It took me a moment to find, but Alertly claims to do something similar while being open-source. Last commit was made two years ago though.
https://f-droid.org/packages/com.example.notificationalerter
What about this?
https://f-droid.org/packages/co.adityarajput.notifilter
Apparently that is part of implementing ECH (Encrypted Client Hello) in TLS 1.3 where the DNS hosts the public key of the server to fully encrypt the server name in a HTTPS request. Since Nginx and other popular web servers don't yet support it, I suspect the 7% of requests are mostly Cloudflare itself.
(1) https://radar.cloudflare.com/?ref=loworbitsecurity.com#dns-q...