Skip to content
Skip to main content
Websites, Domains & Internet Infrastructure Technical Explainer

Can I prove somebody downloaded a file from a website?

Server and device evidence can show that data was transferred to a device or account. The person who initiated it, whether the file completed and what happened afterwards are separate questions.

Join both ends of the transfer

Server logs may record the file URL, timestamp, source address, response status and bytes sent. Browser or application history may record the download. The device may contain a complete file, temporary part-file, thumbnail, recent-file entry or security scan record.

Compare expected size and, where available, a cryptographic hash. Matching hashes can show that two files contain the same bytes even if their names differ.

A parcel analogy helps: an order, dispatch, delivery and opening are different events. A download record should not silently become proof of deliberate acquisition, knowledge or use.

Automatic downloads, synchronisation, browser preloading and malware can create files without a conscious request. Shared devices and accounts also affect attribution.

Evidence of opening, renaming, moving, sharing or repeated access can explain later use. Link the event to the device user through account activity, communications and surrounding actions.

The point to remember

Establish transfer and file identity first; attribute initiation, possession, opening, knowledge and intent separately.

Reference: WDH-083Websites, Domains & Internet Infrastructure