Skip to content

Domain Takedown Evidence: What to Capture Before You Report

Updated October 4, 2026

Every takedown channel, whether abuse desk, UDRP panel, or court, acts on documented observations, not assertions. A complete package holds the current registration record, DNS answers, timestamped full-page captures, and all correspondence, preserved before the operator is warned and can delete it.

WIPO filing asks for
Current Whois record + site content
Standard of proof
Preponderance of evidence
Golden rule
Capture before you contact

Evidence decides every channel. A registrar abuse desk triages reports by whether they state verifiable facts. A UDRP panel decides on the preponderance of the evidence (more likely than not) and has repeatedly held that assertions without documents do not meet that bar. The difference between a report that acts and one that is ignored is usually the quality of what is attached.

Capture first, contact second

The single most common mistake is acting before preserving. A cease and desist letter or an abuse report warns the operator, and the standard response is to delete the hosted content or move it. Once the phishing page is gone, your report describes something nobody can verify. Preserve everything before anyone is notified.

The layers of a complete package

Registration record. Save the full RDAP or Whois record as it exists today: sponsoring registrar and abuse contact, creation timestamp, status codes, name servers, and registrant data where visible. UDRP providers ask complainants to annex a copy of the current Whois information with the complaint. The abuse contacts tool pulls this record for any domain.

DNS state. Record the answers, not conclusions: the A/AAAA records resolving the name, MX records if mail is configured (the setup behind misdirected-email fraud), and NS records showing where it is delegated. Note the resolver and the UTC time of each query.

The site content. Providers expect evidence of what the site serves where available. Capture full-page screenshots that include the browser address bar, save the exact URLs of each offending page, and note form fields that ask for credentials or payment data. Record the precise UTC timestamp of each observation.

Correspondence. Keep every exchange: your demand letter and proof of delivery, their reply, any offer to sell. WIPO panels admit sale offers made in settlement discussions as bad-faith evidence, and the reply you get is often the strongest exhibit you will have.

Inbound email. When the abuse arrives as mail rather than a site, such as fake invoices or impersonating replies, preserve the original message with full headers intact. The Received chain records which servers handled the message, and paired with the domain’s MX records it ties the mail to the lookalike registration.

What each audience needs

Audience Decides on Needs most
Registrar abuse desk Deceptive or malicious use The observed content, DNS facts, timestamps
Hosting provider The hosted material Exact URLs and what they serve
UDRP panel Three policy elements Whois copy, content captures, rights evidence
Counsel The whole picture Everything, with an unbroken timeline

Each row is a reason to collect broadly: the package that satisfies a registrar is a subset of what a panel needs, and a subset again of what counsel wants.

The product shortcut

notolens keeps this record automatically. Every match carries an append-only record of each observation (registration data, DNS answers, and what the site served at probe time), and the Evidence PDF export packages the verifiable facts a third party can rely on: the probed URL, the capture time, and the register entry, without interpretation layered on top.

Evidence decays in both directions: content disappears when you act, and a subject that reappears after a takedown needs a fresh record of what it serves now. Domain monitoring keeps that record current on every match, so the package you send describes what was observed.

Sources

Frequently asked questions

Related tools and resources

Continuous brand monitoring

notolens checks daily registrations across 1,570 TLDs, trademark registers, and app stores. When a lookalike domain, conflicting mark, or copycat app appears, notolens checks it, explains the risk, and hands you the records and possible next steps.