Reconstructing Who Owned What, and When
Most domain disputes eventually come down to a single question: who controlled this domain at the time in question, and how did that control change? Answering it requires reconstructing registrant history from WHOIS/RDAP snapshots, registrar transaction logs where available, and corroborating sources including zone files, web archives, and security-feed data, then documenting every transfer, registrar push, expiration cycle, and drop-catch sequence in a defensible, dated sequence.
Chain-of-Custody Analysis
Chain-of-custody work in a domain matter is analogous to chain-of-custody work with any other piece of evidence: it establishes an unbroken, sourced record of who held the asset at each point in time. This matters most in disputes involving alleged theft, fraud, unauthorized transfer, or a contested business relationship, where the outcome often turns on precisely when control changed hands and whether that change was authorized.
Registrant Attribution & Privacy/Proxy Records
Modern WHOIS/RDAP privacy practices mean the underlying registrant is frequently redacted behind a privacy or proxy service. Attribution in these cases relies on triangulation — historical WHOIS predating redaction, hosting and IP infrastructure patterns, advertising and analytics IDs embedded in site code, and connections to other domains registered by the same party.
Deliverables
- Sourced registrant and ownership timelines
- Chain-of-custody reports for transfer and theft disputes
- Registrant attribution analysis behind privacy/proxy redaction
- Related-domain and related-asset identification
Related In-Depth Topics
Each of the areas below has its own dedicated page covering methodology, typical evidence, and deliverables in more detail.