Forensic Investigation

Domain Ownership & Forensic Investigation

WHOIS/RDAP history, chain-of-custody reconstruction, registrant attribution, and stolen or hijacked domain investigations.

Reconstructing Who Owned What, and When

Most domain disputes eventually come down to a single question: who controlled this domain at the time in question, and how did that control change? Answering it requires reconstructing registrant history from WHOIS/RDAP snapshots, registrar transaction logs where available, and corroborating sources including zone files, web archives, and security-feed data, then documenting every transfer, registrar push, expiration cycle, and drop-catch sequence in a defensible, dated sequence.

Chain-of-Custody Analysis

Chain-of-custody work in a domain matter is analogous to chain-of-custody work with any other piece of evidence: it establishes an unbroken, sourced record of who held the asset at each point in time. This matters most in disputes involving alleged theft, fraud, unauthorized transfer, or a contested business relationship, where the outcome often turns on precisely when control changed hands and whether that change was authorized.

Registrant Attribution & Privacy/Proxy Records

Modern WHOIS/RDAP privacy practices mean the underlying registrant is frequently redacted behind a privacy or proxy service. Attribution in these cases relies on triangulation — historical WHOIS predating redaction, hosting and IP infrastructure patterns, advertising and analytics IDs embedded in site code, and connections to other domains registered by the same party.

Deliverables

  • Sourced registrant and ownership timelines
  • Chain-of-custody reports for transfer and theft disputes
  • Registrant attribution analysis behind privacy/proxy redaction
  • Related-domain and related-asset identification
Go Deeper

Related In-Depth Topics

Each of the areas below has its own dedicated page covering methodology, typical evidence, and deliverables in more detail.

Need an Ownership History Reconstructed?