Feature
Evidence Packs
Entitled alerts package the evidence actually captured, with timestamps plus explicit completeness and provenance for registrar, compliance, and legal review.
Last reviewed:
Full-page screenshot
Visual capture of the suspected page at the time of detection, timestamped and stored securely.
WHOIS / RDAP data
Registrar, creation date, nameservers, and registrant information where available.
DNS records
A, AAAA, MX, TXT, and NS records for the suspect domain.
HTTP headers & redirects
Full response headers, redirect chain, and final destination URL.
Certificate chain
SSL/TLS certificate details including issuer, validity, and Subject Alternative Names.
AI verdict & reasoning
Explainable risk assessment with specific indicators that triggered the alert.
Why evidence matters
For registrar takedowns
Registrars and hosting providers require specific evidence to act on abuse reports. A screenshot alone is not enough — they need WHOIS proof that the domain is not yours, evidence of malicious content, and clear documentation of the threat.
For compliance audits
NIS2, ISO 27001, and cyber-insurance questionnaires may require documented incident response. Evidence packs can support that record, but their completeness metadata and your response records determine what they actually demonstrate.
For legal review
If a threat escalates to legal action, contemporaneous evidence matters. Evidence packs preserve the source material captured at detection time and state when an artifact or byte digest is unavailable; legal sufficiency requires separate review.
Frequently asked questions
What is an evidence pack?
An evidence pack is the bundle of source material impersona.io captures for an entitled alert: full-page screenshots, WHOIS/RDAP data, DNS records, HTTP headers and redirects, the SSL/TLS certificate chain, and the AI verdict with its reasoning. Completeness and provenance metadata state what was actually captured and verified, so you know exactly what the pack does and does not contain.
What evidence do registrars need for a takedown request?
Registrars and hosting providers require specific evidence to act on abuse reports. A screenshot alone is not enough — they need WHOIS proof that the domain is not yours, evidence of malicious content, and clear documentation of the threat. Evidence packs assemble that material for each entitled alert so an abuse report can reference concrete, timestamped captures.
Can evidence packs be used in legal proceedings?
Evidence packs preserve the source material captured at detection time, with timestamps, and explicitly state when an artifact or byte digest is unavailable. That makes them useful contemporaneous documentation if a threat escalates, but legal sufficiency requires separate review — impersona.io does not provide legal services or file UDRP claims.
Do evidence packs help with compliance audits?
They can support the documented incident-response record that NIS2, ISO 27001, and cyber-insurance questionnaires may require. What a pack actually demonstrates is determined by its completeness metadata and your own response records — the pack is supporting material for that record, not the record itself.
When do I get access to full evidence packs?
Run a free brand check first, then verify domain ownership to claim the brand. Full evidence fields for detected threats require an active Starter+ plan, from €49/month. The free brand check shows a limited preview; the complete captures — screenshots, WHOIS/RDAP, DNS, HTTP, certificates, and verdict reasoning — unlock with the paid entitlement.
Get the evidence on threats targeting you
Run a free brand check, verify your domain to claim the brand, then activate Starter+ to access full evidence fields for detected threats.