The deliverable is a dated chronology
Paragraph 4(c) of the Policy lists circumstances that demonstrate rights or legitimate interests in a domain name, and the list is open-ended. Read them closely and something becomes obvious: each one is a question about dates and documents, not about characterization.
Use of the name, or demonstrable preparations to use it, in connection with a bona fide offering of goods or services before any notice of the dispute. Being commonly known by the name, even without any trademark rights. Legitimate noncommercial or fair use without intent for commercial gain to misleadingly divert consumers (ICANN UDRP). Every one of those turns on what existed at a date certain and what record proves it.
So the expert's product on this side is a records-anchored chronology rather than a narrative: registry creation and transfer events, historical registration records, DNS and MX history, hosting records, certificate issuance entries, archived captures — each row sourced to something retrievable, with the retrieval date stated. Rows that rest solely on documents the holder produced are marked as such. That distinction matters more than it looks, and stating it up front is what keeps the rest of the chronology credible.
What arguments are made from that chronology, and whether a response is filed at all, is counsel's decision. This describes the record, not a position.
Twenty days is the entire investigation
The response is due twenty days from commencement — the date the provider formally starts the case. A respondent may expressly request four additional calendar days, and the provider must grant that automatically. In exceptional cases the provider may extend the period further under Rule 5(e) (UDRP Rules).
That is the whole evidence-gathering window. It is not a filing deadline with an investigation phase in front of it; the notice and the clock arrive together. Third-party records that require someone else's cooperation — a former hosting provider, a marketplace, a parking service — often take longer than twenty days to produce, and the request has to go out on day one or not at all.
The compression has a practical consequence that catches holders repeatedly. The most valuable records in a UDRP response are usually the ones the holder already has and has not looked for: an acquisition invoice in an old email account, a broker confirmation, a registrar account export, hosting and email invoices. Nobody else can produce them, no lookup will surface them, and the search for them consumes days that were already scarce. Start there, not with the public record.
Creation date is not acquisition date
This is the single most common evidentiary confusion on the respondent side. A registry creation date survives transfers. It records when the name first came into existence, not when the current holder acquired it, and those can be separated by decades.
Establishing an acquisition date takes two things together: registry transfer events, which are independently recorded, and the holder's own records — the invoice, the marketplace or broker confirmation, the registrar account history showing when the name entered the account. Neither half is sufficient alone. Transfer events show that a change of sponsoring registrar occurred without necessarily showing a change of holder; a receipt shows a purchase without independently fixing it to the registry record.
Where the two agree, the chronology says so and cites both. Where they do not — and after a registrar transfer or a period of redacted registration data they sometimes do not — the chronology records the divergence rather than picking the more convenient date. An expert who reconciles an inconsistency silently has produced something that falls apart the moment anyone checks it.
Prior use, and what actually proves it
Because paragraph 4(c)(i) turns on the state of affairs before notice, the evidence that carries weight is evidence with an independent date attached. Undated screenshots of your own website prove nothing except that the site looks like that now.
The records that do carry independent dates:
- Archived captures from the Internet Archive, presented with the capture timestamp rather than as a bare image, showing the site as it stood before the dispute.
- Certificate Transparency log entries — a public, append-only log of issued TLS certificates, each carrying an issuance timestamp — which establish that a host existed and was being configured on a given date, even where no page capture survives.
- MX records in historical DNS data, which show the name was in use for mail, a form of use that leaves no visual trace at all.
- Passive DNS — a third-party archive of DNS answers observed over time by sensors rather than queried live — for resolution history.
- "Commonly known by" material: company registrations, trade filings, dated invoices and branding.
Where the domain sits in a portfolio that is descriptive or thematic rather than mark-targeted, the portfolio itself is a documentary question: what the holdings are, on what basis they were linked to the holder, and when each was acquired.
Parked pages and who chose the advertising
A domain displaying automated advertising raises a factual question that people routinely treat as a matter of assertion: who selected the ads. The registrant, or the parking provider's automated feed keyed off the string?
That has a documentary answer. Parking and monetization providers hold the ad-serving configuration, the keyword settings and the revenue reports. Those records show whether a human selected terms or whether a system generated them, and they are held by the provider on the provider's retention schedule — outside the holder's control and, in a UDRP, outside anyone's subpoena power, since the proceeding has none. If the account holder does not export them early, they may not exist when they are needed.
There is a second problem specific to parked pages: they archive badly. Automated ad content varies per visit and per visitor, so an archived capture of a parked page may not represent what any real user ever saw. An expert relying on such a capture should say so in the same breath as producing it. That limitation applies symmetrically, to captures produced by either side.
What the respondent-side record cannot establish
Some of these gaps are structural and no amount of diligence closes them.
The twenty-day window itself. Third-party record retrieval that depends on another organization's cooperation frequently will not complete in time, and a record that arrives after filing generally has nowhere to go — further submissions are at the panel's discretion under Rule 12.
Historical registration data has coverage holes, particularly across registrar transfers and for the period since public registration data became routinely redacted. Absence of a historical record is a collection gap, not proof of anything.
Hosting and advertising logs expire on the provider's retention schedule, which is typically measured in months and is not extended because a dispute has started.
Parked-page captures may not reflect what users saw, for the reason above.
There is no cross-examination. Rules 10 and 15(a) confine the panel to the submitted documents, so an assertion about intent that is not tied to a record is weighed as exactly that — an assertion.
Default is not concession, but it is not harmless either. Under Rule 14 the panel proceeds to a decision on the record it has, and the complainant's burden under paragraph 4(a) does not disappear. It simply goes untested.
Freeze the record on day one
The instinct on receiving a complaint is to fix things — clean up the site, change the DNS, update the registration record, take down the parked page. Every one of those destroys the pre-notice state that paragraph 4(c)(i) turns on, and the destruction is usually irreversible. Attempting to move the domain is worse: Policy paragraph 8 bars transferring the registration to another holder during the proceeding and for fifteen business days afterward, and the registrar lock applied under Rule 4 will usually prevent it anyway.
What to do instead, on the day notice arrives: a full-site capture; a DNS and zone snapshot; a registrar account export; screenshots recording URL, date and time zone; a hash of every artifact at capture; and a contemporaneous log of tool, version, operator and time. Then request, immediately, anything held by a third party — parking configuration, hosting invoices, marketplace records — because those are the items the clock will beat you on.
Preservation is not a defense. It is the precondition for having any evidence at all, and it is the one part of this that is entirely within the holder's control.
Word limits, annex caps, and the self-contained declaration
Rule 5(b)(ix) imposes the same duty on the respondent that Rule 3(b)(xiv) imposes on the complainant: annex the documentary evidence relied on, together with a schedule indexing it. A large unindexed pile of documents is not a response annex set; it is a burden transferred to the panel.
Rule 5(b)(i) requires the substantive response to comply with the provider's word or page limits. At WIPO that is 5,000 words. CIIDRC sets the same word figure and additionally caps annexes at 10MB per file and 50MB per package without prior approval, filed through its online platform (CIIDRC Supplemental Rules). Providers also restrict acceptable file formats, and an export in a format the provider does not accept cannot be uploaded at all.
Note the asymmetry: the respondent does not choose the provider. The complainant does, so the applicable limits and formats are known only once the case arrives — which is another reason to check them on day one rather than day eighteen. And since the word limit sits on the response body, the technical declaration again has to be readable without it: scope, sources, method, capture dates, limits, conclusion.
I have testified in domain-related legal cases and provided expert witness reports in others, and have worked in this field since 1996. Whether to respond, and what to argue, requires counsel.