Domain Takedown Evidence: What to Capture Before You Report
Updated October 4, 2026
Every takedown channel, whether abuse desk, UDRP panel, or court, acts on documented observations, not assertions. A complete package holds the current registration record, DNS answers, timestamped full-page captures, and all correspondence, preserved before the operator is warned and can delete it.
- WIPO filing asks for
- Current Whois record + site content
- Standard of proof
- Preponderance of evidence
- Golden rule
- Capture before you contact
Evidence decides every channel. A registrar abuse desk triages reports by whether they state verifiable facts. A UDRP panel decides on the preponderance of the evidence (more likely than not) and has repeatedly held that assertions without documents do not meet that bar. The difference between a report that acts and one that is ignored is usually the quality of what is attached.
Capture first, contact second
The single most common mistake is acting before preserving. A cease and desist letter or an abuse report warns the operator, and the standard response is to delete the hosted content or move it. Once the phishing page is gone, your report describes something nobody can verify. Preserve everything before anyone is notified.
The layers of a complete package
Registration record. Save the full RDAP or Whois record as it exists today: sponsoring registrar and abuse contact, creation timestamp, status codes, name servers, and registrant data where visible. UDRP providers ask complainants to annex a copy of the current Whois information with the complaint. The abuse contacts tool pulls this record for any domain.
DNS state. Record the answers, not conclusions: the A/AAAA records resolving the name, MX records if mail is configured (the setup behind misdirected-email fraud), and NS records showing where it is delegated. Note the resolver and the UTC time of each query.
The site content. Providers expect evidence of what the site serves where available. Capture full-page screenshots that include the browser address bar, save the exact URLs of each offending page, and note form fields that ask for credentials or payment data. Record the precise UTC timestamp of each observation.
Correspondence. Keep every exchange: your demand letter and proof of delivery, their reply, any offer to sell. WIPO panels admit sale offers made in settlement discussions as bad-faith evidence, and the reply you get is often the strongest exhibit you will have.
Inbound email. When the abuse arrives as mail rather than a site, such as fake invoices or impersonating replies, preserve the original message with full headers intact. The Received chain records which servers handled the message, and paired with the domain’s MX records it ties the mail to the lookalike registration.
What each audience needs
| Audience | Decides on | Needs most |
|---|---|---|
| Registrar abuse desk | Deceptive or malicious use | The observed content, DNS facts, timestamps |
| Hosting provider | The hosted material | Exact URLs and what they serve |
| UDRP panel | Three policy elements | Whois copy, content captures, rights evidence |
| Counsel | The whole picture | Everything, with an unbroken timeline |
Each row is a reason to collect broadly: the package that satisfies a registrar is a subset of what a panel needs, and a subset again of what counsel wants.
The product shortcut
notolens keeps this record automatically. Every match carries an append-only record of each observation (registration data, DNS answers, and what the site served at probe time), and the Evidence PDF export packages the verifiable facts a third party can rely on: the probed URL, the capture time, and the register entry, without interpretation layered on top.
Evidence decays in both directions: content disappears when you act, and a subject that reappears after a takedown needs a fresh record of what it serves now. Domain monitoring keeps that record current on every match, so the package you send describes what was observed.
Sources
Frequently asked questions
UDRP Rules paragraph 3(b) requires the complaint to identify the domains in dispute, describe the grounds, and annex documentary evidence. Provider filing guidance asks for a copy of the current Whois record and the offending site content in the annexes. Panels decide on the preponderance of the evidence (a fact is proven when it is more likely than not true), and assertions without documents carry little weight.
No certification is required, but a screenshot should show the full browser address bar and you should record the URL and the exact UTC time it was taken. Undated captures of partial pages invite challenges that full-frame, timestamped ones do not.
Yes where possible. A capture in a third-party archive such as the Wayback Machine corroborates what the page contained at a given time. Note that respondents can block archivers via robots.txt, which WIPO panels have themselves weighed as a bad-faith factor, so a block is worth documenting too.
That is the common failure mode this process exists to prevent. Operators delete sites after a demand letter or takedown. If your own captures are gone, archives may still hold a copy. And if the subject reappears later, a monitoring record gives you a fresh, timestamped baseline.
Related tools and resources
Continuous brand monitoring
notolens checks daily registrations across 1,570 TLDs, trademark registers, and app stores. When a lookalike domain, conflicting mark, or copycat app appears, notolens checks it, explains the risk, and hands you the records and possible next steps.