Domain name evidence, forensics and litigation support
Pillar guide

Domain Evidence and Admissibility

Where domain records live, which of them are public, how they are authenticated, and what each one is incapable of showing

The problem this evidence presents

Domain evidence is unusual in three ways at once, and a matter that treats it as ordinary documentary evidence tends to fail on all three.

It is distributed. No single custodian holds the record. Registration data sits with a registrar and, for some top-level domains, is mirrored at the registry. Resolution history sits with sensor operators who are not parties. Content history sits with a third-party archive. Certificate history sits with independent log operators. Hosting and access records sit with a provider who may be in another jurisdiction.

It is volatile. Website content, DNS records and redirects change in minutes and leave nothing behind on the domain itself. Logs rotate on windows set by each provider.

And it is machine-produced, which means the foundation question is not "who wrote this" but "what system generated it and what does it actually measure". That is where most of the analytical work lives, and it is why an expert's description of a collection system is part of the evidentiary path rather than commentary on it.

Nothing on this page is legal advice; where procedure is involved, counsel decides.

The four layers, and why the layer matters

Every domain record belongs to a layer, and the layer determines who holds it, what it can prove, and whether legal process is required.

  • Registry. The operator of the top-level domain holds sponsorship, creation and expiry dates, status codes, and the transaction record behind delegation and transfer events. Zone files list the names actually delegated in the top-level domain.
  • Registrar. The sponsoring registrar holds the authoritative registration data and the account behind it — identity, payment instrument, correspondence, transfer documentation and, for a limited period, session logs. Everything public is a derived copy.
  • DNS. What the name resolved to — addresses, nameservers, mail servers — is authored at the DNS operator and observed by third-party sensors.
  • Everything below and beside. Hosting providers, content delivery networks, certificate authorities, web archives, marketplaces and advertising platforms.

The practical consequence is that a subpoena aimed at the wrong layer returns nothing useful. A registry cannot produce a hosting account. A regional internet registry can identify which network holds an address block and, by its own guidance, points downstream to the provider for anything about a customer.

What is publicly retrievable, and what is not

Retrievable without process: current registration data via RDAP, the structured JSON-based successor to WHOIS that ICANN has treated as the definitive source for generic top-level domain registration information since 28 January 2025; commercial historical registration databases; Certificate Transparency log entries; web archive captures and their capture indexes; passive DNS from sensor operators, commonly under contract; zone data through ICANN's zone-access service; regional internet registry allocation records; and public routing-collector archives showing which network announced an address block over time.

Requiring legal process or a policy channel: registrant identity behind redaction or a privacy service, registrar account and payment records, login and session logs, the Form of Authorization behind a transfer, DNS provider configuration change history, hosting access logs, content delivery network origin records, and marketplace or escrow transaction records.

Two channels sit between the categories. ICANN's Registration Data Request Service routes requests for nonpublic generic top-level domain registration data to participating registrars; participation is voluntary, ICANN has no role in the disclosure decision, and the service does not guarantee access. And in a filed UDRP, the registrar supplies full registration data to the provider within two business days of the verification request.

Authentication

This section is US-specific. The Federal Rules of Evidence are United States federal law; other jurisdictions and US state courts apply different rules, and administrative domain proceedings apply no formal rules of evidence at all.

Rule 901(a) requires evidence sufficient to support a finding that an item is what its proponent claims it is. Among the illustrations, 901(b)(9) contemplates evidence describing a process or system and showing that it produces an accurate result, and 901(b)(4) addresses distinctive characteristics taken together with all the circumstances — the illustration most obviously suited to correlation-type infrastructure evidence (FRE 901).

Rules 902(13) and 902(14), added by amendments effective 1 December 2017, provide self-authentication routes: a record generated by an electronic process or system that produces an accurate result, and data copied from an electronic device, storage medium or file authenticated by a process of digital identification. Both require certification by a qualified person and advance written notice. Custodian-produced registrar, registry and hosting records are ordinarily addressed as records of a regularly conducted activity, with the trustworthiness challenge available to the opponent. How any rule applies in a matter is for counsel.

Custody, hashing and the collection log

Chain of custody in a domain matter is a record of the examiner's own conduct, which is why it is the part of a report most directly exposed to challenge.

The published framework is stable. Collection is defined as identifying, labeling, recording and acquiring data while following procedures that preserve its integrity; verification means computing the digest of the original and the copy and comparing them; analysis is performed on copies, with the integrity of both verified (NIST SP 800-86). Collection notes are created contemporaneously and record the software used, the logs, the reports, the file names, the sizes and the hash values, with more than one hash algorithm recommended.

Two limits should be stated in any report that relies on this. A hash proves integrity since hashing and nothing earlier: it says nothing about whether the captured response was accurate when captured. And custody begins at collection, not at creation — for a produced registrar record, everything before the transmittal is outside the examiner's knowledge, and a report should not imply a chain that reaches further back than it does.

Volatility and the retention clocks

Rank the record by how quickly it can vanish, because that ranking is the collection order.

Minutes. DNS answers, live page content, redirect configuration. A redirect is configuration; removing it leaves no residue on the domain, and a redirect that was never captured is generally unrecoverable.

Weeks to months. Hosting, DNS provider and authentication logs, on windows each provider sets for itself. In the registrar context, the short-window category in ICANN's data-retention material covers log files, billing records and session data.

Months to years. Registrar records for the registration itself: at least fifteen months after sponsorship ends for the elements needed in transfer disputes, and an outer bound of two years after deletion or transfer away under the 2013 accreditation agreement. Retention floors are floors, and they have been waived registrar by registrar, so they are not uniform.

Longest. Registry records, certificate logs and third-party archives — the durable categories, and the ones least likely to contain identity.

Filing a UDRP does not change any of this. Its lock prevents modification of registrant and registrar information and expressly does not affect resolution of the domain.

Administrative proceedings apply no formal rules of evidence

This is routinely misunderstood in both directions.

In a UDRP the panel determines the admissibility, relevance, materiality and weight of the evidence, and decides on the basis of the statements and documents submitted. There is no discovery, no hearing and no cross-examination. Nothing is authenticated by the provider; the panel simply weighs what it receives. An annex whose method is unexplained is not excluded — it is discounted, silently.

So the authentication discipline still matters, for two reasons. The first is weight: a capture with a stated method, a timestamp and a hash is a different object from a screenshot. The second is re-use. The Policy expressly preserves court proceedings before an administrative proceeding is commenced or after it concludes, and an annex set frequently becomes a court exhibit later (UDRP, paragraph 4(k)). Material collected to administrative standards and then needed to evidentiary standards cannot be re-collected, because the live record has moved on.

Applying capture discipline at the administrative stage costs nothing extra. Not applying it costs the option.

What domain evidence cannot establish

Each source has a boundary, and the boundaries do not overlap in a way that closes the gaps.

Identity. Public registration data has been largely stripped of registrant fields since 2018, and redaction indicates a withheld value rather than an absent registrant. Registrar validation historically tested whether a contact point worked, not whether the named person existed.

Attribution of an action. A transfer record shows an authorization flow completed, not that the account owner performed it. An address in a log is not a person. Certificate logs show that control was demonstrated to a certificate authority, not by whom.

Negative facts. No archive capture does not mean no page. No passive DNS observation does not mean no resolution — sensor coverage depends on who contributed data and when, and a domain nobody looked up is a domain no sensor saw.

Precise timing. Observation windows bracket a change; caching widens the bracket.

Causation and volume. Referrer information is systematically reduced by browser defaults, analytics platforms suppress low-volume rows, and no record anywhere contains the counterfactual.

Where to start

In practice the order that avoids the most damage is: capture the public record today, identify the custodians and their retention windows in writing, then decide what to ask for.

Capturing first is not a substitute for process; it is what makes process worth serving. A production is far more useful when the requesting side already knows what the public record shows, what it does not show, and which specific categories the custodian is expected to hold, because a request framed in a custodian's own policy language returns a different set of documents than a request for "WHOIS records".

What is requested, from whom, and under what authority, is a matter for counsel. This site describes what records exist, where they sit, and what they are capable of proving.

I have worked in this field since 1996 and have provided expert witness reports in cases involving these records. hartzer.com is the actively maintained record of credentials and engagements.

Frequently Asked Questions

Is a WHOIS or RDAP lookup admissible on its own?

Admissibility is a question for the court applying its own rules, and nothing here predicts how any court would rule. What can be said generally is that a lookup preserved as a screenshot of a website is a weaker object than the raw response preserved with its exact query, the responding server, a retrieval timestamp with time zone, and a hash computed at capture. In United States federal practice, machine-produced records have certification routes available, and those routes assume the record was preserved as a record rather than as a picture.

What is the difference between a registry record and a registrar record?

The registry operator runs the master database for a top-level domain and holds sponsorship, creation and expiry dates, status codes, and the transaction history behind delegation and transfer events. The sponsoring registrar holds the registration data and the customer account behind it: identity, payment instrument, correspondence and transfer documentation. Public lookups are derived copies. Anything that names a person almost always sits at the registrar, which is why identifying the correct registrar of record is the first step in any production request.

Can records from a third-party archive be authenticated?

The retrieval can be documented: the capture URL including its timestamp, the archived response, the rendered copy and a hash of each preserved file. What an examiner cannot vouch for is the archive's internal handling — its crawl history, its exclusions and its processing lag are outside the examiner's knowledge. A report should draw that line explicitly and should also state the archive's own documented limitations, including crawl gaps, robots exclusions, and the fact that a displayed page is assembled from parts that may have been captured on different dates.

Do domain records need to come from the custodian to be useful?

Not always. A large amount of the technical record is public by design and can be collected directly — certificate logs, archive captures, routing archives, zone data, current registration data. Those are third-party records collected by the examiner, authenticated through the examiner's own process description. Custodian production is what adds identity, account activity and configuration history. Most domain reports mix both categories, and the report should mark which rows come from which, because they authenticate differently.

Does a UDRP lock preserve the evidence?

Only part of it, and less than most parties assume. The lock as defined prevents modification of the registrant and registrar information; it expressly does not affect resolution of the domain name or its renewal. Website content, DNS records and redirects remain changeable the day after the lock applies, and in practice a party who has just received notice is precisely the party most likely to change them. Capture before filing, not after.

Are these rules the same outside the United States?

No. The Federal Rules of Evidence material referenced on this site is United States federal law only, and US state courts operate under their own rules. The UDRP and URS are contractual mechanisms applying across generic top-level domains worldwide and apply no formal rules of evidence, leaving weight to the panel or examiner. Country-code top-level domains sit outside ICANN consensus policy entirely, with each registry setting its own publication, retention and disclosure practice.
Keep reading

The engagement types behind this guide

Every kind of analysis named here has its own entry: what it produces, what it is built from, and what has to be obtained under legal process.

A reference, not an intake page. This site describes what a domain name expert witness does and what the domain record can be made to show. It is not legal advice, nothing on it creates any relationship, and no engagement is taken through this website. The current record of credentials is at hartzer.com.

Top