What domain disputes actually turn on
Nearly every domain matter reduces to four questions. Who owned the name, who controlled it, when did each of those things change, and what was it worth. They sound simple. They are separated by a distinction that decides cases: ownership and control are not the same thing, and the public record shows control far more reliably than it shows ownership.
A registrant name in a public lookup is self-asserted. Nobody at the registry verified it. A developer, a former employee, an agency or a hosting vendor may sit in the registrar account with full authority to move the name while the contract says it belongs to the client. I have seen more disputes caused by that gap than by anything resembling bad faith.
My role is to reconstruct the factual chain from primary records - registry and registrar data, historical lookups, DNS history, zone-file lifecycle events and archived content - and to be precise about which links in that chain are documented and which are inferred. In a domain fight, the inference is usually where the argument is.
The record trail behind a domain name
Three layers hold the evidence, and they are not equally accessible.
The registry operates the top-level domain and holds the authoritative record: creation date, expiration, sponsoring registrar, nameservers, and status codes. Those status codes are more informative than they look. clientTransferProhibited tells you a lock was set at the registrar level. pendingTransfer marks a move in flight. serverHold means the name was pulled from the zone, so it stopped resolving even though it was still registered.
The registrar holds what actually matters in a contested transfer and rarely publishes any of it: account ownership and billing, login history and IP addresses, authorization code requests, transfer approvals, support tickets, and internal audit logs. That material generally comes only through the appropriate legal process, and counsel has to ask for it by name.
The public and third-party layer includes current lookups, historical WHOIS archives assembled by commercial providers, passive DNS collections, certificate transparency logs, and web archives. These are observations by outside parties on the dates they happened to collect. Useful, frequently decisive, and not the same thing as a registry record - a distinction worth making explicitly in a report rather than leaving for cross-examination.
Where the public record misleads
Several traps recur often enough to be worth listing:
- Redaction. Since registrant contact data was broadly redacted for privacy compliance, a current lookup on most names shows almost nothing about a person. Absence of a name in a lookup is a policy artifact, not a finding.
- Privacy and proxy services. The listed registrant may be a shielding service. That is ordinary practice, used by the cautious and the evasive alike, and it is not by itself evidence of anything.
- The creation date resets. A name that lapsed, dropped and was re-registered carries a new creation date. A 2004 date does not mean continuous ownership since 2004, and a recent date does not mean the name is new. The lifecycle - expiration, then a redemption grace period, then pending delete, then release - has to be read alongside archived content to see whether the property changed hands.
- Historical archives have gaps. Commercial WHOIS history is a series of snapshots. A change between two snapshots is dated only to that interval.
- Time zones. Registry timestamps are typically UTC while registrar interfaces and e-mail headers may not be. Timelines built without normalizing this are wrong by hours in the exact window that matters.
Cybersquatting, typosquatting and confusion
In matters involving abusive registration, the evidence an expert can develop is pattern evidence, and it is genuinely powerful when it is assembled carefully.
Registration timing relative to a trademark's first use or a public announcement is often the single most probative fact available, because it is documented at the registry and cannot be reconstructed after the fact. Beyond that, portfolios link up in ways their operators do not expect: a shared registrant e-mail address surfaced through reverse lookups, common nameservers, the same hosting address, an analytics or advertising identifier reused across supposedly unrelated sites, an identical certificate covering multiple names, recycled boilerplate text, matching page templates, and mirrored content served under different brands.
The reused analytics or ad identifier is the strongest of these, because it requires a human being to have made a deliberate choice. Shared hosting is the weakest - large providers put thousands of unrelated sites behind one address, and treating that as a connection is how an otherwise good report gets taken apart.
What none of it establishes is intent. I can describe a registration pattern, the monetization behavior, the redirect targets and the timing. Whether that adds up to bad faith is a determination for the tribunal, and an expert who tries to make it has stepped outside his role.
Theft, hijacking and unauthorized transfers
Stolen domain names follow a small number of mechanisms: compromise of the e-mail account tied to the registrar login, social engineering of registrar support, an insider with legitimate account access, a forged authorization, or the interception of a name at expiration by someone watching the drop.
Each leaves a different evidentiary trace, and the useful ones live in records the victim usually does not control. Registrar login and IP history. The timing of the authorization code request against the timing of the transfer approval. Nameserver changes in passive DNS collections, which frequently precede the visible ownership change by hours. WHOIS snapshots on either side of the event. Mail headers from the account used to approve it. Archived captures showing when the content at the address changed hands.
Recovery work is where I have spent a large share of my domain practice, and the two disciplines feed each other: the same reconstruction that gets a name returned is the reconstruction a contested matter requires. By my own count, and it is my figure rather than an audited one, I have helped recover more than 500 stolen domain names. That work sits outside litigation, but it is why I read registrar and registry records the way I do.
Valuation, damages and the appraisal problem
Domain valuation is where damages models tend to go wrong, and the error is usually the same: treating an asking price as a market price.
Public sales data is partial. Reported sales skew toward brokered and marketplace transactions that the parties chose to publicize, private deals often go unrecorded, and a single outlier sale of a superficially similar name gets cited as though it were a comparable. Automated appraisal tools produce a number from a model whose inputs and weightings are not disclosed, which makes them unsuitable as evidence even when the number happens to be reasonable.
A defensible analysis works from completed transactions with dates, from the characteristics that actually drive value - length, extension, dictionary status, commercial meaning, existing traffic and links, prior use - and from the acquiring party's own records. Where a name derives value from traffic, that traffic has to be measured rather than assumed, and it needs to be tested for whether it is type-in demand, brand demand, or the residue of a previous owner's audience that will not persist.
Prior use also carries liability in the other direction. A name with a spam, malware or adult history can arrive with damage attached, which is exactly what a background check is for.
Working with counsel
Not every domain dispute is a lawsuit. Many travel through administrative proceedings run under registry policy instead, on tight schedules with limited briefing, and the evidentiary record has to be assembled before the clock starts rather than during it. That difference in venue changes what is worth developing and how it should be presented.
The requests I most often suggest counsel make, while the material still exists: registrar account records including login and IP history, transfer and authorization logs, billing and payment records identifying who actually paid, support ticket history, the e-mail account associated with the registration, DNS configuration history, and any escrow or purchase agreement. Registrar retention is finite and varies by provider, so timing matters more here than in most technical disciplines.
My related commercial work informs this practice - domain background checks, which grew out of a scoring process I developed in 2013 and describe as patent-pending, and the stolen-domain recovery side I now run through DNAccess. Expert retention itself goes through Hartzer Consulting. This site documents the practice; it does not take engagements.