Who this is for, and why the order matters more than the volume
This page is written for counsel preparing to hand an internet defamation matter to a technical examiner, and it is deliberately concrete. It is about intake — what to send, in what sequence, in what format — because those choices set the cost of the engagement far more than the size of the matter does.
The order is the content. Establish who holds each record before collecting anything. Know what the process to that holder actually returns before demanding it. Collect what is still live before it is not. A matter that arrives in that order costs a fraction of one that arrives as a folder of screenshots and a request for an opinion, and it produces more, because the records that would have completed the picture still exist when somebody asks for them.
None of what follows is advice about your case. It is a description of what a technical examination needs as input.
What to send first, before anything is collected
Five items, and they fit in one email.
- The URLs exactly as they appear — protocol included, full path, query string intact, nothing truncated by a mail client or a document viewer. A shortened or wrapped link is a different address.
- Whether each item is still live, and when it was last seen. Content still reachable can be collected properly. Content already down has to be reconstructed, which is the largest single driver of cost in this work.
- The platform's own identifiers — the profile URL, the numeric or opaque account identifier where it is visible, the exact username with its capitalization preserved, and the permalinks to the individual posts. A description such as the negative reviewer is not actionable by a platform or by me.
- The dates alleged, with their time zones. Some platform timestamps are absolute, some are rendered relative, and some are normalized to the viewer's zone, which means two people capturing the same page in different places record different times for the same event.
- What has already been demanded or produced, and from whom.
Nothing on that list requires a decision about strategy, and all of it changes what I would tell you to do next.
The one-page fact frame
Alongside the inventory, a short frame saves several rounds of questions. It needs the specific statements at issue, quoted rather than characterized, because the difference between the alleged statement and the words on the page is often the whole analysis. It needs every string by which the subject may be identified — legal name, former names, married names, initials, nicknames, professional handles, common misspellings, and any transliteration. Exact-string searching misses all of the variants, and deliberate obfuscation with zero-width or look-alike characters is designed to defeat it; normalizing text before searching is a real step and it needs the variants to work from.
It needs the claimed publication dates and the date the content was discovered, which are usually different and the gap is frequently important. It needs the identity of the defendant if known, and if not, whether the account is believed to be operated by a competitor, a former employee, a customer or an unknown party — not because I will assume it, but because it determines which cheap tests are worth running first.
It does not need a theory of the case, and I would rather not have one before the collection. A threshold or a search chosen after the conclusion is known is not a method.
Records your own client already holds
This is the part of intake most often skipped, and it is the part where the client controls the outcome without needing anyone's permission.
- Web server access logs. No standard retention period exists and nothing preserves them by default; typical configurations rotate them away in weeks. They are also the one attribution-adjacent dataset the client owns outright, because anonymous posters visit the target's site before and after posting.
- Content delivery network logs, which are frequently the only place a client address appears at all where a site sits behind such a network.
- Analytics access and exports. User-level data expires on a window the account owner set and may have shortened, while aggregate reports can outlive the underlying event data.
- Search performance exports. The window is rolling and finite and measured in months. Export it now, export it monthly, and store the exports with hashes.
- Content management revisions. Where the disputed page is on a site the client or the defendant controls, the system's stored post revisions show wording at each save with a user and a time — and routine database cleanup destroys them.
- The client's own screenshots, however poor. They are the weakest form of evidence and sometimes the only record that content existed. Send them, with whatever the client can say about when and how they were taken.
How to send it
Format decisions made in the first week are difficult to reverse later.
Send native files, not printed copies. A document printed to PDF loses the properties that carry authorship information — the creator and last-modified-by fields, revision counts and editing time — which in matters where the statement began as a letter, a complaint or a dossier before it was posted are often the strongest authorship material in the file.
Send email as email. An original message file preserves headers and any cryptographic signature the sending domain applied. A forwarded copy, and especially a screenshot of a message, discards both.
Send images as files, not as chat attachments. One published evaluation of transfer methods found that direct transfer and email attachments retained all metadata fields, that sending a file in document mode through messaging applications also retained them, and that image or chat modes across the platforms tested retained roughly a sixth of the fields — effectively resolution only. The transfer mode matters more than the platform.
Do not crop, convert, annotate or clean up. Any of those changes the bytes. Derived exhibits are fine when they are documented as derived and the original is kept.
Avoid round trips through cloud sync, which rewrites modification times, and send a manifest listing what is in the package.
What makes a production readable, and what makes it expensive
When material arrives from the other side or from a platform, its structure decides how much of the budget goes to data handling rather than analysis.
Structured exports are cheap to work with: one file per account or per record class, machine-readable, with timestamps in a stated convention. Images of text are expensive, because every field has to be transcribed and every transcription is a place to be wrong. A platform archive delivered as a printed report of screenshots is the most expensive form of a production that was originally structured.
Timestamp conventions cause more trouble than any other single field. Platform exports mix absolute times, epoch integers and several different epochs, and mis-conversion is a repeated source of wrong chronologies. Where a production is being negotiated, specifying the export format and asking for times in a single stated convention costs nothing at the time and saves a great deal later.
Two things productions frequently do not contain, so expect them: a clean version-by-version history of edits, which most consumer platforms do not maintain in producible form, and anything about who read the content, which is not generally produced at per-viewer granularity and for most services is not kept that way for long.
What to ask the other side for, and what it returns
The framing that saves the most time is that two separate constraints govern what process returns. One is what the requester is entitled to reach. The other is whether the holder still has it. The second is knowable in advance and is the binding constraint in a large share of real matters.
On the account side, one major operator describes its basic tier as returning name, length of service, payment card information, email addresses and a recent login or logout address if available. Read the wording: recent, and singular. That is not a login history, and it is not necessarily the address used at the moment of the post, so a request that does not specify the post's timestamp and time zone will often produce something that cannot be used. The next tier is described as adding message headers and addresses, and content sits behind a further tier that a private litigant does not reach.
Items worth naming specifically because they are often omitted: the address associated with account registration, which is what links separate accounts to each other; the source port range assigned by a mobile carrier at the relevant instant, without which a shared address may resolve to nobody; deletion and moderation records, which are frequently the only proof that content once existed; and payment records, which are the one identifying field with an out-of-band verification step behind them.
The preservation demand, stated plainly
A preservation request is not process. It asks a holder to set a copy aside pending process, and the mechanics reported by the operators themselves are unglamorous.
Send it through the operator's own channel — the platforms operate legal request portals and one designates a registered agent for subpoenas — rather than to a general corporate address. Identify the account the way the platform identifies it, with the profile URL, the account identifier, the exact username and the permalinks. Then set out the classes of record sought instead of asking generally: the registration record and the address used at registration, session history with times, content and any edit history, deletion and moderation records, and payment records.
Then calendar the expiry. Where a window is 90 days and extendable on renewed request, the renewal is the requester's job and not the holder's. And note the asymmetry that catches civil litigants: the statutory preservation letter at 18 U.S.C. 2703(f) runs, by its terms, to a governmental entity. What a private party has instead is a request the provider may honor and a court order. Whether and how to obtain one is counsel's question, not mine.
Expect the account holder to learn of it. Several operators publish that they notify users of legal requests seeking their account information, and one publishes that it tries to give affected users a reasonable period to object before producing records.
What makes an engagement cheap
Summarizing the whole of the above as a sequence, because the sequence is the saving.
- Send the inventory and the fact frame first — URLs, live status, platform identifiers, dates with zones, identity strings. An hour of your time.
- Preserve on your own side immediately — server logs, delivery logs, analytics and search performance exports, content management revisions. None of it requires anyone's cooperation and all of it expires quietly.
- Establish who holds what, and what each holder publishes, before demanding anything. On pages read 15 August 2026, two of the five operators most often involved set out a 90-day window and three set out none.
- Collect what is still live, properly, with headers and hashes computed at collection and a contemporaneous log, and repeat the collection later where the content is dynamic.
- Write the question down before the analysis, including any threshold, so that the method is not a description of the answer.
Reversing steps two and three is the most common and most expensive mistake in this work. Skipping step five is the one that costs credibility rather than money.
What will not work
Six intake patterns that produce a weak file, listed so they can be avoided rather than corrected later.
- A folder of screenshots with no URLs and no dates. A screenshot with no address bar in frame carries a URL only as a caption, and a device clock is user-settable.
- A phone photograph of a screen as the sole record of an item that is still live and could be collected directly today.
- Forwarded email. Headers and any sending-domain signature are lost on the forward, and a screenshot of a message loses everything.
- Text pasted into a word processor. It preserves the words and destroys every property that made the source identifiable.
- An account described rather than identified. Platforms act on identifiers, not on descriptions.
- Asking for the opinion before the collection. If the conclusion is fixed before the method is written down, the method is not a method, and that is visible to anyone who reads the file carefully.
Frequently Asked Questions
What should counsel send an internet defamation expert first?
Five things, and they fit in one email: the URLs exactly as they appear with protocol and full path and nothing truncated; whether each item is still live and when it was last seen; the platform's own identifiers for the account, meaning the profile URL, the account identifier, the exact username and the post permalinks; the dates alleged with their time zones; and a note of what has already been demanded or produced. None of that requires a strategic decision and all of it changes the next step.Why do native files matter more than PDFs?
Because printing to PDF discards the properties that carry authorship information. Office documents store creator and last-modified-by fields, revision counts and total editing time; PDFs store producer and creation and modification dates, and incrementally saved files can retain prior revisions. Where an allegedly defamatory statement began as a letter, a complaint or a dossier before it was posted, those fields are frequently the strongest authorship material in the matter. A printed copy preserves the words and loses everything that made the file identifiable.Does sending an image through a messaging app destroy its metadata?
It depends on the transfer mode rather than the application. In one published evaluation, direct transfers and email attachments came through with every field intact and hashes unchanged, as did files sent in document mode through messaging applications; the same files sent in image or chat mode came back with roughly a sixth of their fields, effectively resolution only. The practical instruction is to send originals as files or attachments, never as chat images, and never as a photograph of a screen.What should a preservation demand to a platform name?
Record classes rather than a general instruction: registration record and registration address, login and session history with timestamps, content and any edit history, deletion and moderation records, and payment records. Send it through the operator's own legal request channel rather than to a corporate address, identify the account the way the platform does with the profile URL, account identifier, exact username and permalinks, and calendar the expiry, because where a window is extendable on renewed request the renewal is the requester's job.Why does a subpoena return often produce an address that cannot be used?
Because the wording of what platforms produce at the basic tier is narrower than it appears. One major operator describes that tier as returning a recent login or logout address if available — recent, and singular, not a history, and not necessarily the address used at the moment of the post. A request that does not specify the post timestamp with its time zone frequently returns an address from an unrelated session. Registration addresses and, for mobile connections, the source port range are the items most often left out.What should a client preserve before anyone is retained?
The records that expire without anyone touching them and that need nobody's permission: web server access logs, which have no standard retention period and rotate away in weeks by default; content delivery logs, which may be the only place a client address appears; analytics access and exports, which expire on a window the account owner set; search performance exports, whose window is rolling and measured in months; and content management system revisions, which routine database cleanup destroys. The client's own screenshots are worth keeping too, weak as they are.What makes a platform production expensive to work with?
Images of text, and mixed timestamp conventions. A structured export with one file per account or record class is cheap to analyze; a production delivered as printed screenshots forces every field to be transcribed and every transcription is a chance to be wrong. Timestamps cause more trouble than any other field, because exports mix absolute times, epoch integers and several different epochs, and mis-conversion is a repeated source of wrong chronologies. Specifying the format and a single time convention when a production is negotiated costs nothing then.Published