Skip to content
Skip to main content
Websites, Domains & Internet Infrastructure Technical Explainer

How do I identify the evidence chain behind a website?

Build outward from the exact page, following the services that made the activity possible. A website rarely produces one decisive record.

Follow the layers

The page may be published through a platform account. Its hostname is connected through DNS to a host or intermediary. The domain is managed through a registrar account. Payments may go through a separate provider, while enquiries are handled through email or messaging accounts.

Each layer can provide a different joining point:

  • account email addresses and telephone numbers;
  • payment instruments or beneficiaries;
  • administrator login IP addresses;
  • device or browser identifiers;
  • support communications;
  • configuration and publishing times; and
  • recovery details.

Think of it as reconstructing a journey from several ticket systems. One ticket records the passenger name, another the payment and another the gate used. Their value grows when time and identifiers align.

Arrange the records chronologically. A domain change immediately before publication, followed by access to the platform and receipt of payment, may be more informative than the same facts viewed separately.

Keep realistic alternatives visible. Shared administration, stolen payments, compromised accounts and ordinary shared infrastructure can explain individual links. The strength comes from independent records converging on the relevant activity while those alternatives are tested.

The point to remember

Build a timed, corroborated chain across services; do not search for one supposedly conclusive website record.

Reference: WDH-033Websites, Domains & Internet Infrastructure