# Beyond WHOIS: Using Visual Evidence in UDRP & Bad-Faith Domain Disputes

Source: PageCrawl.io Blog
URL: https://pagecrawl.io/blog/visual-evidence-domain-disputes-udrp
Published: 24 August, 2026

---

Your trademark counsel forwards a complaint from a customer: a domain that pairs your brand name with the word "outlet" is selling counterfeit versions of your flagship product and collecting card details at checkout. By the time you open the link an hour later, the storefront is gone. The page now shows a bland "this domain may be for sale" parking notice. The registrant did not give up. They sanitized the page the moment they sensed attention.

This is the central problem in almost every domain dispute. A WHOIS lookup tells you who registered a domain and when, but a UDRP panel does not award transfers based on registration records alone. It wants proof of how the domain was actually used, and that proof lives in page content that the respondent fully controls and can rewrite in seconds. The evidence you need is the most perishable thing in the entire case.

This guide covers why WHOIS records fall short on their own, what "bad faith" actually requires you to demonstrate, which kinds of visual evidence carry weight before a panel, and how to set up automated capture so a respondent cannot quietly erase the conduct your complaint depends on. None of this is legal advice. Treat it as a preservation playbook to hand your counsel, not a substitute for them.

<iframe src="/tools/visual-evidence-domain-disputes-udrp.html" style="width: 100%; height: 500px; border: none; border-radius: 4px;" loading="lazy"></iframe>

### Why isn't WHOIS enough to win a UDRP case?

WHOIS is necessary but never sufficient. It establishes who registered a domain and on what date, which supports the "registered in bad faith" half of the test. But the Uniform Domain-Name Dispute-Resolution Policy, administered under [ICANN](https://www.icann.org), also requires proof that the domain is *being used* in bad faith, and use is a question of page content over time, not registration metadata.

A registrant can hide behind a WHOIS privacy service, transfer the domain mid-dispute, or simply argue that the registration was innocent. What undermines those defenses is a documented record of what the domain actually displayed: a counterfeit storefront, a pay-per-click parking page monetizing your trademark, a redirect to a competitor, or a "make an offer" listing aimed at you. WHOIS captures none of that.

Monitoring registration data still matters as an early-warning layer, and the [WHOIS domain change monitoring guide](/blog/monitor-whois-domain-changes) covers how to watch registrant, nameserver, and status changes. But registration records are the skeleton of a case. The page content is the muscle. Panels decide on the muscle, and the muscle decays the fastest.

### What does "bad faith" actually require you to prove?

Paragraph 4(b) of the UDRP Policy lists four circumstances that, if shown, are evidence of bad-faith registration and use. Each one is provable through page content rather than registration data, which is exactly why timestamped captures of the live domain are so valuable. You are documenting behavior, and behavior happens on the rendered page.

The four enumerated circumstances, paraphrased, are:

1. **Registration primarily to sell the domain** to the trademark owner or a competitor for more than out-of-pocket costs. The evidence is a "for sale" or "make an offer" listing, ideally one naming a price or soliciting offers.
2. **Registration to block the trademark owner** from reflecting the mark in a domain, where the respondent has engaged in a pattern of such conduct. The evidence is multiple infringing registrations by the same party.
3. **Registration to disrupt a competitor's business**, often shown by a redirect to a rival or by competitive advertising on the page.
4. **Using the domain to attract users for commercial gain** by creating a likelihood of confusion with your mark. This is the broadest category: counterfeit shops, phishing pages, and pay-per-click parking pages monetizing your brand all fall here.

#### What about a domain that just sits there parked?

Even a passively held domain can support a finding of bad faith. The well-known *Telstra Corporation v. Nuclear Marshmallows* decision established that inactivity does not insulate a respondent when other factors point to bad faith, such as a famous mark, concealed identity, and no plausible legitimate use. To run that argument, your counsel needs proof of the passive holding *over time*, which means dated captures showing the domain stayed dormant or cycled through parking templates rather than a single snapshot.

#### What defeats a "legitimate interest" defense?

Respondents routinely claim a bona fide offering of goods or a legitimate noncommercial use. A change history that shows the page flipping from a parking page to a counterfeit store to a redirect, then back to parking once a complaint lands, directly contradicts any claim of consistent good-faith use. The pattern itself is the argument, and you can only show a pattern if you captured each state as it happened.

### What kinds of visual evidence carry weight before a UDRP panel?

Panels respond best to evidence that is dated, complete, and hard to fabricate. A bare screenshot pasted into a document with no URL or timestamp invites the respondent to dispute its authenticity. Stronger evidence pairs the visual rendering with the URL, a precise capture time, and a continuous history showing the content was persistent rather than cherry-picked.

The most persuasive package usually combines several layers:

- **Full-page screenshots** of the live domain showing the infringing content exactly as a visitor saw it, including content below the fold.
- **The captured text content** of the page, so quoted language (a brand name, a price, a "for sale" notice) is searchable and verifiable rather than locked inside an image.
- **A timestamped change history** proving the content existed across multiple dates, which defeats the "you caught a one-off glitch" defense.
- **A complete archive of the page resources** where available, so the rendering can be independently replayed long after the live site changes.

This mirrors the standards for any litigation-grade web capture. The [guide to preserving internet evidence for legal proceedings](/blog/preserving-internet-evidence-defamation) walks through authentication, chain of custody, and the best-evidence considerations that apply equally to domain disputes. The same self-contained [web archiving](/blog/website-archiving) format that survives a defamation matter survives a UDRP matter, because in both cases the question is what a page said on a specific date.

#### Why does a change history beat a single screenshot?

A single screenshot proves a page looked a certain way at one instant. A respondent can argue it was momentary, doctored, or unrepresentative. A series of dated captures over days or weeks proves persistence and intent, which are precisely the elements bad faith turns on. [Visual regression monitoring](/blog/visual-regression-monitoring-detect-ui-changes) makes each change explicit by highlighting exactly what was added or removed between checks, turning a pile of screenshots into a clear before-and-after narrative a panelist can read in seconds.

### How do you capture and preserve domain evidence before it changes?

Set up automated monitoring the moment a suspect domain surfaces, not after counsel has reviewed it. The window between discovery and the respondent sanitizing the page is often measured in hours. Automated capture removes the human delay and produces dated, consistent records without anyone remembering to take a screenshot. Here is a concrete walkthrough using PageCrawl.

**Step 1: List every domain in scope.** Start with the offending domain, then add the variations a cybersquatter is likely to operate in parallel: your brand plus "shop," "outlet," "login," "secure," and common misspellings. The [domain fraud and lookalike detection guide](/blog/web-domain-fraud-monitoring-brand-protection) explains how to generate these variants systematically so you are not capturing one domain while three siblings stay invisible.

**Step 2: Add each domain in full-page mode.** Full-page tracking captures the entire rendered page, not just one element, which is what you want for evidence. Do not narrow it to a single selector. A respondent who changes the page layout should not be able to slip the change past a monitor watching only one box.

**Step 3: Enable screenshots on every monitor.** Screenshots are the visual exhibit a panelist understands at a glance. Combined with the captured text content, they give you both the picture and the searchable words. PageCrawl timestamps each capture and records the URL automatically, so the metadata that authentication depends on is built in rather than added by hand later.

**Step 4: Set an aggressive check frequency for active threats.** For a domain you believe is about to be cleaned up, check hourly. For dormant lookalikes you are watching defensively, every 6 to 12 hours is enough to catch the transition from parked to active. The goal is to leave no gap a respondent can claim the infringing content appeared and disappeared inside.

**Step 5: Turn on a complete web archive where available.** A full archive bundles the page's HTML, styling, images, and response data into a single self-contained file that can be replayed independently of the live site, as described in [what's inside a PageCrawl WACZ archive](/help/features/article/web-archiving-wacz.md). For evidence that may not be argued for 45 to 60 days (a typical UDRP timeline) or longer, a [self-contained web archive with a signed timestamp](/web-archives) that does not depend on the original server is the strongest record you can hold.

**Step 6: Organize captures by matter.** Put each dispute in its own folder and tag monitors with the respondent or the disputed mark. When counsel asks for everything on one domain between two dates, you want to pull it in one filtered view, not reconstruct it from a dozen scattered monitors.

**Step 7: Document the setup itself.** Write down which domains you are monitoring, when monitoring started, and the frequency you chose. This record supports chain of custody and shows the preservation was systematic rather than selective. You can validate this whole workflow on PageCrawl's free tier, which includes 6 monitors and 220 checks per month, enough to cover the primary infringing domain and a handful of its closest variants before you scale up.

### How do you document a domain's changes over time?

Let the monitor run continuously and never delete history, even after a domain goes dark. The value of the record grows as it lengthens, because each captured state adds another data point to the pattern of conduct your complaint relies on. A domain that cycles parked, then counterfeit, then redirect, then parked again tells a story that no single capture can.

[Image: PageCrawl change diff for brand-outlet.com - Page Snapshot History, highlighting the added and removed text]

When PageCrawl detects a change, it records the new state alongside the prior one and flags exactly what shifted. That produces a dated timeline: the day the parking page went live, the day it became a storefront, the day it started redirecting to a competitor, and the day it reverted once your cease-and-desist arrived. That reversion is often the single most damaging fact for a respondent, because it shows consciousness of the infringement. You only have it if you were already watching.

For respondents who operate many domains, the same timeline approach across a folder of monitors builds the "pattern of conduct" argument under paragraph 4(b)(ii). Side by side, ten dormant lookalikes registered by the same party and captured on the same dates are far more persuasive than ten isolated screenshots. Broader [domain monitoring](/blog/domain-monitoring) practices help you keep that portfolio view current as new registrations appear.

### How do you catch new infringing domains before they go live?

Combine registration alerts with content monitoring so you learn about a domain at registration and again as soon as a check finds it hosting real content. Registration monitoring tells you a suspicious domain now exists. Content monitoring tells you when it becomes dangerous and, crucially, captures the dangerous content before the respondent can remove it.

Pair a [domain availability and registration alert](/blog/domain-availability-monitoring-alerts) workflow with the capture setup above. When a new brand-adjacent domain is registered, add it as a full-page monitor immediately, even while it is still parked. A parked domain is low risk and low evidence value, but when it transitions to a storefront or a login clone, the next check captures that first active state with a timestamp. That first capture is frequently the cleanest evidence in the entire case, because it predates any attempt to look legitimate.

This is also where a broader trademark watch and [brand and reputation monitoring](/use-cases/brand-monitoring) pay off. The [trademark and patent watch guide](/blog/patent-monitoring-trademark-watch-alerts) covers monitoring registries and brand mentions, and feeding any new infringing domain it surfaces straight into content capture closes the loop between "a threat exists" and "we have it on the record."

#### How do you wire alerts into your dispute workflow?

Route change alerts into the tools your team already uses so evidence collection starts automatically rather than waiting for someone to read an email. With [webhook automation](/blog/webhook-automation-website-changes), a detected change on a monitored domain can open a matter ticket, notify counsel in Slack or Teams, and log the capture in your case-management system as soon as a check detects the change. For a respondent racing to sanitize a page, the difference between a webhook firing on the next check and a human noticing days later is often the difference between holding the evidence and losing it.

### How should you package the evidence for counsel and the complaint?

Hand counsel a clean, dated chronology rather than a folder of loose images. UDRP complaints are decided on documents, with no live hearing in the standard process, so the quality and clarity of your written record carries the case. Present each capture with its URL, its precise timestamp, and a short note on what it shows and which bad-faith factor it supports.

A practical structure that maps to the Policy:

- **Identity or confusing similarity.** Captures showing the domain prominently displaying or trading on your mark.
- **No legitimate interest.** The change history showing inconsistent, non-bona-fide use, plus the absence of any genuine offering.
- **Bad-faith registration and use.** The "for sale" listing, the counterfeit storefront, the competitor redirect, or the pay-per-click parking, each tied to a specific paragraph 4(b) circumstance and a specific dated capture.

Never edit a capture. Present it as recorded, and if you need to highlight a detail, annotate a copy while keeping the original untouched. If a capture's authenticity is challenged, the guide to [verifying a PageCrawl web archive](/help/web-archives/article/verifying-a-web-archive.md) shows how to demonstrate its integrity and certified timestamp. Most UDRP cases go to [WIPO](https://www.wipo.int) or the Forum, run roughly 45 to 60 days, and cost on the order of $1,500 and up in provider fees for a single-member panel. A clean evidentiary record shortens the back-and-forth and strengthens the panel's confidence that the conduct was real and sustained. Your counsel decides the legal strategy; your job is to make sure the proof still exists when they need it.

### Which PageCrawl plan do you need for domain evidence?

The **Free plan** covers **6 pages** with **220 checks per month**, enough to lock down a primary infringing domain and a few lookalikes while a dispute is still forming. Brand protection programs move up for the page count and the faster checks that close the gap a respondent could clean up inside.

| Plan | Price | Pages | Checks / month | Frequency |
|------|-------|-------|----------------|-----------|
| Free | $0 | 6 | 220 | every 60 min |
| Standard | $8/mo or $80/yr | 100 | 15,000 | every 15 min |
| Enterprise | $30/mo or $300/yr | 500 | 100,000 | every 5 min |
| Ultimate | $99/mo or $999/yr | 1,000 | 100,000 | every 2 min |

Annual billing saves two months across every paid tier. Enterprise and Ultimate scale up to 100x if you need thousands of pages or multi-team access.

A single UDRP filing costs more than a year of monitoring, and losing the evidence can cost the case entirely. Standard at $80/year covers 100 domains with 15-minute checks, enough to watch a primary infringer alongside dozens of lookalike variants and your own brand pages with full screenshots and change history retained. For IP firms or in-house teams running several disputes at once, Enterprise at $300/year covers 500 domains with 5-minute checks and multi-team access, which is the scale a serious brand protection program needs to document a respondent's entire portfolio at once.

### How do you get started today?

Pick the single most damaging domain in your current dispute and add it to PageCrawl today with full-page monitoring, screenshots on, and an hourly check. Then add its closest lookalike variants. The free tier's 6 monitors are enough to lock down a primary infringer and its siblings before a respondent senses the heat and starts cleaning up.

The respondent controls the page. You control whether anyone can still see what it said. Start capturing before they hit delete.

---

Need more? The complete PageCrawl.io help center, with every article, is available as a single document at https://pagecrawl.io/llms-full.txt. Read it for context on anything this page does not cover.
