multiparty ratchet encryption is called MLS
it's always better to not send out a signal than to encrypt it over an untrusted line, this is one of the purposes of the outbox (rendezvous) model, but it, like MLS, will require client support for it, that's where all the logic is