Although the security benefits of domain name encryption technologies such as\nDNS over TLS (DoT), DNS over HTTPS (DoH), and Encrypted Client Hello (ECH) are\nclear, their positive impact on user privacy is weakened by--the still\nexposed--IP address information. However, content delivery networks, DNS-based\nload balancing, co-hosting of different websites on the same server, and IP\naddress churn, all contribute towards making domain-IP mappings unstable, and\nprevent straightforward IP-based browsing tracking.\n In this paper, we show that this instability is not a roadblock (assuming a\nuniversal DoT/DoH and ECH deployment), by introducing an IP-based website\nfingerprinting technique that allows a network-level observer to identify at\nscale the website a user visits. Our technique exploits the complex structure\nof most websites, which load resources from several domains besides their\nprimary one. Using the generated fingerprints of more than 200K websites\nstudied, we could successfully identify 84% of them when observing solely\ndestination IP addresses. The accuracy rate increases to 92% for popular\nwebsites, and 95% for popular and sensitive websites. We also evaluated the\nrobustness of the generated fingerprints over time, and demonstrate that they\nare still effective at successfully identifying about 70% of the tested\nwebsites after two months. We conclude by discussing strategies for website\nowners and hosting providers towards hindering IP-based website fingerprinting\nand maximizing the privacy benefits offered by DoT/DoH and ECH.\n