What should I preserve when I suspect self-hosting?¶
Preserve the public observation and the chain that connects it to the local device. The website, accounts, router and server each explain a different part of the service.
Start outside the network¶
Record the complete URL and hostname, public IP address, date, time and time zone, visible content, redirects, certificate details, error messages and sign-in state. Note how the service was reached and avoid unnecessary interaction.
Follow the route inward¶
Domain and DNS records may identify how the hostname was pointed. Dynamic-DNS or tunnel providers may hold update and connection history. The ISP may hold address assignment. Router configuration may show forwarding, firewall and remote administration. DHCP records may identify the internal device.
The host may contain files, databases, logs, credentials, configuration and backups. Other systems can hold development copies, saved passwords or administrator communications.
This is a chain, not a single seizure target. A photograph of the webpage cannot replace router or server evidence, while a server image cannot by itself prove what an external user saw.
Small devices and routers may contain volatile or limited history. Powering down, resetting, reconnecting or allowing continued operation can each affect evidence and service availability. Use specialist support where the environment is unfamiliar or live.
The point to remember
Preserve from public page to internal host, including the accounts and network configuration that join each step.