Why a domain matter turns on records nobody in the room can read
A domain name dispute is decided on a small set of records that are technical in form and perishable in nature. Registration data held by the sponsoring registrar. The registry's record of transfers, locks and status changes. What the name actually resolved to, month by month. What the website displayed on a date that matters. Which certificates were issued for the name and when. Where a visitor who typed the name was actually sent.
Two things make that record difficult, and they are different problems. The first is retrieval: most of it sits with third parties, some of it is public only in a redacted form, and all of it runs on retention clocks that expire quietly. The second is interpretation. A registration record's updated date does not mean the registrant changed. A passive DNS observation window is not the date a record was created. An archived page is evidence that content was retrievable by a crawler, not evidence of what a visitor saw. A domain name expert is retained because those two problems arrive together, and because a record that is misread in a filing is worse than a record that was never collected.
The two things an expert is actually retained for
Retrieval and authentication. Collecting the raw record rather than a screenshot of a lookup tool, capturing it in a way that a second examiner can evaluate, and being able to describe on the record how the collection system works and what it produces. In United States federal practice this is the material that Federal Rule of Evidence 901 addresses through evidence describing a process or system, and that Rules 902(13) and 902(14) address through certification (FRE 902). That framework is US-specific; other jurisdictions and US state courts apply their own rules.
An opinion tied to the forum's own test. Every proceeding asks a defined question, and the useful expert work is organized around that question rather than around the technology. A UDRP filing needs an indexed annex set mapped to the three elements. A US federal cybersquatting claim needs a date-anchored record aligned to statutory considerations. A theft claim needs a control timeline. The same underlying captures serve all of them; the organization does not transfer.
What an expert does not do is decide the legal question. Bad faith, likelihood of confusion, and the quantum of damages are for the panel, the court or the trier of fact. Counsel directs the matter.
What the work produces
The deliverables in a domain matter are unusually concrete, which is helpful when scoping an engagement:
- A dated timeline with one row per observed event and a source column for every row, separating the time an event occurred from the time it was observed.
- An annex or exhibit set of raw captures — registration data responses, DNS output, HTTP transcripts with headers, archived captures with their capture timestamps, certificate records — each hashed at collection.
- A schedule indexing the exhibits, which in a UDRP is a rule requirement rather than a courtesy.
- An attribution or linkage matrix, where the question is who stood behind a redacted registration, stating each link, its source, and its strength.
- A written report or declaration stating scope, sources, method, tools and versions, capture times, hash values, and the limits of each source.
- A chain-of-custody log and a data-needs analysis naming the records still outstanding and the custodian who holds each, so counsel can direct process at the right party.
Timing: the clocks that decide how much record still exists
The binding deadlines in a domain matter are usually not the litigation calendar. They are retention windows that run whether or not anyone has asked.
Under ICANN's Registration Data Policy, effective 21 August 2025, a registrar must retain the data elements needed for the Transfer Dispute Resolution Policy for no less than fifteen months after its sponsorship of the registration ends (ICANN Registration Data Policy). The 2013 Registrar Accreditation Agreement sets an outer bound of two years after a registration is deleted or transferred away, and the associated data-retention material treats log files, billing records and session data on a much shorter footing. Hosting and authentication logs — the records that would show how an account was actually accessed — are typically the first to age out, and their windows are set by each provider rather than by policy.
Two more clocks matter. A transfer dispute must be filed within twelve months of the alleged violation. And where a UDRP decision has issued, the registrar waits ten business days before implementing it. An expert brought in at that point is working inside a window measured in days.
Consulting, testifying, and what changes between them
A consulting engagement and a testifying engagement produce different documents, and the difference is worth settling at the outset rather than mid-matter.
A consulting role is usually about scope and direction: what records exist, who holds them, what a subpoena should name, what is already gone, and whether the technical theory a filing depends on is supportable by anything retrievable. That work often prevents a request from being served on the wrong custodian, or a claim from resting on an archive capture that does not say what it appears to say.
A testifying role adds the report and the exposure that goes with it. Everything relied on becomes discoverable, the method becomes the subject of examination, and the parts of the analysis that were left implicit get tested. In my experience the section that most often decides how a technical opinion is received is not the conclusion but the limits: an expert who has already stated what the passive DNS coverage does not reach, or where the archive has no captures, is describing a known feature of the data rather than conceding a surprise.
Whether the same person can move from one role to the other, and on what terms, is a question for counsel.
How an engagement is structured
Structurally, and in the order these things usually happen:
- Conflict check. The domains, the parties and the related entities, before any substantive material is exchanged.
- Scope. The question to be answered, the forum it is being answered for, and the boundary of the opinion — written down, because scope creep in a technical report is what produces an opinion nobody can defend.
- Materials. The domains and date ranges at issue, the filings or the draft claim, anything already captured by the client, and any productions already received.
- Preservation. Immediate capture of what is publicly available, and a written list of custodians and their retention windows so counsel can decide what to serve and when.
- Analysis and report. The timeline or matrix, the exhibit set, the method statement and the limits.
- Deposition and testimony availability, where the matter reaches that stage.
Fees, rates and turnaround are settled directly with counsel and are not published here.
What this evidence cannot establish
Every category of domain evidence has a specific, technical boundary, and the boundaries are not interchangeable.
Registration data. Since 2018 most registrant identity fields are redacted from public output. A redacted field means the value is withheld, not that no registrant exists — and a name on a record was never verified as belonging to a real person, only as a working contact point.
Passive DNS (a historical database of DNS answers that sensors happened to observe, rather than a live query) proves that a resolution was seen. It cannot prove a record never existed, and its first and last observation times bracket a change rather than dating it.
Web archives have crawl gaps, robots exclusions, and captures whose embedded images and scripts come from other dates. A missing capture is not evidence a page was absent.
Certificate Transparency logs (public, append-only records of issued TLS certificates) show that control was demonstrated to a certificate authority on a date. They do not name who demonstrated it.
Traffic records contain no counterfactual. No log anywhere records where a visitor would otherwise have gone. And an IP address in a log is not a person.
Where the current record of engagements lives
I have worked in the domain name industry since 1996. I have testified in domain-related legal cases and have provided expert witness reports in other cases.
This site describes the practice: what the work involves, what evidence it produces, what that evidence cannot do, and what a retaining attorney should expect procedurally. It deliberately does not maintain an engagement list. A list of that kind is either incomplete or out of date, and on a reference site it is worse than useless because a reader cannot tell which. hartzer.com is the actively maintained record of credentials and engagements, and that is where a retaining attorney should look for the current position.
Nothing on this site is legal advice, and nothing here characterizes any reader's position or predicts how any court or panel would decide anything. Where a matter touches procedure, counsel is required.