Domain Evidence for IP and Brand Counsel
You have a client, a mark, and a list of domains that infringe it. The hours go into turning that list into evidence a registrar or a UDRP panel will act on: registration data, dated screenshots, proof of common control, all in the order a complaint cites them. VigilDNS monitors the lookalikes and prepares that evidence set, with draft complaints your attorneys review and complete.
Where the hours go in a domain matter
Finding the domains is rarely the hard part. The work is the record around them: pulling registration data before it changes, capturing each site with a date on it, setting it beside the client's official site, documenting certificates and mail setup, working out which names belong to one respondent, and assembling it all into annexes. Done by hand across a portfolio of client brands, that is paralegal time on every matter, and a screenshot saved to a shared drive last month carries no proof of when it was taken or that it has not changed since.
Consolidation is the other trap. Joining names into one complaint because they share a registrar or a hosting provider invites a panel to split the case, since unrelated registrants share both all the time. A consolidated complaint needs links a panel can verify.
The evidence bundle
From the permutations list, the Watchlist, or the takedown report, any member of a tenant can export an evidence bundle for the domains selected, on any plan. Registration data is refreshed first, and an optional matter reference prints on every annex. The bundle is a ZIP laid out in WIPO model complaint annex order:
- Registration data for each domain from RDAP, each record stating when it was retrieved.
- Dated screenshots of each site as captured, unmodified, each with its capture time and SHA-256 digest. Where a domain served no page, the annex states what was observed instead.
- Side-by-side comparison of each lookalike with the client's official site, with the similarity method stated.
- DNS and mail records. A null MX, which declares that a domain accepts no email, is never presented as mail capability.
- Certificates naming each domain, from public Certificate Transparency records (via crt.sh) and live TLS handshakes.
- Change history: the hosting, name server, and content changes VigilDNS recorded, each dated.
- Common control: the links between names that point to one operator.
- Prior notices: abuse reports your tenant recorded, quoted as recorded for the firm to confirm.
The trademark certificates, reputation evidence, and copy of the Policy are the firm's to supply; the bundle lists those annexes as yours and never fills them in. Alongside the annexes come the screenshots, CSV and JSON data files for your own case records, and a SHA256SUMS file listing every file's digest, so anyone can confirm nothing changed after export. Every time is in UTC. No VigilDNS risk score appears in any annex or complaint: a complaint cites facts, not our metric.
Draft complaints, grouped into cases a panel can follow
The bundle groups the domain names into cases, one complaint each. Names join a case only on links a panel can verify: one TLS certificate naming both, the same published registrant, the same tracking ID or page text, the same redirect destination, or the same storefront template. Shared hosting, name servers, or registrar never join a case on their own, and identifiers that turn up on lookalikes of many unrelated brands are treated as shared infrastructure, not common control.
Each case folder holds a draft complaint in Word, with the facts VigilDNS holds written in and highlighted fields for the firm to complete, plus its own annexes covering only that case's names. The drafts are a drafting aid: attorney review is required before anything is filed, and the bundle says so. The wording asserts only what the captures show.
Drafts are written only for TLDs that follow the UDRP. Names on other TLDs, including many country codes, are pointed to that registry's own dispute procedure, with a reminder to confirm the registry's current policy before filing.
The takedown dossier, for the abuse desk
Not every name needs a dispute. For lookalikes your client's tenant confirmed as malicious, the takedown dossier groups them by the abuse address that handles them, not by registrar name, and splits them into abuse reports, for active harm such as phishing or counterfeit sales, and trademark claims under the UDRP or ACPA, for names held but serving nothing actionable. You get an email draft per group with an evidence PDF attached, or the PDFs alone, and you send them from your own mail.
What VigilDNS monitors before you build the case
- 13 generation techniques plus brand keyword packs: typos, homoglyphs, and combosquats, plus 28 keyword packs in 7 lines of business and up to 25 of the client's own terms per domain.
- A discovery queue that searches over a million observed certificate names every 6 hours for the client's brand in names no generator would build.
- Counterfeit storefront verdicts that flag likely counterfeit shops selling the client's goods. See counterfeit storefront monitoring.
- Campaigns that cluster lookalikes by shared certificates, tracking IDs, redirects, and templates, triaged in bulk with preset reasons.
- Dated screenshot history: each visible change to a lookalike's page is kept, dated, and hashed.
- Scans on the plan's schedule: every 24 hours on Starter, every 12 hours on Team and Business.
Many client brands
Each client brand can be its own tenant, with its own domains, members, triage, and evidence, and a colleague can belong to several tenants and switch between them. Firms monitoring many clients arrange multi-client tenants under Enterprise; request an Enterprise quote on the pricing page. An in-house IP team protecting one company's brands can start on a published plan today.
What we do not do
VigilDNS prepares evidence and drafts; it never files a complaint, sends a notice, or contacts a registrar, and it does not keep your correspondence with them. Its drafts are a starting point for your attorneys, not a substitute for their judgment. It covers domains and the websites on them, not marketplace listings or social media accounts.
Plans
Every feature, including the evidence bundle, the draft complaints, and the takedown dossier, is on every plan. Starter is $79 a month (5 domains, 3 seats, scans every 24 hours), Team is $199 (20 domains, 10 seats, every 12 hours), and Business is $899 (100 domains, 25 seats, every 12 hours). Annual billing includes two months free. Multi-client tenants and portfolios beyond 100 domains or 25 seats are Enterprise, by quote.
| Step | By hand | With VigilDNS |
|---|---|---|
| Registration data | Looked up and saved per domain | Retrieved for the bundle, each record dated |
| Screenshots | Saved ad hoc, dated by file name | Each visible change kept, dated, and SHA-256 hashed |
| Grouping into complaints | A judgment call per matter | Cases joined only on links a panel can verify |
| Annexes | Assembled per complaint | Laid out in WIPO model complaint annex order |
| Integrity | Trust the folder | SHA256SUMS for every file |
| Complaint | Started from a blank template | A Word draft per case, highlighted fields, attorney review required |
Frequently asked questions
Are the draft complaints ready to file?
No. They are a drafting aid: every fact VigilDNS holds is written in, and the fields only the firm can complete are highlighted. Attorney review is required before filing, and the bundle says so. VigilDNS never files anything.
How do you decide which domains belong in one complaint?
Only on links a panel can verify between two names: one TLS certificate naming both, the same published registrant, the same tracking ID or page text, the same redirect destination, or the same storefront template. Shared hosting, name servers, or registrar are supporting facts at most and never join a case on their own.
Does a VigilDNS risk score appear in the evidence?
No. Scores are a monitoring metric and appear in no annex or complaint. Automated classifications are quoted only where they corroborate the recorded observations, labelled as automated with their confidence and date.
What about domains on country-code TLDs?
Complaint drafts are written only for TLDs that follow the UDRP. Other TLDs are pointed to that registry's own dispute procedure, and the bundle asks you to confirm the registry's current policy before filing.
Can we manage many client brands?
Yes. Each client brand can be its own tenant, and a colleague can belong to several and switch between them. Multi-client tenants for firms are arranged under Enterprise.
Start with the free typosquat checker on a client's domain, then review pricing. For clients whose problem is fake stores, see counterfeit storefront monitoring; for background, see how domain takedowns work and RDAP vs WHOIS. Protecting your own firm's domain from wire fraud is a different job, covered on domain monitoring for law firms.