relay the traffic between the two, what’s the attack vector?
Also, botnets uses legitimate services to rely C&C traffic. Forums, pastebins, github gits, IRC and email gateways, VMs on AWS and other cloud services...