Domain name evidence, forensics and litigation support
Retaining a Domain Name Expert Witness

What a Domain Name Expert Witness Does

The actual tasks: retrieval, capture, authentication, timeline construction, and an opinion that stops where the records stop

The short answer

A domain name expert converts a scattered, perishable technical record into something a proceeding can use, and then says what that record does and does not show.

That covers four distinct tasks, and they are worth separating because they carry different risks. Retrieval — finding the records, in the right form, from the right custodian, before they age out. Capture — preserving each one so its integrity can be demonstrated later. Authentication — being able to describe the system that produced the record and what it measures. Analysis — assembling the records into a chronology, a matrix or a comparison that answers the question the forum actually asks.

None of those four tasks includes deciding the legal question. That distinction is not a formality: an expert who characterizes a registrant's motive, or states that a mark is famous, or concludes that conduct constitutes bad faith, has moved outside the records and made the rest of the report easier to attack. Counsel is required on every procedural question this page describes.

Retrieval: the public record, and what has gone missing from it

A great deal is publicly retrievable, and the first day of an engagement is usually spent collecting it while it still exists.

Current registration data comes from RDAP — the structured, machine-readable successor to WHOIS, which since 28 January 2025 ICANN treats as the definitive source for generic top-level domain registration information. Historical registration data is assembled rather than queried: there is no official archive, so a history is stacked from dated observations, commercial history databases and, where legal process is available, the registrar's own records.

Resolution history comes from passive DNS. Certificate history comes from Certificate Transparency logs. Content history comes from web archives. Network and hosting facts come from the regional internet registries and from public routing-collector archives.

What is largely gone from the public record is identity. Since the 2018 registration-data changes, most registrant contact fields are redacted in public output, with the redaction signaled rather than hidden. The practical consequence for an engagement is that public collection establishes what happened in considerable detail and establishes who only rarely.

Retrieval: the records that require legal process

The records that name a person are held by custodians and reach a file through process, a policy channel, or a proceeding's own verification step.

  • The registrar holds the account file: registrant identity behind a privacy or proxy service, the registration data submitted at application, transfer documentation including the Form of Authorization, payment instruments, correspondence, and — for a limited period — session and log data.
  • The registry operator holds the transaction record behind delegation, status and transfer events.
  • The hosting or DNS provider holds configuration change history and the access logs that tie a change to an account.
  • Marketplaces and escrow agents hold the only primary records of a completed sale.

There are two channels that are frequently misunderstood. ICANN's Registration Data Request Service routes requests for nonpublic registration data to participating registrars, but participation is voluntary, ICANN plays no part in the disclosure decision, and the service guarantees nothing. And in a UDRP, the registrar's verification response supplies full registration data to the provider within two business days of the request — a disclosure route that exists only because a case was filed.

Capture and custody

Capture is where most domain evidence is lost, and it is lost in an ordinary way: someone screenshots a lookup site instead of preserving what the server actually returned.

The practice that survives examination is narrow and repeatable. Preserve the raw response — the RDAP JSON, the port-43 text, the DNS output including which resolver answered, the full HTTP transcript with headers rather than the rendered page. Record the exact query, the responding server, and a retrieval timestamp with its time zone. Hash each file at the moment of capture, under more than one algorithm, and record the hashes in a manifest that travels with the set.

Then stop touching it. The published guidance is unambiguous on this point: work from copies and verify the integrity of both the original and the copy (NIST SP 800-86). Keep the collection log contemporaneously rather than reconstructing it later, and record the failures as carefully as the successes — the capture that would not reproduce, the page that returned differently from a second location, the request a custodian refused.

Authentication

Authentication is a foundation question rather than a technical one, and in United States federal practice it runs through a defined set of provisions. This section is US-specific.

Rule 901(a) requires evidence sufficient to support a finding that an item is what its proponent claims it is, and Rule 901(b)(9) contemplates evidence describing a process or system and showing that it produces an accurate result (FRE 901). That illustration is why an expert's description of how passive DNS collection works, or how a certificate log's append-only structure operates, is part of the evidentiary path rather than background.

Rules 902(13) and 902(14), added by amendments effective 1 December 2017, provide self-authentication routes for a record generated by an electronic process or system and for data copied from an electronic device or file authenticated by a process of digital identification — the language that makes a hash record a working part of the foundation. Both require a qualified person's certification and advance written notice. Custodian-produced registrar and hosting records are ordinarily addressed as records of a regularly conducted activity. How any of this applies in a particular matter is for counsel.

Analysis: the four deliverable shapes

Domain analysis takes a small number of recurring forms, and choosing the right one is most of the work.

The timeline. One row per observed state change — registration, transfer, contact change, nameserver change, status-code change, certificate issuance, content change — with the custodian, the event time, the observation time and the artifact hash. Used wherever a date is load-bearing, which in domain matters is nearly always.

The attribution matrix. One row per candidate link between a name and an operator, each with its source, observation date and stated strength, and each carrying its innocent alternative explanation. Shared hosting, shared nameservers and shared analytics accounts are links, not identifications.

The comparison. A string-against-mark analysis isolating the second-level label, showing the edit operations, and rendering confusable characters visually with their codepoints, because a homoglyph is unreadable as plain text in a report.

The factor or element matrix. One row per element the forum's own test enumerates, with the records located, the records not located, and an explicit "no records found" entry where that is the answer.

What the expert does not do

The boundary is easier to hold if it is stated in the report rather than defended in a deposition.

An expert does not opine on the ultimate legal question. Bad faith intent to profit is a determination reserved to the court; whether a domain name is confusingly similar for the purposes of a proceeding is for the panel; likelihood of confusion in a marketplace is a multifactor legal inquiry that a string comparison contributes to and does not answer.

An expert does not characterize a party's state of mind. Records show what happened and when; they do not show why, and an inference about motive dressed as a technical finding is the most common way a defensible report becomes an indefensible one.

An expert does not choose the forum, predict a result, or advise a party what to file. And an expert does not value a name from an automated appraisal tool. Those tools produce an algorithmic estimate from an undisclosed model on incomplete sales data, and they are not reproducible over time. Reported as a dated third-party data point they are fine. As an opinion of value they are not one.

What this evidence cannot establish

Stating the limits is part of the deliverable, not a caveat attached to it.

Identity. Post-2018 redaction removed most registrant fields from public output, and the underlying data was never identity-verified in the first place — registrar validation tests whether a contact point works, not whether the named person exists.

Timing precision. Passive DNS brackets a change between the last observation of the old value and the first observation of the new one; caching and sensor coverage set the width of that bracket. A registration record's update timestamp reflects a database update, which may have nothing to do with a change of registrant.

Completeness. Web archive coverage depends on what crawlers found, what robots.txt allowed, and what a site owner asked to have excluded; captures can also become unavailable later. Certificate Transparency has partial coverage before 2018.

Causation and volume. Referrer data is systematically stripped by modern browser defaults, so referrer-derived counts are floors of unknown depth, and analytics platforms suppress exactly the low-volume rows a single disputed domain generates.

Frequently Asked Questions

Can a domain name expert tell me who registered a redacted domain?

Not from public records alone, in most cases. Redaction withholds the registrant fields from published output, and the underlying identity sits with the registrar. What public analysis produces is a linkage matrix — shared nameservers, shared hosting, shared analytics or advertising identifiers recovered from archived page source, pre-2018 registration observations of the same or sibling domains — with each link's strength and its innocent explanation stated. Naming a person generally requires registrar records obtained through legal process, a disclosure channel, or a proceeding's own verification step.

Is a screenshot enough to prove what a website showed?

A screenshot with no URL, no timestamp, no time zone and no capture method is weak on its own, because nothing about it can be verified independently. The stronger form is the full HTTP response with headers, the page source, a rendered copy, a hash of each file computed at capture, and a contemporaneous log recording the tool and version used. Where the question is historical, an archived capture with its capture timestamp adds a third-party record, subject to the archive's own documented gaps.

Does the expert decide whether a domain was registered in bad faith?

No. Bad faith is a legal determination made by the panel or the court. An expert identifies, retrieves, authenticates and explains the records that bear on the question a forum's test poses — registration dates against mark dates, redirect chains, monetization identifiers, portfolio linkage — and states the limits of each. A report that scores factors or announces that conduct was in bad faith has crossed from evidence into argument.

What does an expert need from counsel to start?

The domains and the date ranges at issue, the forum the question is being asked in, the filings or the draft claim, anything the client has already captured, and any productions already received. A conflict check comes first, and scope is agreed in writing before substantive work begins. If preservation has not started, that is generally the first task, because the shortest retention windows run regardless of what else is happening in the matter.

Are automated domain appraisals useful in litigation?

As an opinion of value, no. The model is proprietary, so the method cannot be stated or tested; the training data inherits the coverage gaps of the public sales record, in which private transactions are absent by definition; the output is not reproducible over time; and the tool cannot see encumbrance, traffic, revenue or the valuation date. An automated estimate can properly appear in a report as a dated third-party data point with its stated basis. It cannot be the conclusion.

How does an expert handle records produced by the other side?

Produced records enter custody on receipt: the transmittal, the receipt timestamp, and a hash of each file as received are logged alongside self-collected captures. The analysis then usually includes a completeness assessment — what policy and the custodian's own obligations indicate should exist, what was produced, and what was not. What happened to a record inside a custodian's systems before production is outside an examiner's knowledge, and a report should say so rather than imply otherwise.
Keep reading

The engagement types behind this guide

Every kind of analysis named here has its own entry: what it produces, what it is built from, and what has to be obtained under legal process.

A reference, not an intake page. This site describes what a domain name expert witness does and what the domain record can be made to show. It is not legal advice, nothing on it creates any relationship, and no engagement is taken through this website. The current record of credentials is at hartzer.com.

Top