I have found a website - where should I start?¶
Start by preserving the exact observation and defining what you need to establish. A website is a collection of connected technical and customer relationships, not one identifier that leads straight to a person.
Preserve, separate, then trace¶
Record the full URL, date, time, time zone, route to the page, account state, visible content and capture method. Avoid unnecessary interaction that may change the service or alert its operator.
Next separate what you can see:
- the domain and particular hostname;
- the exact page or account;
- contact, payment and messaging details;
- the apparent website platform; and
- the public-facing infrastructure or intermediary.
Then state the question. Preserving content, identifying a domain customer, finding the publisher and tracing payments require different records from different organisations.
Think of the website as a shop assembled from rented services. One company supplies the sign, another the premises, another the till and another the telephone. Finding the landlord does not identify who served a particular customer.
Map the registrar, DNS provider, host, platform, CDN or proxy, payment service and communication accounts only as far as the question requires. Record each result with its source and time, and distinguish present-day information from the historic position.
The point to remember
Preserve first, define the question and then follow the relevant service chain. The first technical result is a route forward, not the conclusion.