This site is a record, not a business. BillHartzer.net publishes Bill Hartzer’s professional history and practice. It sells nothing, quotes nothing and takes no engagements — consulting and expert witness inquiries go to Hartzer Consulting.

BillHartzer.net logo mark — the professional record of Bill HartzerBillHartzer.netThe professional record of Bill Hartzer
Practice area
Engagement: TestimonyExpert Witness and InvestigationsLegal and Investigative

Domain Name Expert Witness

Registrar, registry, WHOIS and DNS records read the way a dispute requires - ownership, control, timing and value

Abstract tilted diamond illustration representing Domain Name Expert Witness

What domain disputes actually turn on

Nearly every domain matter reduces to four questions. Who owned the name, who controlled it, when did each of those things change, and what was it worth. They sound simple. They are separated by a distinction that decides cases: ownership and control are not the same thing, and the public record shows control far more reliably than it shows ownership.

A registrant name in a public lookup is self-asserted. Nobody at the registry verified it. A developer, a former employee, an agency or a hosting vendor may sit in the registrar account with full authority to move the name while the contract says it belongs to the client. I have seen more disputes caused by that gap than by anything resembling bad faith.

My role is to reconstruct the factual chain from primary records - registry and registrar data, historical lookups, DNS history, zone-file lifecycle events and archived content - and to be precise about which links in that chain are documented and which are inferred. In a domain fight, the inference is usually where the argument is.

The record trail behind a domain name

Three layers hold the evidence, and they are not equally accessible.

The registry operates the top-level domain and holds the authoritative record: creation date, expiration, sponsoring registrar, nameservers, and status codes. Those status codes are more informative than they look. clientTransferProhibited tells you a lock was set at the registrar level. pendingTransfer marks a move in flight. serverHold means the name was pulled from the zone, so it stopped resolving even though it was still registered.

The registrar holds what actually matters in a contested transfer and rarely publishes any of it: account ownership and billing, login history and IP addresses, authorization code requests, transfer approvals, support tickets, and internal audit logs. That material generally comes only through the appropriate legal process, and counsel has to ask for it by name.

The public and third-party layer includes current lookups, historical WHOIS archives assembled by commercial providers, passive DNS collections, certificate transparency logs, and web archives. These are observations by outside parties on the dates they happened to collect. Useful, frequently decisive, and not the same thing as a registry record - a distinction worth making explicitly in a report rather than leaving for cross-examination.

Where the public record misleads

Several traps recur often enough to be worth listing:

  • Redaction. Since registrant contact data was broadly redacted for privacy compliance, a current lookup on most names shows almost nothing about a person. Absence of a name in a lookup is a policy artifact, not a finding.
  • Privacy and proxy services. The listed registrant may be a shielding service. That is ordinary practice, used by the cautious and the evasive alike, and it is not by itself evidence of anything.
  • The creation date resets. A name that lapsed, dropped and was re-registered carries a new creation date. A 2004 date does not mean continuous ownership since 2004, and a recent date does not mean the name is new. The lifecycle - expiration, then a redemption grace period, then pending delete, then release - has to be read alongside archived content to see whether the property changed hands.
  • Historical archives have gaps. Commercial WHOIS history is a series of snapshots. A change between two snapshots is dated only to that interval.
  • Time zones. Registry timestamps are typically UTC while registrar interfaces and e-mail headers may not be. Timelines built without normalizing this are wrong by hours in the exact window that matters.

Cybersquatting, typosquatting and confusion

In matters involving abusive registration, the evidence an expert can develop is pattern evidence, and it is genuinely powerful when it is assembled carefully.

Registration timing relative to a trademark's first use or a public announcement is often the single most probative fact available, because it is documented at the registry and cannot be reconstructed after the fact. Beyond that, portfolios link up in ways their operators do not expect: a shared registrant e-mail address surfaced through reverse lookups, common nameservers, the same hosting address, an analytics or advertising identifier reused across supposedly unrelated sites, an identical certificate covering multiple names, recycled boilerplate text, matching page templates, and mirrored content served under different brands.

The reused analytics or ad identifier is the strongest of these, because it requires a human being to have made a deliberate choice. Shared hosting is the weakest - large providers put thousands of unrelated sites behind one address, and treating that as a connection is how an otherwise good report gets taken apart.

What none of it establishes is intent. I can describe a registration pattern, the monetization behavior, the redirect targets and the timing. Whether that adds up to bad faith is a determination for the tribunal, and an expert who tries to make it has stepped outside his role.

Theft, hijacking and unauthorized transfers

Stolen domain names follow a small number of mechanisms: compromise of the e-mail account tied to the registrar login, social engineering of registrar support, an insider with legitimate account access, a forged authorization, or the interception of a name at expiration by someone watching the drop.

Each leaves a different evidentiary trace, and the useful ones live in records the victim usually does not control. Registrar login and IP history. The timing of the authorization code request against the timing of the transfer approval. Nameserver changes in passive DNS collections, which frequently precede the visible ownership change by hours. WHOIS snapshots on either side of the event. Mail headers from the account used to approve it. Archived captures showing when the content at the address changed hands.

Recovery work is where I have spent a large share of my domain practice, and the two disciplines feed each other: the same reconstruction that gets a name returned is the reconstruction a contested matter requires. By my own count, and it is my figure rather than an audited one, I have helped recover more than 500 stolen domain names. That work sits outside litigation, but it is why I read registrar and registry records the way I do.

Valuation, damages and the appraisal problem

Domain valuation is where damages models tend to go wrong, and the error is usually the same: treating an asking price as a market price.

Public sales data is partial. Reported sales skew toward brokered and marketplace transactions that the parties chose to publicize, private deals often go unrecorded, and a single outlier sale of a superficially similar name gets cited as though it were a comparable. Automated appraisal tools produce a number from a model whose inputs and weightings are not disclosed, which makes them unsuitable as evidence even when the number happens to be reasonable.

A defensible analysis works from completed transactions with dates, from the characteristics that actually drive value - length, extension, dictionary status, commercial meaning, existing traffic and links, prior use - and from the acquiring party's own records. Where a name derives value from traffic, that traffic has to be measured rather than assumed, and it needs to be tested for whether it is type-in demand, brand demand, or the residue of a previous owner's audience that will not persist.

Prior use also carries liability in the other direction. A name with a spam, malware or adult history can arrive with damage attached, which is exactly what a background check is for.

Working with counsel

Not every domain dispute is a lawsuit. Many travel through administrative proceedings run under registry policy instead, on tight schedules with limited briefing, and the evidentiary record has to be assembled before the clock starts rather than during it. That difference in venue changes what is worth developing and how it should be presented.

The requests I most often suggest counsel make, while the material still exists: registrar account records including login and IP history, transfer and authorization logs, billing and payment records identifying who actually paid, support ticket history, the e-mail account associated with the registration, DNS configuration history, and any escrow or purchase agreement. Registrar retention is finite and varies by provider, so timing matters more here than in most technical disciplines.

My related commercial work informs this practice - domain background checks, which grew out of a scoring process I developed in 2013 and describe as patent-pending, and the stolen-domain recovery side I now run through DNAccess. Expert retention itself goes through Hartzer Consulting. This site documents the practice; it does not take engagements.

Frequently asked questions

Can a WHOIS record prove who owned a domain name?

Not on its own, and this surprises people. Registrant details are self-asserted and were never verified by the registry, and contact data is now broadly redacted for privacy compliance, so a current lookup on most names reveals little about any person. Historical archives help, but they are third-party snapshots taken on particular dates, which means a change is dated only to the interval between them. Proof of ownership usually comes from the registrar's internal records - account holder, billing, login history, transfer approvals - and those generally arrive only through appropriate legal process.

How do you tell whether separate-looking domains are operated by the same party?

By looking for connections that required a human decision. A reused analytics or advertising identifier across supposedly unrelated sites is the strongest signal, because someone had to paste it in. Registrant e-mail addresses surfaced through reverse lookups, matching nameserver configurations, certificates covering multiple names, identical templates and recycled boilerplate all add weight. Shared hosting addresses are the weakest evidence and I treat them as leads rather than findings, since large providers place thousands of unrelated sites behind a single address. The conclusion should be graded, not asserted.

What records should be preserved immediately after a domain is taken?

Anything tied to the registrar account and the e-mail address behind it. Capture the current and prior public lookups, the nameserver history, and full-page captures of the site before it changes. Preserve the mailbox with headers intact, including anything filtered or deleted around the event, because forwarding rules set by an intruder are frequently the clearest artifact. Ask the registrar to preserve login and IP history, authorization code requests, transfer approvals, billing records and support tickets. Retention windows are finite and vary by provider, so a written preservation request should go out the same day.

Can a domain name be appraised reliably enough to support a damages figure?

It can be valued defensibly, but not by an automated appraisal tool. Those produce a number from an undisclosed model, which is difficult to defend under questioning. A supportable valuation rests on dated completed sales of genuinely comparable names, the characteristics that drive demand, measured traffic rather than assumed traffic, and the acquiring party's own records and correspondence. Asking prices are not market prices, and a single publicized outlier sale is not a comparable. Where the range is wide, the honest output is a range with its reasoning, not a point estimate.

Does an expired-and-reregistered domain keep its original creation date?

No, and this trips up timelines regularly. When a name lapses, it moves through expiration, a redemption grace period and pending delete before it is released, and whoever registers it next receives a new creation date. So an early date does not establish continuous ownership by one party, and a recent date does not mean the name is genuinely new. Reconstructing actual chain of possession means reading the lifecycle events alongside historical lookups, DNS history and archived captures of the content, which usually changes character sharply when the name changes hands.
Top