The problem this evidence presents
Domain evidence is unusual in three ways at once, and a matter that treats it as ordinary documentary evidence tends to fail on all three.
It is distributed. No single custodian holds the record. Registration data sits with a registrar and, for some top-level domains, is mirrored at the registry. Resolution history sits with sensor operators who are not parties. Content history sits with a third-party archive. Certificate history sits with independent log operators. Hosting and access records sit with a provider who may be in another jurisdiction.
It is volatile. Website content, DNS records and redirects change in minutes and leave nothing behind on the domain itself. Logs rotate on windows set by each provider.
And it is machine-produced, which means the foundation question is not "who wrote this" but "what system generated it and what does it actually measure". That is where most of the analytical work lives, and it is why an expert's description of a collection system is part of the evidentiary path rather than commentary on it.
Nothing on this page is legal advice; where procedure is involved, counsel decides.
The four layers, and why the layer matters
Every domain record belongs to a layer, and the layer determines who holds it, what it can prove, and whether legal process is required.
- Registry. The operator of the top-level domain holds sponsorship, creation and expiry dates, status codes, and the transaction record behind delegation and transfer events. Zone files list the names actually delegated in the top-level domain.
- Registrar. The sponsoring registrar holds the authoritative registration data and the account behind it — identity, payment instrument, correspondence, transfer documentation and, for a limited period, session logs. Everything public is a derived copy.
- DNS. What the name resolved to — addresses, nameservers, mail servers — is authored at the DNS operator and observed by third-party sensors.
- Everything below and beside. Hosting providers, content delivery networks, certificate authorities, web archives, marketplaces and advertising platforms.
The practical consequence is that a subpoena aimed at the wrong layer returns nothing useful. A registry cannot produce a hosting account. A regional internet registry can identify which network holds an address block and, by its own guidance, points downstream to the provider for anything about a customer.
What is publicly retrievable, and what is not
Retrievable without process: current registration data via RDAP, the structured JSON-based successor to WHOIS that ICANN has treated as the definitive source for generic top-level domain registration information since 28 January 2025; commercial historical registration databases; Certificate Transparency log entries; web archive captures and their capture indexes; passive DNS from sensor operators, commonly under contract; zone data through ICANN's zone-access service; regional internet registry allocation records; and public routing-collector archives showing which network announced an address block over time.
Requiring legal process or a policy channel: registrant identity behind redaction or a privacy service, registrar account and payment records, login and session logs, the Form of Authorization behind a transfer, DNS provider configuration change history, hosting access logs, content delivery network origin records, and marketplace or escrow transaction records.
Two channels sit between the categories. ICANN's Registration Data Request Service routes requests for nonpublic generic top-level domain registration data to participating registrars; participation is voluntary, ICANN has no role in the disclosure decision, and the service does not guarantee access. And in a filed UDRP, the registrar supplies full registration data to the provider within two business days of the verification request.
Authentication
This section is US-specific. The Federal Rules of Evidence are United States federal law; other jurisdictions and US state courts apply different rules, and administrative domain proceedings apply no formal rules of evidence at all.
Rule 901(a) requires evidence sufficient to support a finding that an item is what its proponent claims it is. Among the illustrations, 901(b)(9) contemplates evidence describing a process or system and showing that it produces an accurate result, and 901(b)(4) addresses distinctive characteristics taken together with all the circumstances — the illustration most obviously suited to correlation-type infrastructure evidence (FRE 901).
Rules 902(13) and 902(14), added by amendments effective 1 December 2017, provide self-authentication routes: a record generated by an electronic process or system that produces an accurate result, and data copied from an electronic device, storage medium or file authenticated by a process of digital identification. Both require certification by a qualified person and advance written notice. Custodian-produced registrar, registry and hosting records are ordinarily addressed as records of a regularly conducted activity, with the trustworthiness challenge available to the opponent. How any rule applies in a matter is for counsel.
Custody, hashing and the collection log
Chain of custody in a domain matter is a record of the examiner's own conduct, which is why it is the part of a report most directly exposed to challenge.
The published framework is stable. Collection is defined as identifying, labeling, recording and acquiring data while following procedures that preserve its integrity; verification means computing the digest of the original and the copy and comparing them; analysis is performed on copies, with the integrity of both verified (NIST SP 800-86). Collection notes are created contemporaneously and record the software used, the logs, the reports, the file names, the sizes and the hash values, with more than one hash algorithm recommended.
Two limits should be stated in any report that relies on this. A hash proves integrity since hashing and nothing earlier: it says nothing about whether the captured response was accurate when captured. And custody begins at collection, not at creation — for a produced registrar record, everything before the transmittal is outside the examiner's knowledge, and a report should not imply a chain that reaches further back than it does.
Volatility and the retention clocks
Rank the record by how quickly it can vanish, because that ranking is the collection order.
Minutes. DNS answers, live page content, redirect configuration. A redirect is configuration; removing it leaves no residue on the domain, and a redirect that was never captured is generally unrecoverable.
Weeks to months. Hosting, DNS provider and authentication logs, on windows each provider sets for itself. In the registrar context, the short-window category in ICANN's data-retention material covers log files, billing records and session data.
Months to years. Registrar records for the registration itself: at least fifteen months after sponsorship ends for the elements needed in transfer disputes, and an outer bound of two years after deletion or transfer away under the 2013 accreditation agreement. Retention floors are floors, and they have been waived registrar by registrar, so they are not uniform.
Longest. Registry records, certificate logs and third-party archives — the durable categories, and the ones least likely to contain identity.
Filing a UDRP does not change any of this. Its lock prevents modification of registrant and registrar information and expressly does not affect resolution of the domain.
Administrative proceedings apply no formal rules of evidence
This is routinely misunderstood in both directions.
In a UDRP the panel determines the admissibility, relevance, materiality and weight of the evidence, and decides on the basis of the statements and documents submitted. There is no discovery, no hearing and no cross-examination. Nothing is authenticated by the provider; the panel simply weighs what it receives. An annex whose method is unexplained is not excluded — it is discounted, silently.
So the authentication discipline still matters, for two reasons. The first is weight: a capture with a stated method, a timestamp and a hash is a different object from a screenshot. The second is re-use. The Policy expressly preserves court proceedings before an administrative proceeding is commenced or after it concludes, and an annex set frequently becomes a court exhibit later (UDRP, paragraph 4(k)). Material collected to administrative standards and then needed to evidentiary standards cannot be re-collected, because the live record has moved on.
Applying capture discipline at the administrative stage costs nothing extra. Not applying it costs the option.
What domain evidence cannot establish
Each source has a boundary, and the boundaries do not overlap in a way that closes the gaps.
Identity. Public registration data has been largely stripped of registrant fields since 2018, and redaction indicates a withheld value rather than an absent registrant. Registrar validation historically tested whether a contact point worked, not whether the named person existed.
Attribution of an action. A transfer record shows an authorization flow completed, not that the account owner performed it. An address in a log is not a person. Certificate logs show that control was demonstrated to a certificate authority, not by whom.
Negative facts. No archive capture does not mean no page. No passive DNS observation does not mean no resolution — sensor coverage depends on who contributed data and when, and a domain nobody looked up is a domain no sensor saw.
Precise timing. Observation windows bracket a change; caching widens the bracket.
Causation and volume. Referrer information is systematically reduced by browser defaults, analytics platforms suppress low-volume rows, and no record anywhere contains the counterfactual.
Where to start
In practice the order that avoids the most damage is: capture the public record today, identify the custodians and their retention windows in writing, then decide what to ask for.
Capturing first is not a substitute for process; it is what makes process worth serving. A production is far more useful when the requesting side already knows what the public record shows, what it does not show, and which specific categories the custodian is expected to hold, because a request framed in a custodian's own policy language returns a different set of documents than a request for "WHOIS records".
What is requested, from whom, and under what authority, is a matter for counsel. This site describes what records exist, where they sit, and what they are capable of proving.
I have worked in this field since 1996 and have provided expert witness reports in cases involving these records. hartzer.com is the actively maintained record of credentials and engagements.