Every entry in this category describes a kind of examination performed on the record a domain name leaves behind. Not a tool, and not a checklist: a defined body of work, described by what it retrieves, where that material is held, how it is preserved so it survives a challenge, and — the part usually left out — what it cannot establish standing alone. A registration record shows what a database said on a date. It does not show who typed it. Keeping those two statements apart is most of the discipline.
Why these are grouped by where the record lives
The obvious way to organize forensic material is by tool, and it is close to useless. Tools change, providers come and go, and an index built around them is stale before it is finished. What does not change is the question a retaining attorney actually has: where is this material held, who controls it, is it public, and if it is not, what has to be served on whom to get it. That is the axis these entries are grouped on.
Three disciplines cover this category. Registration and historical records covers the registration database itself and the copies of it that survive elsewhere — historical registration data, resolution history, archived pages, certificate issuance logs — along with the procedural work of getting records out of a registrar and keeping what has been collected intact. Hosting and infrastructure covers what a name resolved to and where its traffic went: the servers, the networks and the redirect chains. Attribution and ownership covers the inference built on top of all of it — who controlled the name, and when — which is never a lookup and is always an argument from converging records.
The field at the top of every entry
Each entry opens with one word before any prose: documentary, analytical or procedural. That is the answer-first field for this site, and it is the single most useful thing to know before reading further, because it decides what the output of the work will be and how it will be challenged.
Documentary means the work retrieves records that exist independently of the matter and would exist whether or not anyone had gone looking. Registration history, resolution history, archived captures, certificate logs. The examiner's job is retrieval, preservation and faithful presentation, and the challenge to it is almost always about authentication and completeness rather than about opinion. Analytical means the output is an opinion built on records: an attribution, a valuation, a similarity assessment. The records underneath are documentary; the reasoning on top of them is not, and it has to be stated with its method, its assumptions and its confidence in the open. Procedural means the work is defined by rules external to the examiner — a chain of custody, a production made under legal process, a preservation exercise governed by the standards that apply to digital evidence. The output is a process record, and its value comes from having been done in the right order, contemporaneously.
The same field appears as a chip on every card in this index, so the whole category can be scanned before anything is opened. One field driving three surfaces is what keeps it honest — a label that appeared in only one place would drift.
What the strip under each heading records
Directly beneath the heading of every entry is a strip carrying four values: what the work produces, the sources it draws on, how those sources are obtained, and the authority the other three were read from.
Produces is stated as an artifact, not as an activity — a dated chronology, a preserved capture set, a comparison table, a custody file. An engagement that cannot name its artifact is an engagement without a deliverable. Sources names the repositories that artifact is built from, in the order they matter. How it is obtained is the field that decides scheduling: some of this material is publicly retrievable within the hour, and some of it exists only inside a registrar, a hosting provider or a certificate authority and arrives, if at all, under a subpoena or a preservation demand. Confusing the two is how a matter discovers in month four that the record it needed had a retention floor measured in months. Authority cites the policy, standard or rule the description rests on, so the other three fields can be checked rather than taken on trust.
What these entries will not do
They do not name a case, a court, a docket, a party, a panel or a law firm, and that includes matters of public record. They do not describe any engagement. They carry no counts of matters and no outcome claims, because a technical examination that is presented as a way to win is no longer a technical examination.
They also do not give legal advice. Several of these entries touch on how records are authenticated and what a proceeding will accept, and every one of them is written on the assumption that counsel is directing the matter and making the calls that belong to counsel — whether to proceed by certification or by custodian testimony, what to serve and on whom, and what the record is being offered to prove.
The limits section is not a disclaimer
Every entry carries a section on what its evidence does not establish, and that section is load-bearing rather than defensive. Registration data identifies an account, not a person. Resolution history shows what a name answered with, not who changed it. An archived capture shows what a crawler retrieved, not what every visitor saw. Certificate logs show that a certificate was issued for a name, not who controlled the server it was installed on.
Stating those limits plainly is what makes the rest of the analysis usable. An examination presented without them invites a cross-examination that consists entirely of discovering them one at a time, in front of the tribunal, from the other side's expert.
How to read this index
If a matter is already running, start from the field on the card and find the entry that matches the question being asked, then follow it into the evidence guides rather than reading sideways across the category. Preservation comes before everything, including scoping, because the live record does not wait.
If the goal is to understand the field rather than to solve a problem, the disciplines are the better order: registration and historical records first, because everything else is measured against them, then hosting and infrastructure, then attribution, which is a different kind of reasoning wearing the same vocabulary. Each entry cross-links to the litigation-support work it feeds, because a forensic finding that never reaches a forum in a usable shape is only half the job.