Website representations

The provider asks for domain proof, but public registration details are private

Start with the exact ownership or control fact the provider requested, not with a public lookup result. Treat private registration data as neutral: it can hide the holder without proving either control or lack of control. Inventory only evidence produced through legitimate access, such as registrar account records, DNS or hosting administration, matching-domain contact, renewal records and provider-accepted website verification steps. Ask which form the provider accepts before sending anything, disclose the minimum needed and keep credentials out of every worksheet and public form. The provider decides whether the proof is accepted; this process only makes the evidence attributable and authorized.

For: An authorized representative of a research-only merchant whose provider asks for website ownership or control evidence while a public registration lookup is redacted, proxied or inconclusive.

Updated 2026-10-01

Name the precise fact under review

Copy the request and determine whether the provider is asking who owns the domain, who controls the website, whether the disclosed website matches the account, or whether the applicant can make an authorized change. Those are related but different facts. A registrar invoice may support payment or renewal history without proving current administrative control; a login screenshot may show access without proving that access is authorized for this business.

Record the domain exactly as requested, including subdomain or protocol if the provider named them, and the account the request concerns. If the request says website ownership verification but the dispute is really about a mismatched application URL, solve the mismatch first. Do not broaden the request into a demand for every domain record you hold.

Keep public privacy separate from evidence of control

ICANN's privacy and proxy materials describe arrangements that affect what registration contact or holder information is publicly shown. A redacted or proxied public record therefore does not answer who may log in, change DNS, renew the domain or approve transfer. It also does not create suspicion by itself; many legitimate registrations limit public contact display.

The wrong conclusion in both directions matters. Do not argue that privacy proves ownership, and do not let a reviewer imply that redaction proves concealment. State that public registration display is inconclusive for control, then move to evidence generated by authorized access. That keeps the response factual and avoids turning a privacy setting into an accusation or a defense.

Build a minimum-disclosure proof inventory

List candidate evidence by what it can establish: registrar account holder record for account custody, DNS or nameserver change capability for technical control, hosting and CMS administration for website control, matching-domain email for contact control, renewal receipts for continuity and dated domain purchase or transfer records for acquisition. Use document references and field labels rather than exposing full account numbers, authorization codes, passwords or personal identity details.

Prefer proof the provider names or accepts. Stripe's website ownership verification materials indicate that website-control evidence can be requested during account verification and that matching-domain contact or authorized website changes can be relevant. That is Stripe's process, not a universal checklist; another provider must name its own accepted evidence. No particular method is guaranteed acceptable until the provider confirms it for the actual request.

Use authorized controls without creating new exposure

Complete any requested verification step only through access your business is authorized to use. If a contractor holds the registrar account, obtain the authorized action or confirmation rather than borrowing credentials. If a matching-domain mailbox does not exist, record that gap instead of creating evidence after the fact and presenting it as historical. If a site change is requested, preserve the before state, the change published and the date it was live.

Send files only to the destination verified inside the provider account or documented support route. Keep public consultation messages limited to the website, the research-only products and a non-sensitive description of the proof problem. Prism can help organize that public description and the questions to ask; confirm scope, responsibilities, fees and terms before work. Prism does not receive registrar passwords, authorization codes or identity documents through its inquiry form.

Leave acceptance and custody as separate outcomes

After submission, record what was provided, through which channel, on what date and the provider's response. Distinguish proof accepted, more information required, method rejected and no reply. A receipt establishes delivery only. If the provider rejects the method, ask which accepted method remains rather than repeatedly sending stronger-looking versions of the same evidence.

Keep this verification answer separate from agency custody questions and from legal title. The sheet can show that a particular person could complete a control step on a date; it does not decide ownership law, transfer rights or whether the account is eligible. The provider owns acceptance of the evidence and any account decision that follows.

Provider-proof acceptance sheet

Use one sheet per domain and request. Record evidence references and the fact each can support. Never enter passwords, authorization codes, full account numbers, identity documents or bank details.

Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.

Provider-proof acceptance sheet. The last column is for temporary notes.
Record or checkDecision it supportsYour finding
Exact provider request, domain, account context and whether ownership, control or matching website is askedPrevents answering a control question with title evidence or a matching question with unrelated registrar history.
Public registration lookup result, including privacy or proxy display and lookup dateRecords that public display may be redacted and is not treated as proof for or against control.
Registrar account record and authorized custodian referenceIdentifies who can legitimately produce registrar evidence without exposing credentials.
DNS, nameserver, hosting or CMS administration evidence available through authorized accessShows technical or website control only to the extent the access is documented and authorized.
Matching-domain contact or provider-named website verification stepConnects the proof method to the provider's stated process rather than a guessed universal method.
Dated acquisition, renewal or transfer records with sensitive values held in restricted storageSupports chronology and continuity without deciding legal ownership from this worksheet.
Minimum disclosure package and verified destination confirmed before sendingLimits exposure and prevents use of an unverified portal, email thread or public form.
Provider outcome: accepted, more information required, method rejected or unansweredKeeps delivery separate from acceptance and names the next unresolved step.

These are temporary notes. Leaving or reloading this page may clear them. Worksheet entries are not sent automatically. If you copy notes into the consultation message and submit the form, Prism receives them as part of your request.

Limits

  • Public registration privacy is inconclusive: it does not prove ownership, disprove control or establish concealment.
  • Use only legitimate authorized access; never borrow registrar credentials, invent a mailbox or backdate a control step.
  • No proof method is universally accepted; the provider must confirm the method for the actual account and request.
  • This worksheet does not decide legal title, transfer rights, provider eligibility or account status.

Sources

  • ICANN: Privacy and proxy services — checked 2026-10-01. Privacy and proxy arrangements can affect public registration contact or holder information, so public display is distinct from evidence of control.
  • Stripe: Website ownership verification — checked 2026-10-01. Stripe may request website-control evidence during account verification and matching-domain contact or authorized website changes can be relevant; no particular evidence is guaranteed acceptable.
  • Prism contact — checked 2026-09-21. The inquiry form is for the website, products and question and excludes passwords, payment-card details and customer records; it is not a registrar or provider verification channel.

Request a website review

Want a second look at your own storefront pages?