ProofSnap logo ProofSnap Get ProofSnap

United States courts · Authentication

FRE 901: what a court actually requires to authenticate a screenshot

Federal Rule of Evidence 901(a) requires the proponent to "produce evidence sufficient to support a finding that the item is what the proponent claims it is." For a screenshot that means evidence beyond the image: when it was captured, from what URL, and by what process. ProofSnap records all of that automatically. Who captured it is the one part no software supplies, because that is your witness or your declarant.

This page covers the three Rule 901(b) routes courts accept for a screenshot, why a bare screenshot collapses the moment fabrication is raised, how Maryland, Texas, and Pennsylvania split on social media, the limits of authentication, and where Rule 901 hands off to self-authentication under Rules 902(13) and 902(14).

By Radim Motycka · Last reviewed August 25, 2026 · Rule text verified against the Federal Rules of Evidence as published by Cornell's Legal Information Institute

What Rule 901(a) actually requires

Rule 901(a) is one sentence, and reading it carefully saves a great deal of argument:

"To satisfy the requirement of authenticating or identifying an item of evidence, the proponent must produce evidence sufficient to support a finding that the item is what the proponent claims it is."

Federal Rule of Evidence 901(a). Cornell Legal Information Institute

Two things follow. First, the bar is low. The judge is not deciding whether the screenshot is genuine. Under the conditional relevance standard of Rule 104(b), the judge asks only whether a reasonable juror could find that it is. Authenticity itself is for the jury, and the opponent's contrary evidence goes to weight. The proponent does not have to prove authenticity beyond a reasonable doubt or by clear and convincing evidence.

Second, the rule says produce evidence. Not produce the item. The image is the thing being authenticated; it cannot authenticate itself. A screenshot offered with nothing around it asks the court to accept its own assertion, which is exactly what the rule declines to do. Everything below is about what that surrounding evidence looks like.

The three routes for a screenshot

Rule 901(b) lists ten illustrations, not an exhaustive list. Three of them do nearly all the work for a screenshot, and a strong foundation usually rests on more than one.

Illustration Rule text What it looks like Where it breaks
901(b)(1)
Testimony of a witness with knowledge
"Testimony that an item is what it is claimed to be." The person who took the screenshot testifies to what they saw on the screen and that the image fairly reflects it. Necessary but thin on its own. It proves what the witness believes, not that the page was unaltered or that the file has not changed since.
901(b)(4)
Distinctive characteristics
"The appearance, contents, substance, internal patterns, or other distinctive characteristics of the item, taken together with all the circumstances." Content only the purported author would know, a nickname, writing style, a reply chain, a reference to a contemporaneous event, a phone number or address tied to a party. The workhorse for digital evidence, and the illustration courts rely on most. It is circumstantial, so it is only as strong as the specifics you can point to.
901(b)(9)
Process or system
"Evidence describing a process or system and showing that it produces an accurate result." A description of the capture method and why it is reliable: what it recorded, how files were hashed, what it changed on the page and disclosed. Requires a process worth describing. A tool that outputs only an image gives the witness nothing beyond the tool's name.

Rule text quoted verbatim from Federal Rule of Evidence 901(b). The illustrations are examples, not requirements: 901(b) introduces them as "examples only, not a complete list, of evidence that satisfies the requirement."

Why a bare screenshot fails once fabrication is raised

Screenshots get admitted every day. Usually that is because nobody objected, or the other side conceded the content, or a witness filled the gap. None of those is a plan. The moment an opponent says the image was edited, a bare screenshot has a specific structural problem: it contains no evidence of its own origin.

A screenshot is a picture of a screen. It does not carry the URL it came from, the time it was taken, the HTTP response the server actually sent, the account it was viewed under, or any value that would change if a pixel were edited afterward. Cropping, retouching and outright fabrication all leave the file looking exactly like a real screenshot, because a real screenshot has nothing in it to disturb.

That is why courts keep returning to the same question, how do we know where this came from, and why the strongest foundations pair a witness with a record the tool generated rather than the witness. What follows is what opponents attack, in the order they usually raise it.

  1. It is not from where you say it is. No URL, no domain resolution, no server response inside the image.
  2. It was not taken when you say it was. A file timestamp is metadata anyone can set.
  3. It was edited after capture. Nothing in the image would show it.
  4. Your client made it. The fabrication argument, and the one a bare image cannot answer at all.
  5. Somebody else wrote the post. A separate problem from authenticity, and the one Pennsylvania singled out. See the state split.

Maryland, Texas, and Pennsylvania do not agree

Most disputes are not in federal court, and state courts have split on whether social media deserves a stricter standard than other documentary evidence. Worse, the split is usually described from a 2011 snapshot that two of the three states have since moved past. The current position in each:

Started strict, then moved

Maryland

Griffin v. State, 419 Md. 343 (2011) held that a "printout of an image from such a site requires a greater degree of authentication than merely identifying the date of birth of the creator and her visage in a photograph on the site in order to reflect that Ms. Barber was its creator and the author of the 'snitches get stitches' language." It pointed to three routes: testimony from the author, examination of the purported author's device, or information obtained from the platform.

Do not stop at Griffin. Sublet v. State, 442 Md. 632, 113 A.3d 695 (2015) adopted the reasonable-juror test, expressly elucidating and implementing Griffin rather than discarding it, and Mooney v. State, 487 Md. 701 (2024) applied that standard again in the Supreme Court of Maryland, as the Court of Appeals has been named since December 2022. A Maryland practitioner cites Sublet first in 2026. And the third Griffin route is narrower than it sounds: under 18 U.S.C. 2702 a Rule 45 subpoena is not an exception to the Stored Communications Act, so a provider generally will not hand over private content in a civil case. Whether content the user configured as public sits outside that bar at all, and on what theory, is unsettled and litigated case by case. Either way it is the content you could have captured yourself, which is the practical answer to the third route.

Ordinary standard

Texas

Tienda v. State, 358 S.W.3d 633 (Tex. Crim. App. Feb. 8, 2012). The court applied the ordinary standard and found the circumstantial evidence sufficient to "support a finding that the exhibits were what they purported to be", which is the language of Rule 901(a) itself.

What carried it: photographs of the defendant on the pages, a reference to the author wearing an ankle monitor while the defendant wore one, nicknames and email addresses matching his, the city he lived in, his gang, and references to the victim's death and funeral. Circumstantial, cumulative, and enough. The fabrication risk went to weight.

Ownership is not authorship

Pennsylvania

Commonwealth v. Mangel, 181 A.3d 1154 (Pa. Super. Ct. Mar. 15, 2018). An account bearing the defendant's name, hometown, and high school was not enough. In the court's words:

"[T]he proponent of social media evidence must present direct or circumstantial evidence that tends to corroborate the identity of the author of the communication in question, such as testimony from the person who sent or received the communication, or contextual clues in the communication tending to reveal the identity of the sender."

Cite the rule, not just the case. Pennsylvania codified this at Pa.R.E. 901(b)(11), adopted May 20, 2020 and effective October 1, 2020, which allows authorship to be shown by identifying content, or by proof of ownership, possession, control, or access to the account "when corroborated by circumstances indicating authorship." The comment cites Mangel directly.

Before any of this, there is a cheaper move the explainers skip: serve a request for admission on genuineness under FRCP 36(a)(1)(B), early. Either you get the admission and the fight is over, or you get the objection on paper months before trial and can build the foundation around it instead of discovering the problem at the podium.

Otherwise the practical consequence is the same in all three: build the foundation the strictest likely forum would want, because you can always use less of it. A capture that records the URL, the time, the server response, and a hash of every file satisfies Texas trivially, gives Maryland a process to examine, and leaves Pennsylvania's authorship question exactly where it belongs, as a separate question you answer with different evidence.

The federal baseline: resemblance is not a foundation

United States v. Vayner, 769 F.3d 125 (2d Cir. 2014)

A printout of a social media profile was admitted on the theory that it resembled the defendant's. The Second Circuit vacated the conviction and remanded for a new trial. For a screenshot specifically, the lesson is that the things visible inside the image, a name, a photograph, a hometown, are the weakest possible foundation, because they are exactly what anyone fabricating the image would put there. Maryland cited Vayner when it adopted the reasonable-juror test in Sublet, which is how a federal case ends up governing a state courtroom.

How far these citations were checked

Case names, reporter citations, courts, and filing dates were verified against the CourtListener opinion database: Griffin at 419 Md. 343, 19 A.3d 415, filed April 28, 2011; Tienda at 358 S.W.3d 633, filed February 8, 2012; and Mangel at 181 A.3d 1154, filed March 15, 2018. Every passage shown here in quotation marks was matched as an exact string against the text of the opinion itself in that database, not taken from a secondary summary, and the same was done for the language of Pa.R.E. 901(b)(11).

Treat this page as a map, not as authority. Shepardize or KeyCite before any of it goes into a filing. Authentication law for social media has moved steadily since 2011 and continues to move, and a case that was good law when this page was written may since have been distinguished, limited, or overruled.

A foundation script for the 901(b)(9) witness

Rule 901(b)(9) asks for evidence describing a process and showing that it produces an accurate result. In practice that is a short direct examination. Below is the outline, with the artifact each answer points to, so the witness is reading from the record rather than from memory. Print it, hand it to whoever ran the capture, and have them check every answer against the package before the hearing.

  1. 1. "What is your role, and how do you know how this system works?"

    Establishes the qualified person. Points to: their own job, and how often they run captures.

  2. 2. "Describe what the software did, step by step."

    The heart of 901(b)(9). Points to: forensic_log.json, which lists each operation in order.

  3. 3. "How do we know this file is the one that was captured?"

    Points to: the SHA-256 value in manifest.json, and the fact that opposing counsel can recompute it.

  4. 4. "Did the software change anything on the page?"

    Ask it on direct, before the other side does. Points to: the layout disclosure in chain_of_custody.json.

  5. 5. "How do you know the time is right?"

    Points to: the NTP consensus block, which records how many independent time sources agreed and by what margin.

The four cross questions, and where the answer lives

What they ask What the witness reaches for
"You could have edited this afterward."The hash was computed at capture and is recorded in a manifest signed with a key generated for that capture. Recompute it.
"That is your browser, not the page."Correct, and the record says so: the HTTP response headers and the DNS resolution are in metadata.json.
"The tool altered the page."It did, and it wrote down what and how much. Read the disclosure aloud.
"You do not know what the software really did."The log is hash-chained, so a removed or altered entry is detectable. This is the question to have rehearsed.

This outline is a starting point for counsel to adapt, not a form to file. The witness must be able to answer every question from their own knowledge, because a script recited without understanding is what the fourth cross question is designed to expose.

What authentication does not do

Authentication answers exactly one question: whether the item is what the proponent says it is. Four things it does not answer, and each has ended a case where counsel assumed otherwise.

It does not answer hearsay

An authenticated post is still an out-of-court statement if offered for its truth. Authentication and the hearsay rules are separate hurdles, cleared separately, in that order.

It does not establish relevance

A genuine screenshot of an irrelevant page is still excluded, and Rule 403 still applies once it is in.

It does not prove authorship

Proving the page existed as captured is not proving who wrote it. That is the whole holding of Mangel, and it needs its own evidence.

It does not prove the content is true

A hash shows a file has not changed since the hash was computed. It says nothing about whether what the page claims is accurate.

Rule 901 or Rule 902(13) and 902(14)?

Rule 901 is the general route and it ordinarily needs a witness. Rules 902(13) and 902(14), added in December 2017, are the self-authenticating shortcut over the same ground: a written certification by a qualified person replaces the live testimony, subject to a pretrial notice requirement. They are alternatives, not opposites.

Which one you use is a tactical choice, and the answer is often both. Serving a certification puts the burden of going forward on the opponent, and if they do not object in time no authenticating witness is needed at trial. If the certification is challenged, the proponent falls back on a witness describing the very same process under Rule 901(b)(9). A capture documented well enough for one supports the other, which is the practical reason to document it once and properly.

Our companion page covers the certification route in full: what a Rule 902(13) and 902(14) certification must say, the notice requirement both subsections impose, why software cannot be the declarant, and the declaration template that ProofSnap prefills with every capture.

Proposed Rule 901(c) and the deepfake objection

The deepfake objection exists today. The rule does not. Opposing counsel can already argue that any image could be AI-generated, and nothing has to change for that argument to be made in your next hearing.

Proposed Rule 901(c) would shift the burden in that fight: the challenger would have to produce evidence sufficient to support a finding of fabrication, and only then would the proponent have to show authenticity by a preponderance. It is a working draft, it has never been published for public comment, and the Advisory Committee carried it as an information item on May 7, 2026 while scheduling a mini-conference for fall 2026. The February 16, 2026 comment deadline that commentators keep attaching to it belongs to proposed Rule 707, not to this rule, and anyone telling you to prepare for a December 2027 rule is claiming more than the record supports.

Either way the answer is the one Rule 901(b)(9) already gives: a capture whose process can be described and tested. A record made at the time, by a method somebody can explain, is what a fabrication argument runs into.

The three situations you are actually in

Everything above is the law. Which route is open to you depends on something more mundane: whether the page still exists, and who took the picture. There are three cases, and only one of them is the easy one.

Situation 1

The page is still up

Capture it yourself, today, before anything else happens to it. This is the only situation where you get the full record: the URL, the server's own response headers, the DNS answers, the hash values, and a description of the process a witness can testify to under 901(b)(9). A Glassdoor review, a LinkedIn post, a marketplace listing and a public comment thread can all be deleted by their author at any moment, and no tool can capture a page retroactively. If the exhibit matters to the case, the cheapest hour you will ever spend on it is the one before it disappears.

Situation 2

The page is gone and your client has a screenshot from months ago

This is the most common situation in practice and the one most tools ignore. You cannot manufacture a capture record that never existed, and you should not try. What you can do is fix the custody record from the moment the file reached you, which is a different and honest claim.

File certification hashes the file your client gave you, records when it came into your custody, signs the result and anchors it, and produces its own evidence package and PDF. It proves the JPEG has not been altered since that date. It does not prove the page looked that way, and the PDF says so.

Your authentication route is then 901(b)(1), the client's own testimony that they took it, supported by 901(b)(4) distinctive characteristics, with the certification answering the separate question of whether anything changed after the fact. Combine it with an early FRCP 36 request for admission on genuineness. Every plan includes file certifications, starting with three in a $4.99 SnapPack.

Situation 3

The evidence is a text message thread on a phone

Be clear about the limit: ProofSnap is a browser extension, and a browser cannot photograph an iPhone or an Android handset. SMS, iMessage and WhatsApp threads that live only on a device are outside what it captures directly. Two things it does cover: a web client of a messaging service open in the browser, such as WhatsApp Web, Telegram Web, Messenger, Slack or Discord, is captured like any other page; and a screenshot or export already taken off the phone can be run through file certification as in Situation 2. For the phone itself, the answer is a forensic extraction by an examiner, not a capture tool.

What a documented capture gives the witness

Rule 901(b)(9) turns on evidence describing a process or system and showing that it produces an accurate result. The value of a capture tool under that illustration is the record it leaves behind, not the picture it produces. A witness cannot describe a process that left no trace.

A ProofSnap capture writes 11 to 15 files depending on plan, and every one of them is a fact a witness can state and an opponent can test:

What was on the screen

  • Full-page rendered screenshot
  • Page source with stylesheets inlined
  • Extracted text content as rendered

Where it came from

  • Source URL and capture times
  • HTTP response headers from the server
  • Domain resolved against two independent DNS resolvers

That it has not changed

  • SHA-256 value for every file, in a signed manifest
  • RSA-4096 signature over that manifest
  • Verification scripts that re-check it all offline

What the tool itself did

  • Chain of custody along ISO/IEC 27037 lines
  • Every page change disclosed, cookie banners included
  • Any incomplete capture recorded, not hidden

The fourth group, what the tool itself did, is the one lawyers underrate. A capture tool that quietly hides a cookie banner and says nothing gives opposing counsel a line of cross-examination. A tool that records the change lets the witness answer it in one sentence.

What does that look like in practice? In a ProofSnap capture of a single news article taken on August 25, 2026, the manifest carried 32 SHA-256 values, 17 of them for images embedded in the page, each hash recorded with the file's byte length. The count scales with what the page actually contains, which is the point: the witness reads from a list the page dictated, not from a number the vendor chose. A hash in that manifest is only useful if the other side can recompute it. They can, in a browser, with our free SHA-256 hash checker.

What ProofSnap looks like

A side panel in the browser you already use

There is no desktop client to install and no separate portal to log into. You open the page you need on the record, open the ProofSnap side panel, and press Capture. The capture runs on your own machine, so a page behind your own login is recorded as you see it, which matters because that is the version the dispute is usually about.

  • One click produces the whole record, not just the image
  • Nothing about the page is sent to a server to be rendered
  • The ZIP opens with any archiver, in any decade
The ProofSnap side panel open in Chrome next to a web page, showing the capture button, video recording and the Trust Verifier

ProofSnap side panel, English interface

The record a Rule 901(b)(9) witness reads from

This is the difference the whole page turns on. On the left is what an opponent attacks, a picture with nothing behind it. On the right is what the same capture also wrote, and every line of it is a sentence a witness can say on the stand and an opponent can go and check.

A bare screenshot

No URL. No time. No server response. No value that changes if a pixel is edited. Everything the witness could say about it is what the witness remembers.

The same capture, in manifest.json and chain_of_custody.json

capture_id ps_e41dffe2-eda0-4652-bf04-76bfcd1f3ff4

url https://www.arabnews.com/node/2655769/middle-east

captured_at 2026-08-25T06:53:54.954Z

hash_algorithm SHA-256

files hashed 32 (17 of them page images)

screenshot.jpeg  bf4117...fcb851

page.html       ec8486...b1d9fe

metadata.json   76b387...7173a6

dns_verification

sources_queried 2  sources_agreed 2

all_ips_match true  status verified

ntp_verification

sources_agreed 3  consensus_offset 82 ms

layout_modifications (disclosed, not hidden)

fixed_hidden 7  headers 6  footers 1

Real values from a ProofSnap capture of a news article taken on August 25, 2026, abridged and with hashes shortened. The full manifest lists all 32.

See a finished document from that same capture

The Rule 902 declaration ProofSnap wrote from this capture is four pages, including every hash value in the list above. Read it before you decide whether the record is one you would put a name on. No download and no account required.

Read more about what that document is and is not on the Rule 902(13) and 902(14) page.

Look at the last two lines. The capture hid seven fixed elements, six of them headers, in order to photograph the whole page, and it wrote that down. A tool that made the same change silently would have left the witness with nothing to say when opposing counsel pulls up the live page and asks why the exhibit looks different. Disclosure is not an admission against interest here. It is the thing that makes the rest of the record credible.

Pricing

Every plan produces the full record described above. The differences are volume, the Bitcoin anchor, the eIDAS qualified timestamp, and branding.

All plans include a 7-day trial. A credit card is required at sign-up. Cancel anytime. Billed in USD.

One matter

SnapPack

$4.99

one-time, $0.50 per capture

  • 10 web captures
  • 3 file certifications for screenshots you already have
  • Rule 902 certification included
  • Bitcoin OpenTimestamps anchor
  • No subscription, and nothing renews

Essential

$8.99

per month

  • 100 captures per month
  • 11-file evidence package
  • SHA-256 and RSA-4096 signature
  • Rule 902 certification needs a paid credit

Professional

$16.99

per month

  • 200 captures per month
  • 12-file evidence package
  • Rule 902 certification included
  • Bitcoin anchor and C2PA Content Credentials

Enterprise

$28.99

per month

  • Unlimited captures
  • 15-file evidence package
  • Rule 902 certification included
  • White-label PDF, plus eIDAS qualified timestamps for EU-facing matters

Working as a team? Company is $18.99 per seat per month, minimum two seats and no upper limit, with the same 15-file package, eIDAS qualified timestamps and white-label branding as Enterprise, plus shared member management.

What this costs against an hour of your time

A capture in a SnapPack costs 50 cents, and a capture on Essential costs about 9 cents. Set that against what an excluded exhibit costs: the motion it was supporting, the hours spent finding a substitute, and the client conversation about why the evidence they gave you did not come in. The per-capture price is not the decision. Whether the exhibit survives a fabrication challenge is.

How a firm usually buys this

Most firms do not need a seat per lawyer. Captures are usually run by whoever handles evidence intake, so one paralegal seat plus a backup covers a small firm's entire capture workload, which is the two-seat Company minimum at $37.98 a month. Buy a SnapPack first for one matter, see the package that comes out of it, and move to seats only once someone is capturing weekly. For invoicing, annual billing, or a W-9, write to support@getproofsnap.com before you buy.

Frequently asked questions

What does Rule 901 require to authenticate a screenshot?+

Rule 901(a) requires the proponent to produce evidence sufficient to support a finding that the item is what the proponent claims it is. That is a low bar and it is not proof: the judge does not decide whether the screenshot is genuine, only whether a reasonable juror could find that it is. The proponent does not have to prove authenticity beyond a reasonable doubt or by clear and convincing evidence. What the bar does require is some evidence beyond the image itself, because an image asserts its own authenticity and nothing more.

Is a screenshot admissible in court on its own?+

Rarely, and never once authenticity is actually contested. A screenshot is a picture of a screen. It carries no record of where it came from, when it was taken, or whether the pixels were edited afterward, and every one of those is trivial to fake. Courts admit screenshots all the time, but usually because nobody objected, or because a witness testified to what they saw, or because the surrounding circumstances supplied the missing link. Once an opponent raises fabrication, the screenshot alone gives the court nothing to weigh.

What is the difference between Rule 901 and Rule 902(13) or 902(14)?+

Rule 901 is the general route: the proponent produces evidence, usually a witness, sufficient to support a finding of authenticity. Rules 902(13) and 902(14) are the self-authenticating shortcut over the same ground, replacing live testimony with a written certification by a qualified person, subject to a pretrial notice requirement. They are alternatives, not opposites. A well-documented capture supports both, which matters because if a certification is challenged the proponent falls back on a witness describing the same process under Rule 901(b)(9).

Who testifies if the other side challenges the capture software itself?+

Your own witness, and the package is built so that no vendor employee has to appear. Rule 901(b)(9) asks for evidence describing a process and showing that it produces an accurate result, and every fact that witness needs is written into the package rather than held by ProofSnap: the forensic log records each operation in a SHA-256 hash chain, so a removed or altered entry is detectable, and the chain of custody discloses every change made to the page in order to capture it. The verification scripts shipped in the package re-check every hash and the manifest signature offline, on any machine, using standard tools. That means the opponent can test the claim themselves instead of taking anyone's word for it, which is the point of proving a process rather than vouching for a product.

Do state courts apply the same standard to social media screenshots?+

No, and this is the trap for anyone working from the federal rule alone. Maryland is the state cited most often and cited wrong most often: Griffin v. State (2011) held that a printout from a social networking site requires a greater degree of authentication, but Sublet v. State (2015) then adopted the reasonable-juror test and Mooney v. State (2024) applied it again, so a Maryland practitioner cites Sublet first, not Griffin. The Texas Court of Criminal Appeals applied the ordinary standard in Tienda v. State, asking only whether a jury could reasonably find the evidence authentic. The Pennsylvania Superior Court held in Commonwealth v. Mangel that an account bearing the defendant's name, hometown, and high school was not enough, because ownership of an account is not authorship of a post, and Pennsylvania then codified the point in Pa.R.E. 901(b)(11). Check the forum before you plan the foundation, and check separately whether your state has adopted an analog to Federal Rules 902(13) and 902(14), because many states have not.

Does authenticating a screenshot make it admissible?+

No. Authentication answers one question only: is this what you say it is. It does not answer a hearsay objection, it does not establish relevance, and it does not prove who wrote or posted the content. The Pennsylvania rule in Mangel is the clearest statement of the last point: proving an account belongs to someone is not proving they wrote the post. Treating authentication as a general admissibility ticket is the most common way the argument is lost.

What is proposed Rule 901(c) and does it exist yet?+

It does not exist yet, and it has not even been published for public comment. Proposed Rule 901(c) would address evidence challenged as fabricated by generative artificial intelligence: the party making the challenge would have to present evidence sufficient to support a finding of fabrication, and if they met that burden it would shift to the proponent to show by a preponderance of the evidence that the item is authentic. The Advisory Committee on Evidence Rules carried the working draft as an information item at its meeting on May 7, 2026, to be held in abeyance, and scheduled a mini-conference on it for fall 2026. The February 16, 2026 comment deadline often attached to Rule 901(c) belongs to proposed Rule 707, not to this rule.

My client took the screenshot months ago and the page is now deleted. Can anything be done?+

Yes, but be precise about what it proves. No tool can capture a page retroactively, so you cannot produce a capture record that never existed. File certification hashes the file your client gave you, records when it entered your custody, signs the result and anchors it, and produces its own evidence package and PDF. That proves the image has not been altered since that date. It does not prove the page looked that way, and the PDF says so. Your authentication route is then Rule 901(b)(1), your client's own testimony that they took it, supported by Rule 901(b)(4) distinctive characteristics, with the certification answering the separate question of whether anything changed afterward. Serve an early FRCP 36(a)(1)(B) request for admission on genuineness as well. File certifications are included in every plan, starting with three in a 4.99 dollar SnapPack.

Can ProofSnap capture text messages from a phone?+

Not directly. ProofSnap is a browser extension, and a browser cannot photograph an iPhone or an Android handset, so SMS and iMessage threads that live only on a device are outside what it captures. Two things it does cover. A web client of a messaging service open in the browser is captured like any other page, which includes WhatsApp Web, Telegram Web, Messenger, Slack and Discord. And a screenshot or export already taken off the phone can be run through file certification, which hashes it and fixes the custody record from the date it reached you. For the device itself the answer is a forensic extraction by an examiner, not a capture tool.

What happens to my evidence package if ProofSnap stops operating?+

Nothing about verifying the package requires ProofSnap to exist. The package is an ordinary ZIP file that opens with any archiver. Inside it, the hash values are SHA-256 and SHA-512, the signature is RSA-4096 over manifest.json with the public key included as publickey.pem, and the verification scripts shipped in the package re-check all of it offline using standard command line tools. The OpenTimestamps anchor is recorded in the Bitcoin blockchain and is verifiable by anyone against that chain, independently of any company. Download the ZIP and it stays verifiable on your own machine for as long as you keep it.

Give the witness something to describe

A screenshot carries no evidence of its own origin. A documented capture records the URL, the time, the server response, and a hash of every file, which is what Rule 901(b)(9) asks a witness to describe.

SnapPack from $4.99 for 10 captures, one-time, no auto-renewal. The 7-day trial requires a credit card at sign-up.

Get ProofSnap, SnapPack from $4.99