Combining encrypted DNS and TLS 1.3 with encrypted handshakes, there's a reasonable cause for deniability which service you have accessed even if you can never hide the resolved IP address.
Even better would be to use ODoH(3), that way not even your local resolver can know who resolved what. Let's just hope TLS ECH and the rest takes off before the legislation against it.