Skip to content
Skip to main content
Websites, Domains & Internet Infrastructure Foundation Explainer

How do a domain name and website fit together?

A domain name is the memorable label in a web address. It helps a browser find a service, but it is not the webpage, the server or the person operating either of them. Separating those parts tells an investigator what the first record means and which provider may hold the next one.

In one sentence
The URL identifies what was requested; the domain helps route the request; DNS supplies routing information; and hosting makes the content available. Different organisations and customer accounts may control each part.

Start with the complete address

Example reported address
scheme=httpsdomain=northmere-archive.examplepath=/member/collection/AR-184observed_at=2026-06-12T20:16:08Z
Established the report identifies this address and path at the stated timeStill open what the provider served, which account published it and who controlled that account

The domain is only one part of a URL. The path can identify a particular page, collection, account or object. One domain may serve many different webpages, so preserving only northmere-archive.example may discard the most useful part of the report. Recording the exact webpage keeps the resource and its context together.

Registration, DNS and hosting do different jobs

Complete URL
Domain registration
DNS answer
Intermediary or origin
Hosted content

This is a functional chain, not a list of suspects. Each layer answers a different question and may belong to a different provider or customer.

  • The registrar manages the domain registration and customer relationship.
  • DNS publishes information that helps requests reach the service.
  • A hosting provider stores or serves the website or application.
  • A reverse proxy or intermediary may stand between visitors and the origin host.
  • The website platform or administrator publishes and changes the content.

DNS can point to an intermediary rather than the computer holding the content. That may look odd because the visible IP address belongs to a large provider. The reason is simple: the intermediary is receiving the request first. Its customer and origin records may therefore be the next useful line of enquiry.

Why the separation matters
Infrastructure identifies services and accounts before it identifies a human being. Treat the registrant, hosting customer, site administrator, content contributor and beneficiary as potentially different until evidence joins them.

Privacy does not remove the provider record

Public registration details may be hidden or replaced by a privacy service. This means the public lookup is not displaying the customer; it does not mean the registrar has no customer, billing or account records. Why registration information may be hidden and what registrar records may exist explain the useful distinction.

Public lookupRegistrant: Privacy serviceDescribes what is exposed publicly.
Provider recordaccount_id=REG-6204May retain customer, recovery, billing and event information.

The privacy service has not performed an evidential vanishing act. It has changed which provider must be approached and which proposition the public record can support.

Today's answer may not describe yesterday's website

Domains change registrar, DNS answers change and sites move between hosts. A current result cannot safely be projected backwards. Historical hosting evidence, historical registration information and records showing which infrastructure served a site at a particular time help reconstruct the offence-time position.

29 MayDomain created and first DNS configuration recorded.
12 JuneReported resource observed through the intermediary.
14 JuneDNS changed and the visible site disappeared.

An archived webpage may show earlier public content. It does not automatically reveal every page, prove who published it or replace provider records, but it can establish that a particular presentation existed and preserve filenames, text or links for comparison.

What the records can establish

Simplified provider map
RegistrarREG-6204creation, customer fields, recovery details, billing token
DNS or intermediaryZONE-418 / EDGE-92configuration, customer account, origin or routing history
Hosting platformWEB-11872deployments, administrator events, stored content, source addresses
The precise fields depend on the service and retention position

Provider administrator records can connect changes to an account, session or application. They do not automatically prove the named customer personally made the change. The distinction between infrastructure and responsibility keeps that limitation clear while allowing the investigation to move forward.

Read infrastructure positively but precisely

Several records can create a strong evidential route even where none is decisive alone: the same recovery address across registrar and host; a billing method associated with a suspect; repeated administration from a relevant connection; a live provider session on a recovered device; and local files matching a deployment.

Those facts corroborate because independent systems record different parts of one operation. The account, service, device and human remain distinct propositions, explained further in how the domain, registrar, registrant and host fit together, which organisation may hold which records and what best links a person to a website.

Operational takeaway
Use each layer for the question it can answer. The URL fixes the reported resource; domain and DNS records reconstruct routing; hosting records address publication and administration; wider account and device evidence can take the enquiry to a suspect.
Reference: WDH-002Websites, Domains & Internet Infrastructure