ScreenshotNeo

BlogHow-to

How to Preserve Evidence of Internet Defamation

Save the post, its URL, context and related records before they disappear. Learn how to document what appeared online without mistaking a capture for proof of authorship or admissibility.

By the ScreenshotNeo team4 October 202611 min read

To preserve evidence of internet defamation, capture the post promptly, record its direct URL and the date and time with time zone, save enough surrounding context to identify the conversation, and retain original files and related messages. Keep an unchanged master copy and a separate working copy. A screenshot can document what appeared on a page, but it does not by itself prove who authored the words or guarantee that a court will admit the material. Preservation and admissibility rules vary by jurisdiction. If the dispute is urgent or high-stakes, speak promptly with a lawyer in the relevant jurisdiction.

This is practical preservation guidance, not a finding that a statement is defamatory or admissible. The cited procedure materials below are jurisdiction-specific: UK civil procedure and US federal evidence rules are examples, not universal rules.

What to save before a post is deleted

Make a record that another person can understand later. Preserve the visible statement and where it appeared, not just a cropped sentence.

  • The post or page: capture the entire statement, displayed account or publisher identity, and enough surrounding material to show the thread or page context.
  • The direct URL: save the address in your notes and, where practical, include the browser address bar in a screenshot.
  • When and how you captured it: record the date, time, time zone, device or software used, and the person who collected it.
  • Related material: retain replies, preceding and following posts, reposts, notifications, direct messages, emails, and attached photos, video, or documents that may help explain the publication.
  • Platform records: use the platform’s export or download feature when available, and keep the downloaded files in their original available formats.
  • A collection note: write down where each item came from and the steps used to save it. If the page changes or disappears, make another capture and note the change; do not replace the earlier file.

UK Practice Direction 31B defines electronic documents broadly. Its examples include email, texts, voicemail, files on devices and servers, deleted material, metadata, and embedded data. It says that once litigation is contemplated, legal representatives must notify clients of the need to preserve disclosable documents. Those are UK procedural materials, not a worldwide rule. UK Practice Direction 31B.

Step-by-step preservation workflow

  1. Open the original page and capture it promptly. Save one or more screenshots that show the statement, account or publisher identity, and surrounding context. If the post belongs to a thread, include enough preceding and following material to make the exchange understandable.
  2. Record the direct location and capture details. Copy the full URL into a plain-text note. Add the capture date and time, time zone, device or method, and collector’s name. If a page has no stable public URL, note the platform, account, post identifier if visible, and how you reached it.
  3. Save fuller records and original media. Download platform exports, attached files, and relevant communications where available. Keep the original formats. Do not edit, crop, annotate, recompress, or rename the only preserved copy. Make a separate working copy for highlighting, redaction, or explanation.
  4. Write a collection note for each item. A simple note can include an item number, source URL or platform location, capture date and time with time zone, collector, device or software, file name, and actions taken. Record any failed attempt or unusual page behavior instead of silently omitting it.
  5. Store an unchanged master and a backup. Limit access to people who need it, retain a separate backup, and keep relevant device or account data where appropriate. A removable drive can hold a copy, but storage media does not authenticate the contents or make them legally admissible.
  6. Preserve related data and avoid impulsive changes. Do not delete relevant messages, accounts, files, or notifications. Avoid replying in anger or reposting the allegation before you have preserved the material. Discuss legal next steps and any preservation request with counsel.
  7. Seek help if authenticity is disputed or stakes are high. A digital-evidence professional can advise on a collection and integrity process suited to the circumstances. Ask a lawyer in the relevant jurisdiction about procedure, deadlines, and how to handle any request or threatened claim.

Are screenshots enough?

Usually, a screenshot is a useful first record, but relying on it alone can leave gaps. It may omit a URL, date or time, thread context, recipients, metadata, or the original attached media. Keep it as part of a fuller record, alongside the page location, collection note, native files, platform downloads, and related communications when available. The ABA discusses ways screenshots can omit context and metadata in its article on social media evidence: Social Media Evidence.

No single screenshot format or capture method is prescribed by the supplied sources as universally sufficient. A screenshot, printout, web archive, or API capture may help preserve a record of what a page displayed; none should be described as automatically proving authorship or guaranteeing admission. Do not rely on an archive snapshot as your only record.

Choose a preservation method that fits the dispute

Method What it can preserve Limits and effort
Browser screenshot A quick visual record of visible content and context, if the capture includes them. Fast and low burden, but can omit URL, metadata, material outside the viewport, or original media.
Platform export or original download May retain fuller account, post, message, or media data in the format the platform makes available. Availability and contents depend on the platform; save the export unchanged and note how it was obtained.
Collection note plus copies and backup Documents who captured an item, where it came from, when, and how it was saved; provides a safer working arrangement. Requires careful recordkeeping and does not independently prove authorship or admissibility.
Professional digital-evidence collection Can provide a more carefully explained collection and integrity process when authenticity is disputed or the stakes justify it. Involves additional time and cost. Ask a qualified professional and local counsel what is proportionate.

Compare methods by the context they retain, whether they preserve original files and metadata, how clearly another person can understand the collection process, and their time, cost, and technical burden. No method guarantees admission.

Capture a page with Playwright

If you need a repeatable visual capture and are comfortable running Node.js, Playwright can save a full-page screenshot and a copy of the rendered page HTML. These are additional records of what the browser rendered; the HTML is not a complete archive of the original site, and the process does not establish who authored the content.

Install Node.js, then create a folder and install Playwright:

mkdir evidence-capture
cd evidence-capture
npm init -y
npm install playwright
npx playwright install chromium

Save this as capture.mjs. Pass the exact post URL as the first argument:

import { chromium } from 'playwright';
import { writeFile } from 'node:fs/promises';

const url = process.argv[2];
if (!url) {
  console.error('Usage: node capture.mjs <post-url>');
  process.exit(2);
}

const browser = await chromium.launch({ headless: true });
const page = await browser.newPage({ viewport: { width: 1440, height: 1000 } });

try {
  const response = await page.goto(url, {
    waitUntil: 'domcontentloaded',
    timeout: 30000,
  });

  // Record the final URL and response status alongside the captured files.
  const details = {
    requestedUrl: url,
    finalUrl: page.url(),
    status: response?.status() ?? null,
    capturedAt: new Date().toISOString(),
    viewport: { width: 1440, height: 1000 },
  };

  await page.screenshot({ path: 'page.png', fullPage: true });
  await writeFile('page.html', await page.content(), 'utf8');
  await writeFile('capture-note.json', JSON.stringify(details, null, 2));
  console.log(details);
} finally {
  await browser.close();
}

Run it with:

node capture.mjs 'https://example.com/path-to-post'

Replace the example with the direct post URL. Preserve the generated files as collected and make separate copies before annotating them. The script records the final URL and an ISO timestamp, but it does not certify the computer’s clock, capture hidden content, preserve all network responses, or prove authorship. A site may render differently in automation than in an ordinary browser, and login-gated material may require a lawful, carefully documented method. Take an ordinary visible screenshot too when it helps explain the page.

Or skip the browser setup

ScreenshotNeo is a website screenshot API and MCP server. A one-call capture can be a convenient additional visual record of a public page; keep your collection note and other source records as well. ScreenshotNeo removes cookie banners, popups, and chat widgets before the shot; bot checks, blank pages, and failed loads are never billed; its MCP server lets AI agents take screenshots; and 1,000 screenshots a month are free with no card, with paid plans starting at $5 for 3,000. See the ScreenshotNeo API documentation.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com/path-to-post -o shot.webp
import requests

url = "https://example.com/path-to-post"
r = requests.get(
    "https://api.screenshotneo.com/v1/shot",
    params={"access_key": "YOUR_API_KEY", "url": url},
    timeout=90,
)
r.raise_for_status()
with open("shot.webp", "wb") as f:
    f.write(r.content)
const target = 'https://example.com/path-to-post';
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: target });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot request failed: ${res.status}`);
const bytes = new Uint8Array(await res.arrayBuffer());
await (await import('node:fs/promises')).writeFile('shot.webp', bytes);

Replace the example URL with the page you need to document. Store the response alongside a note recording the requested URL, capture time and time zone, collector, and method. A service capture documents page appearance; it does not establish the poster’s identity or guarantee legal admissibility. Create a free ScreenshotNeo account for 1,000 screenshots a month with no card.

What a capture can and cannot establish

A capture can help show that particular words and page details appeared at a location when the record was made. The displayed username or account name is not, by itself, proof of the real person’s identity or authorship. Proving who posted material and satisfying admissibility requirements are separate questions that depend on the evidence and the applicable law.

As a US example, Federal Rule of Evidence 902 addresses self-authentication for certain records and electronic processes. Authentication does not settle hearsay, relevance, authorship, or every other objection. Consult the current US Federal Rules of Evidence and a lawyer about the rules that apply to your case.

In the UK, the Pre-Action Protocol for Media and Communications Claims applies to specified claims, including defamation and certain claims arising from online or social-media publication. It encourages early information exchange and resolution. It is a UK procedure source and should not be generalized to other jurisdictions.

Common problems and fixes

Problem Why it matters What to do
The screenshot cuts off the account name or thread. A cropped fragment can be hard to place in context. Capture the page again with the identity and surrounding exchange visible. Keep both captures and note when each was made.
The URL is missing or the post is hard to find again. A picture alone may not show where the content appeared. Copy the direct URL into a collection note. If there is no stable URL, record the platform, account, post identifier if shown, and navigation steps.
The post changed or disappeared. A later capture cannot replace the earlier state. Keep the earlier file, make a new capture if possible, note the difference and timing, and retain notifications, replies, exports, or downloaded media.
The page needs a login or displays different content. An automated or logged-out view may not match what a visitor saw. Use an authorized account and a lawful method. Record whether you were logged in, what browser or tool you used, and any access limitations. Do not bypass access controls.
A capture tool produces a blank page or a loading error. The site may require additional rendering time, scripts, or human interaction; a failed capture is not evidence of the missing content. Try a manual browser capture, wait for the relevant content to load, and record the failure and retry. Do not present a failed or blank capture as showing the post.
The file was edited, compressed, or annotated. Changes can make it harder to explain what was collected originally. Retain the original unchanged if available. Label edits as working copies and document the changes.
You do not know whether the displayed account belongs to the person you suspect. Page appearance does not by itself establish real-world identity or authorship. Preserve platform records and related communications, and ask counsel how to address attribution and any formal evidence requirements.
You are unsure which deadline applies. Deadlines depend on jurisdiction and claim circumstances. Get prompt advice from a lawyer in the relevant jurisdiction. Do not rely on a general online checklist to calculate a limitation period.

Reliability, privacy, and cost considerations

  • Reliability: Capture promptly and keep the method explainable. A second capture, source export, original media, or contemporaneous notification can help fill gaps, but none guarantees authenticity or admissibility.
  • Integrity: Keep an unchanged master, separate working copies, and a backup. Restrict access and record any transfer or editing. Do not claim that a file hash or storage device alone proves who created a post.
  • Privacy: Preserve only material relevant to the issue and store it securely. Threads and exports can contain other people’s personal information; seek local advice before sharing or publishing them.
  • Cost: A manual screenshot and written note have little technical overhead. Platform exports may take time and may not be available in the needed form. Professional collection adds cost, so consider it when authenticity is disputed or the stakes justify a more formal process.
  • Screenshot API usage: ScreenshotNeo’s listed plans are Free: 1,000 shots/month with no card; Starter: $5 for 3,000; Growth: $15 for 15,000; Pro: $39 for 60,000; Scale: $99 for 250,000; Business: $249 for 1,000,000. Yearly billing gives two months free, and every feature is on every plan. Use a screenshot API as a capture aid, not as a legal certification.

Frequently asked questions

Should I contact the platform before saving the post?

Preserve what is currently available first if you can do so safely and lawfully. A lawyer can advise whether and how to contact the platform or another party in your circumstances.

Can I prove who posted it with a screenshot?

A screenshot can record the displayed account and page. It does not, by itself, establish who controlled that account or authored the words. Attribution may require other records and legal analysis.

Should I post my evidence publicly?

Do not assume public posting is a safe preservation step. Keep records securely and ask counsel about any response, publication, or takedown request.

Is a web archive enough?

No single archive should be your only record. Save your own capture, URL, collection note, and available native files or platform records too. Recognition of archive snapshots depends on the applicable rules and circumstances.

Does this checklist guarantee the court will accept the evidence?

No. It helps create and preserve a clearer record, but admissibility and the weight of evidence depend on jurisdiction, procedure, and the facts of the dispute.

Sources and jurisdiction note

This guide draws on UK Practice Direction 31B for electronic documents and preservation, the UK Pre-Action Protocol for Media and Communications Claims, the US Federal Rules of Evidence Rule 902, and the ABA’s discussion of screenshot limitations. These sources illustrate specific procedures; they do not establish one worldwide evidence rule. Rules can change, so check the current official materials and get advice in the relevant jurisdiction, especially where a deadline or litigation is involved.