Who this is for, and the decision it is about
This page is written for counsel deciding whether to spend a client's money chasing a name. It is the least commercial page on this site by design, because the honest answer in a meaningful share of anonymous-poster matters is that nobody is going to be named, and the sooner that is known the less it costs to find out.
I am not an attorney and nothing here is advice about a claim. What follows is the technical triage: which failures are visible early, which are terminal, and what the records are still worth once a name is off the table. There is a version of this work that consists of billing through every available step and reporting at the end that the trail went cold. I would rather run the cheap tests first and tell you in the first week.
The chain, and which link is missing in your matter
Naming a poster requires five things to hold, and only four of them are records: the post has to be tied to an account or session; the account has to have registration details worth having; the platform has to have logged an address at the relevant moment; the carrier has to be able to map that address at that instant to a subscriber; and somebody has to connect that subscriber to a person.
Cases do not fail vaguely. They fail at a specific link, and which link is usually visible within a day of looking. A matter that fails at link three because the platform holds nothing for the relevant date is a different problem from one that fails at link four because the address is shared, and a completely different problem from one that fails at link five because the address resolves to an office with sixty people in it. The first two are terminal. The last is where discovery and ordinary witness testimony take over from anything technical.
The triage question I ask first is not who did it. It is: which link is missing, and is there any process that could still produce it?
The VPN case
If the poster used a commercial VPN or an anonymizing service, the address the platform logged belongs to the service, not to the poster. Geolocating it returns the exit server's location. The provider most commonly used for this publishes accuracy figures of roughly 80 percent at state or region level and about 66 percent for cities within a 50-kilometer radius; says a VPN geolocates to the VPN server rather than the user; and states in terms that its data is never precise enough to identify or locate a specific household, individual or street address. That last sentence disposes of most of what gets offered in this area.
What remains is process to the anonymizing service itself, and that is counsel's problem rather than a technical one. From a records point of view, the practical position is that a matter which arrives with a VPN address as its strongest artifact does not have an attribution case; it has a preservation case and possibly a pattern case. The exception worth checking, because it costs almost nothing, is whether the poster was consistent. People who use a VPN for the post often did not use one for the account registration, for a password reset, or for the visits to the target's own website before and after. Inconsistency is the whole game, and it is only visible if the records covering those other moments still exist.
The shared address case
An address can be logged, produced and useless. Home routers place an entire household behind one public address. Mobile and many broadband carriers place many unrelated subscribers behind a single public address at once using carrier-grade address translation; the standards body allocated a dedicated address block for that purpose, and the specification notes that services limiting simultaneous logins per public address break under it — another way of saying unrelated subscribers present the same address at the same moment.
The consequence for a subpoena return is direct. For a post made from a mobile connection, an address plus a timestamp may not resolve to one subscriber at all unless the carrier also logged the source port range assigned to that subscriber at that instant, and unless somebody asked for it. Asking for the source port is the most commonly omitted item in civil process to a carrier. Whether a given carrier logs and can produce it is a question to put to the carrier rather than an assumption to make about it.
Two mundane failures live here as well, and both are avoidable. A platform timestamp expressed in one zone matched against process specifying local time without an offset produces a lookup against the wrong window. And where a site sits behind a content delivery network, an origin server log records the network's address rather than any client at all unless the operator configured forwarded-address logging — which means the log you fought for may contain no client addresses.
The record that aged out
This is where most attribution attempts actually die, and the published picture is thinner than the commentary around it. Read on 15 August 2026:
| Holder | Published position |
|---|---|
| A large residential carrier's law enforcement guide, updated December 2024 | IP address logs retained for 180 days; information responsive to a preservation request retained 90 days, after which it may be deleted absent valid process or a 90-day extension |
| Meta | 90 days for account records in connection with official criminal investigations, pending formal legal process |
| X | 90 days as a temporary snapshot; IP logs stored for a very brief period, no figure published |
| Google, Reddit, Yelp | No preservation window and no log-retention period published on the pages read |
18 U.S.C. 2703(f) | 90 days plus one further 90 on renewal, available only to a governmental requester |
Three points follow that decide cases. By its terms the statutory mechanism is available only to a governmental requester, which leaves a private party with a voluntary request and a court order. Meta's guidelines condition retention for law enforcement purposes on a valid preservation request arriving before the user deleted the material, so a post taken down before anyone wrote to the platform is usually gone as a record and not only as a page. And for three widely litigated operators there is no published number at all — so if a number has been quoted to you for Google, Reddit or Yelp, it came from somewhere other than the operator.
Where the content is a year old and no preservation request was ever sent, the realistic expectation is that the address records that would have supported links three and four no longer exist. That is not a reason to stop working. It is a reason to stop working on attribution.
The account built to leave nothing
Every identifying field a consumer platform holds is self-asserted except one. A name is typed. An email address is free and disposable. A phone number can be a voice-over-IP line obtained in a couple of minutes. The single field with an out-of-band verification step behind it is the payment instrument.
So the honest expectation for a throwaway account that never bought anything is a subscriber record consisting of a display name, a disposable email address and, in the language one major operator uses for the basic tier, a recent login or logout address if available. Note the wording: recent, and singular. That is not a login history, and it is not necessarily the address used at the moment of the post. On a platform that publishes no retention figure, whether anything older exists is not knowable from outside.
The corollary is the most actionable thing in this subject. Where an account did buy something — a promotion, a subscription, a domain registration, a review package — the payment record is frequently the strongest identity link in the file, and it is production-only. Look for the transaction rather than the login. Where there was no transaction, and the address records have expired, and the account was operated behind an anonymizing service, there is no fifth link to reach and there is no fourth or third either.
What will not rescue a failed attribution
Each of these is offered regularly, and each fails on its own terms rather than on mine.
- Writing-style attribution of a short post. No published error rate exists at that length, and machine-assisted text has no accepted method at all. It supports exclusion more comfortably than identification.
- Geolocation presented as identification. The vendor's own documentation says the data cannot identify a household, an individual or a street address.
- A probability attached to timing overlap. No base rate for coincidental posting overlap has been published, so there is no denominator and the figure would not be a probability.
- An automated inauthenticity score. The published evaluation of the most used tool reported roughly four in ten flagged accounts were human at a common threshold.
- Browser fingerprinting. It is a collection technique, not an analysis technique; it produces evidence only where somebody was running fingerprinting code on a page the poster visited, which the defendant's page and the platform's page will not have been doing for the plaintiff's benefit.
- Open-source investigation offered as a substitute for process. Addresses, registration details, device identifiers and the platform's own linkage assessments are internal. An expert who says they traced someone from public signals alone should be asked which record they relied on.
What is still worth doing when nobody will be named
Losing the name does not empty the file. Several things stay valuable and several of them get more valuable, because they are what the matter will run on instead.
Fix the content and the date. A defensible collection of what was published, when, at what address, with response headers and hashes computed at collection, holds its value regardless of who wrote it. Content still live when you read this is content that can still be collected properly rather than reconstructed later from a client's phone screenshots.
Preserve the client's own logs. Anonymous posters visit the target's website before posting and repeatedly afterward to watch. Those requests sit in the plaintiff's own access logs with referrers, user-agent strings, timestamps and addresses, under the plaintiff's own control, needing nobody's permission — and they rotate away while everyone is looking at the post. The correlation runs only one way, and a visit is not authorship. It is still the cheapest attribution dataset in the matter and it is almost never preserved.
Document the pattern rather than the identity. A dated, scripted analysis of account creation timing, posting timing, shared errors, naming conventions, profile emptiness, review-history overlap and avatar reuse across platforms establishes that a pattern exists and describes how unlikely it looks under an independence assumption. It does not establish common control. Keeping those two claims apart is what makes the work usable.
Map the spread. Where content was copied, direction and common operation are tractable: canonical tags copied back to the origin, feed artifacts, assets still served from the origin, and shared account-scoped analytics or advertising identifiers across otherwise unconnected sites.
The negative finding is a deliverable
A dated record of what was checked and what returned nothing is worth writing down rather than discarding, for two reasons that have nothing to do with billing.
The first is that the file otherwise looks like nobody looked. A log showing that a URL returned a 404 on a given date is evidence; a log that quietly omits the attempt is a gap somebody else will find. The same is true of the account that had no public join date, the platform that published no retention figure on the date it was read, and the archive that held no capture for the relevant window.
The second is that at least one state has put into statute a requirement that a party seeking to unmask an anonymous communicator show that other reasonable efforts to identify them proved fruitless. Where a requirement like that applies — and whether it applies is for counsel — the technical investigator's product is not the name. It is the documented record that the cheaper routes were run and returned nothing.
What it costs to find out, and how I say no
The triage is deliberately front-loaded and deliberately cheap relative to the work that would follow it. It consists of establishing what is still live and collecting it; identifying which holder has each record class; checking what each holder publishes about preservation and retention, with the date read; and identifying which link in the chain is missing. None of that requires building anything, and all of it is reusable if the matter proceeds.
What makes an engagement expensive is the opposite order: collecting everything first, then discovering the records that would have completed the chain expired before anyone wrote to the holder. Scope drives cost here far more than volume does.
So the shape of the answer you should expect from me on a dead attribution is a short one, early, in writing, saying which link failed and why, what would have been required to save it and when that window closed, and what in the file is still worth doing. I cannot promise any outcome and I do not. What I can do is tell you which of these matters is not worth an expert, which is the advice that costs me a retention and is the reason the next call comes.
Frequently Asked Questions
How early can you tell whether an anonymous poster can be identified?
Usually within the first week, and often in a day. Identification requires five things to hold and only four of them are records: post to account, account to registration details, account to a logged address at the relevant time, address to subscriber, and subscriber to a person. Establishing which link is missing is a cheap exercise that involves checking what is still live, who holds each record class, and what each holder publishes about retention. That check is worth running before any collection work is scoped.Does a VPN end an attribution attempt?
For the address itself, effectively yes. The logged address belongs to the anonymizing service, and the most widely used geolocation provider states that a VPN geolocates to the VPN server rather than the user and that its data is never precise enough to identify a household, an individual or a street address. What is worth checking cheaply is consistency: people who used a service for the post often did not use it for registration, for a password reset, or when visiting the target's own website. Inconsistency is the opening, if the relevant records still exist.Why can a carrier subpoena return an address that identifies nobody?
Because addresses are shared. A household router puts a whole household behind one public address, and mobile and many broadband carriers place many unrelated subscribers behind a single address simultaneously using carrier-grade translation. A return can therefore name an address that belongs to hundreds of people at once. Unless the carrier logged the source port range assigned to a subscriber at that instant, and unless somebody asked for it, the record does not narrow to one account. That request is the item most often left out.How long do platforms keep the records that would identify a poster?
It depends on the operator and three major ones publish nothing. Read on 15 August 2026: Meta and X each publish a 90-day preservation window pending legal process, and the statutory preservation letter provides 90 days extendable by 90 but runs only to a governmental entity. Google, Reddit and Yelp published no preservation window and no log-retention period. A large residential carrier publishes 180 days for IP address logs. Any other figure quoted to you for those three operators did not come from the operator.If the post was already deleted, is the record gone too?
Often, and one operator addresses it directly. Meta conditions retention for law enforcement purposes on a valid preservation request arriving ahead of the user's own deletion. Where a post came down before anyone wrote to the platform, the account-side records that would have supported attribution are frequently gone too, not only the page. Material that has not yet come down can be collected directly instead of pieced together from screenshots afterward.What is worth doing when the poster will never be named?
Four things. Fix the content and the date with a defensible collection while the material is still reachable. Preserve the client's own web server access logs, which are the one attribution dataset nobody's permission is needed for and which rotate away by default. Document the behavioral pattern across accounts as a pattern, without claiming common control. And map the spread using direction-of-copying artifacts such as copied canonical tags, feed fingerprints, hotlinked assets and shared account-scoped analytics identifiers.Is a record of failed searches worth anything?
Yes, and it should be dated and kept. An attempt that returned nothing is itself a dated fact, and a file that silently omits the attempts looks like a file where nobody looked. Preserving negative results also matters where a forum requires a showing that other reasonable efforts to identify an anonymous communicator proved fruitless — at least one state has put that requirement in statute. Whether it applies to a given matter is a question for counsel, not for me.Published