No, the owner can sign the dns records and also sign the absence of a record, and if the censor tries to tell the browser that there is no SNI key, without being able to produce the signature to prove that, the browser can just treat this as an MITM attack. This only work on signed DNS entries though.
There is a difference between inciting end point devices to drop down to less secure protocols, and alerting the user that you are running an active attack.