Data Collection
Sources typically include WHOIS/RDAP records, registrar and registry correspondence and logs, DNS zone files and passive DNS, name server and MX histories, SSL/TLS certificate transparency logs, hosting and CDN footprints, domain marketplace records, escrow artifacts, and web archives and screenshots. Timestamps and time zones are aligned across sources before any comparison is drawn between them — a step that is frequently skipped and that frequently changes the conclusion.
Verification
Ownership signals are cross-checked across independent sources rather than accepted from a single record. Screenshot authenticity and capture dates are validated, and privacy/proxy registration records are reconciled with underlying registrant data when it becomes available through discovery or registrar disclosure. Gaps and limitations in the record are documented explicitly rather than papered over.
Analysis
The domain’s timeline is reconstructed, intent and use are evaluated against that timeline, related assets are identified, and likelihood of confusion is assessed where relevant. A key part of this step is distinguishing natural churn — expirations, drops, routine renewals — from intentional acquisition and use patterns that support an inference of bad faith.
Conclusions
Findings are presented in plain language with cited exhibits, stating clearly what the record supports and what it does not. Demonstratives such as annotated timelines, DNS change maps, and ownership charts are prepared to make technical findings accessible to judges, juries, and arbitration panels without a technical background.
Why Methodology Matters More Than Conclusions
An expert opinion is only as strong as the record it stands on. Because every step above is documented and sourced, opposing counsel can test the reasoning directly rather than attacking the expert’s credibility in the abstract — which is a better outcome for every party, including the court.