From what I understand, HTTPS sites that don’t enable OCSP stapling will force the visitors to visit the OCSP servers to check if the certificate is valid/revoked.
I’ve tested quite a few HTTPS sites that don’t have OCSP stapling enabled on webpagetests but none of the runs shows a ocsp connection.
Is this intentional?