Evidence & Investigation System
Build court-ready and registrar-ready evidence packages for every domain threat. WHOIS, DNS, hosting, and content are captured and preserved automatically.
The problem
Takedown requests and legal action require solid evidence. Manually collecting WHOIS, DNS history, and screenshots is slow and often incomplete. Registrars and hosts expect structured, timestamped evidence before they act.
- Phishing domains that change hosting or go offline quickly
- Impersonation sites that need content and DNS proof for takedown
- Portfolios where you need a clear audit trail for compliance
- Disputes (e.g. UDRP) that require documented history and intent
What we do
- WHOIS data capture and historical tracking
- DNS record history and change analysis
- IP address and hosting attribution
- SSL/TLS certificate monitoring
- Website content archival
- Timeline reconstruction for investigations
How it works
- 1
Automatic capture on alert
When a domain is flagged, we automatically capture current WHOIS, DNS records, and IP and hosting data. Content and certificates are archived so you have a point-in-time record.
- 2
Ongoing tracking
We continue to track changes to the domain: WHOIS updates, DNS changes, and content. This creates a timeline that supports takedown and compliance narratives.
- 3
Structured evidence packages
You can request evidence packages tailored for registrars, registries, or legal use. Packages include summaries, screenshots, and machine-readable data where relevant.
- 4
Export and retention
Evidence can be exported for your records or for counsel. Retention policies can be aligned with your compliance and legal requirements.
Example: anonymized case snapshot
Frequently asked questions
What evidence do you collect for each domain?
We collect WHOIS (registration and contact data), DNS records (A, MX, NS, etc.), IP and hosting information, SSL/TLS certificate details, and archived content (screenshots and, where applicable, stored copies). The exact set depends on the domain and your plan.
How long is evidence retained?
Retention depends on your plan and settings. We can align retention with your compliance or legal needs. Contact us to discuss retention and export options.
Can evidence be used in legal proceedings?
We design evidence packages to be thorough and timestamped. Suitability for legal proceedings depends on your jurisdiction and case. We recommend your counsel review our evidence format and retention for your use case.
Do you support UDRP or other dispute procedures?
Our evidence (WHOIS, DNS, content, timeline) is often used to support UDRP and similar proceedings. We do not provide legal advice; your counsel can use our documentation as part of a dispute or recovery strategy.
How quickly can I get an evidence package?
For domains we already monitor, evidence is collected automatically. You can request a full package from the dashboard; delivery is typically within the same business day for standard requests.
Explore further
See how DomainHQ can help
Get a free risk assessment or talk to our team about your domain protection needs.