Lawyerd · Free tool · Evidence Snapshot

Preserve that page before it disappears.

Paste the address of the infringing page. In about two minutes an evidence package lands in your inbox: full-page screenshot, page source, SHA-256 hashes, who hosts it, an Internet Archive snapshot and a Bitcoin-anchored timestamp. Screenshots get deleted and disputed — packages get preserved.

Nothing to wait for on this page — the package is delivered to your email, usually within ~2 minutes.

Free for rights holders — 3 captures a day, 10 a month. The capture runs from Lawyerd's infrastructure; nothing is sent to the site owner. Your details stay with Lawyerd.

What lands in your inbox

One email, one ZIP, seven artifacts — each hashed with SHA-256 at capture time, so any of them can later be proven byte-identical to what was captured.

report.pdf
Human-readable capture report — the file you forward to management or counsel.
screenshot.png
Full-page screenshot of the rendered page, exactly as a visitor saw it.
raw.html + rendered.html
The source as the server sent it, and the DOM after scripts ran.
headers.json
Every HTTP response header — server, redirects, status.
manifest.json
The machine-readable record: URLs, times (UTC), IPs, host, registrar, domain age, and the SHA-256 of every file.
proof.ots
OpenTimestamps proof anchoring the manifest hash in the Bitcoin blockchain.
Wayback snapshot
An independent Internet Archive capture requested in parallel — third-party corroboration.

How the capture works

The pipeline fetches the page twice: once as raw HTTP (the source exactly as the server sent it, plus every response header) and once in a headless browser that renders scripts and takes the full-page screenshot. In parallel it records the network context — DNS records, the hosting provider and its abuse contact, the registrar and the domain's registration date (for scam pages, "this domain is 12 days old" is half the case) — and asks the Internet Archive for an independent snapshot of the same page.

Every artifact is hashed with SHA-256. The hashes, URLs, timestamps and network data go into a manifest, and the manifest's own hash is anchored in the Bitcoin blockchain through OpenTimestamps — a public, vendor-independent proof of when the record existed. The email delivery adds one more independent layer: the message's DKIM signature and server timestamps in your own mailbox.

Pages behind logins or paywalls are not captured — the report says so honestly instead of shipping an empty screenshot. Captures run for lawful preservation purposes only; every capture is reviewed.

Will it hold up?

Honest answer: web evidence lives or dies on authentication, and rules differ by jurisdiction. This package is engineered for exactly that fight.

A bare screenshot is trivially challenged — no provable time, no provable integrity. This package answers both challenges with cryptography and independent third parties, and under frameworks like US FRE 902(13)–(14) records of this kind can be self-authenticating with a proper certification. When a dispute demands a human voice behind the procedure, Lawyerd counsel provides a signed declaration describing how this exact capture was made — the step that decided cases like Weinhoffer v. Davie Shoring.

Full jurisdiction-by-jurisdiction breakdown — US FRE 901/902, eIDAS, Ukraine & CIS practice, and the six properties that make a capture defensible: are screenshots admissible in court? →

The package is a forensic-grade preservation record, not a notarial act or a guarantee of admissibility — see the disclaimer inside every report.

Questions people ask before preserving

How do I save a web page as evidence?
Do not rely on a plain screenshot from your phone — it proves little. Use a capture that records the page content, the exact time (from independent sources), the server that hosted it, and cryptographic hashes that prove nothing was edited afterwards. This tool does all of that automatically: paste the URL above and the package arrives in your inbox in about two minutes.
Are screenshots admissible in court?
Often yes, but admissibility turns on authentication — can you show when the capture was made and that it was not altered? Rules differ by jurisdiction (e.g. US FRE 901 and 902(13)–(14) allow self-authenticating electronic records with a proper certification). A screenshot with SHA-256 hashes, independent timestamps and a documented capture procedure is dramatically easier to authenticate than a bare image; where needed, Lawyerd counsel can add a signed declaration describing the procedure.
Why is a plain screenshot not enough?
Anyone can edit a screenshot in a minute, and the other side knows it. A bare image carries no capture time you can prove, no record of which server delivered the content, and no way to show it was not altered. Evidence-grade preservation adds exactly those layers: independent timestamps, network context and cryptographic hashes fixed at capture time.
What exactly is in the evidence package?
A branded PDF report; a full-page screenshot (PNG); the raw page source as served and the browser-rendered HTML; all HTTP response headers; DNS records, hosting provider and abuse contact, registrar and domain registration date at capture time; an Internet Archive (Wayback Machine) snapshot request; a manifest.json with SHA-256 hashes of every file; and an OpenTimestamps proof anchoring the manifest hash in the Bitcoin blockchain. Delivered by email with download links valid for 90 days.
What is a SHA-256 hash and why does it matter for evidence?
A SHA-256 hash is a cryptographic fingerprint: change a single byte of the file and the fingerprint changes completely. Because your package records the hash of every artifact at capture time — and anchors the record itself in the Bitcoin blockchain via OpenTimestamps — anyone can later verify that the screenshot or HTML you present is byte-identical to what was captured, and when.
Is the Wayback Machine enough as legal evidence?
On its own, often not: in Weinhoffer v. Davie Shoring (5th Cir. 2022) an archive.org page was ruled inadmissible for lack of authentication. Wayback snapshots are strongest as one layer of a package that also carries hashes, capture metadata and a person who can describe the procedure. This tool requests a Wayback snapshot alongside its own capture, so the two corroborate each other.
Can it capture pages behind a login or paywall?
No — the capture browser visits the page like a logged-out visitor, and we say so honestly in the report instead of shipping a blank screenshot. For content behind logins, geo-walls or aggressive bot protection, request a manual preservation by counsel — reply to any package email or use the contact form.
How much does it cost?
The tool is free for rights holders: up to 3 captures per day and 10 per month per email address. Counsel services on top of it — signed declarations of the capture procedure, takedown notices to the host, tracked removal — are engagements with Lawyerd.

Preserved. Now remove it.

Fixing the evidence is step one — the package even tells you who hosts the content and where their abuse mailbox is. Step two is a notice under the right statute, followed up until the content is actually gone. That is Lawyerd's core practice.

Have counsel handle the takedown

Related free tool: abuse-contact lookup — find the hosting provider behind any site and the email your complaint should go to.