Knowledge

How Brands Build Court-Ready Evidence From Online Counterfeit Listings

Finding a counterfeit listing is easy. Proving it later is not. How to capture, hash, timestamp and preserve listing evidence that holds up in court.

Chris Collins

Chris Collins

September 25, 2026 · 11 min read

Brand protection teams find counterfeit listings every day. The hard part comes later, when a listing has been taken down, a seller disputes a takedown, or a case reaches court and someone asks a simple question: how do you know this page said what you say it said, on the date you say, to buyers in this country?

A screenshot saved to a shared drive rarely answers that well. This guide covers what makes online evidence hold up, the capture package every listing should get, how to add cryptographic integrity and trusted timestamps, and how to keep a chain of custody from discovery to filing. It builds on detection, which is covered in how to detect counterfeit listings across global marketplaces; this is about what happens after you find one.

Key takeaways

  • Evidence has to show three things: what the page said, that your copy has not changed since, and the circumstances of capture, including where and when.
  • A widely used standard for open-source investigations treats the URL, the HTML source and a full-page capture as a minimum for evidence intended for court.
  • Hash every file at the moment of capture, and get a trusted timestamp on the record. Both are cheap and both are hard to argue with.
  • Capture from the market that matters. Whether a listing was offered to buyers in a specific country is often the point in dispute.
  • Record custody from the start. Who captured, stored, accessed and transferred each item is part of the evidence.

What makes online evidence hold up

Rules of evidence differ by country, and this is not legal advice, but the underlying questions are consistent.

Authenticity. Is the item what you claim it is? In the United States, the Federal Rules of Evidence require the party offering an item to produce evidence sufficient to support a finding that it is what they claim. For web captures, that usually means showing how the capture was made and that the method produces an accurate result.

Integrity. Has it changed since capture? This is where hashing matters. The committee note to the US rule on certified copies of electronic data explains the logic directly: “identical hash values for the original and copy reliably attest to the fact that they are exact duplicates.” The same rules also allow certain electronic records to be authenticated by a certification from a qualified person rather than live testimony, including data “authenticated by a process of digital identification”, such as a hash.

Context. When, where and by whom was it captured? The Berkeley Protocol on Digital Open Source Investigations, published by the UN Human Rights Office and the Human Rights Center at UC Berkeley, sets out practice used by investigators preparing evidence for courts. It lists what to collect with online content and states that the first three items, the URL, the HTML source code and a full-page capture, “serve as a minimum standard for providing evidence in court.” It also calls for recording who collected the item, the IP address of the machine used, a timestamp from a synchronised clock and a hash value at the point of collection.

Marketplace takedowns are less formal than court, but the same package makes them faster and harder to dispute.

The capture package

Every listing you may act on should get the same record, captured in one pass and never edited afterwards.

ItemWhy it matters
Listing URL and final URL after redirectsIdentifies exactly what was captured
Marketplace item and seller identifiersSurvive changes to titles and URLs
Full-page screenshotWhat a buyer saw, including price, images and seller details
HTML sourceThe underlying content, searchable and harder to dispute than an image
Product images as filesOften the clearest evidence of copying
Seller profile pageLinks the listing to an operator, and to their other listings
Price, currency and shipping destinations offeredShows the offer was made to buyers in your jurisdiction
Capture time in UTC, from a synchronised clockEstablishes when
Vantage point: country, network, IPEstablishes where the offer was visible
Collector identity and tool versionEstablishes who and how
SHA-256 hash of every fileProves the files have not changed
Trusted timestamp on the manifestProves the record existed at that time

The vantage point deserves emphasis. Marketplaces show different listings, prices and shipping options by country, and many counterfeit sellers restrict where they ship. Courts care about this too: a standard temporary restraining order template used by one judge in the Northern District of Illinois for counterfeit cases refers to “screenshot evidence confirming that each Defendant internet store does stand ready, willing and able to ship its counterfeit goods to customers in Illinois.” If your case depends on buyers in a particular place, capture from that place. Shifter’s residential gateway takes the country in the username, and a session id keeps the whole capture on one IP, so the screenshot, the HTML and the recorded vantage point all describe the same visit. Why this matters well beyond counterfeits is set out in the vantage-point standard.

Automating the capture

A capture should be one repeatable operation, so every listing gets the same treatment and your method can be described in a sentence. This script loads a page through a country-targeted residential exit, records the vantage point through the same session, saves the HTML and a full-page screenshot, and writes a manifest with a hash for each file:

import { chromium } from 'playwright';
import { createHash, randomUUID } from 'node:crypto';
import fs from 'node:fs';
import path from 'node:path';

const sha256 = buf => createHash('sha256').update(buf).digest('hex');

export async function capture(url, country, outDir) {
  const id = randomUUID();
  const dir = path.join(outDir, id);
  fs.mkdirSync(dir, { recursive: true });
  const username = `${process.env.SHIFTER_PROXY_USER}-country-${country}-sid-${id.slice(0, 8)}-ttl-600`;
  const browser = await chromium.launch({
    proxy: { server: 'http://p.shifter.io:443', username, password: process.env.SHIFTER_PROXY_PASS },
  });
  const page = await browser.newPage({ viewport: { width: 1366, height: 900 } });

  // Record the vantage point through the same session as the capture.
  await page.goto('http://ip-info.com/json');
  const vantage = JSON.parse(await page.evaluate(() => document.body.innerText));

  const response = await page.goto(url, { waitUntil: 'networkidle', timeout: 90000 });
  const files = {
    'page.html': Buffer.from(await page.content()),
    'page.png': await page.screenshot({ fullPage: true }),
  };
  await browser.close();

  const manifest = {
    capture_id: id,
    url,
    final_url: response.url(),
    http_status: response.status(),
    captured_at_utc: new Date().toISOString(),
    vantage: { country: vantage.country, city: vantage.city, ip: vantage.ip, asn: vantage.asn, network: vantage.as_name },
    files: {},
  };
  for (const [name, buf] of Object.entries(files)) {
    fs.writeFileSync(path.join(dir, name), buf);
    manifest.files[name] = { sha256: sha256(buf), bytes: buf.length };
  }
  fs.writeFileSync(path.join(dir, 'manifest.json'), JSON.stringify(manifest, null, 2));
  return manifest;
}

Extend it for marketplace specifics: save each product image as a file, capture the seller’s profile page in the same session, and record item and seller identifiers in the manifest. Make sure the machine’s clock is synchronised, since the manifest time is only as good as the clock that wrote it.

Check what you captured before relying on it. Marketplaces sometimes serve challenge pages or stripped-down pages to automated browsers with a normal success status, which is the problem described in the silent failure rate. A human glance at the screenshot before the record is sealed catches it.

Add a trusted timestamp

Your own manifest says when you captured the page, but it is your word. A trusted timestamp from an independent Time-Stamping Authority adds proof that the manifest, and therefore every file hash it contains, existed at a specific moment. The protocol is RFC 3161, supported by standard tools, and only the hash leaves your machine, never the content:

openssl ts -query -data manifest.json -sha256 -cert -out manifest.tsq
curl -s -H "Content-Type: application/timestamp-query" \
  --data-binary @manifest.tsq https://your-tsa.example/tsr -o manifest.tsr
openssl ts -verify -data manifest.json -in manifest.tsr \
  -CAfile tsa-ca.pem -untrusted tsa.crt

Keep the request, the reply and the authority’s certificates with the capture. For higher-stakes matters, counsel may prefer a qualified timestamping provider recognised in the relevant jurisdiction.

For archiving whole pages with every resource they loaded, the WARC format, standardised as ISO 28500 and used by web archives, preserves the full HTTP exchange. It is a useful addition for important captures, though the HTML, screenshot and manifest above are usually enough for marketplace enforcement.

Keep a chain of custody

The Berkeley Protocol defines chain of custody as “the chronological documentation of the sequence of custodians of a piece of information or evidence”, including its control, transfer, analysis and disposition. In practice:

  • Store captures in write-once storage, such as an object store with retention locks, so files cannot be altered or deleted during the retention period.
  • Log every access and transfer: who opened a capture, who exported it, and to whom it was sent.
  • Never edit originals. Annotated copies for reports are fine; keep them separate and record which original each one derives from.
  • Re-verify hashes when evidence moves, and record that you did.

Test purchases

A screenshot shows an offer. A test purchase shows what was actually sold and shipped, and it is often the decisive piece of evidence that a product is counterfeit rather than grey-market or genuine. Test purchases have legal and practical sensitivities, from payment trails to how the item is handled on arrival, so arrange them with counsel. Document the whole transaction: the listing capture at the time of purchase, the order confirmation, payment records, shipping labels and tracking, photographs of the parcel unopened and opened, and the examination that establishes the item is not genuine.

From evidence to action

A good capture package makes every enforcement route faster.

  • Marketplace programmes. Brand protection programmes are generally restricted to rights owners and their representatives. Amazon Brand Registry requires “an active registered trademark or a pending trademark registration” from an approved office, and eBay’s VeRO programme is “only for rights owners or their authorized representatives.” Each has its own reporting form; a consistent capture package means you can fill any of them quickly.
  • Notices under the EU Digital Services Act. A notice to a hosting service about illegal content should include a substantiated explanation of why it is illegal, the exact location such as the URL, the notifier’s name and email address, and a statement that the notifier believes in good faith that the notice is accurate and complete. Notices from trusted flaggers, a status awarded to qualifying organisations, are given priority.
  • Litigation and customs. Here the full package matters most: authenticated captures, hashes, timestamps, custody records and test purchase evidence, prepared with counsel.

Patterns across listings, such as the same images, the same seller details or the same shipping origin across marketplaces, are often what turns a series of takedowns into one coordinated case. The collection side of that analysis is covered in trademark abuse detection and monitoring unauthorised sellers.

Collect responsibly

Evidence gathered improperly can hurt a case. Capture public listings only, do not access accounts or areas you have no right to be in, pace your collection, and keep personal data about individual sellers to what the case genuinely needs. When the approach is new or the stakes are high, agree the method with counsel before you start, not after.

The bottom line

Finding counterfeit listings is a detection problem. Proving them is an evidence problem, and it is solved at the moment of capture, not later. Capture the URL, the HTML and a full-page image in one pass, from the market that matters, with the vantage point and time recorded. Hash every file, get a trusted timestamp on the manifest, store it where it cannot be altered, and log who touches it. None of this is expensive, and all of it is very hard to reconstruct once a listing has gone.

Sources and references

This article is general information, not legal advice. Consult counsel about evidence requirements in your jurisdiction.

Ready to get started?

Try Shifter's residential proxies, 205M+ IPs, 195+ countries, from $0.10/GB.

Get Started