Guide
The complete guide to documenting online harassment as evidence
Learn what counts as evidence, how to capture it platform by platform, and how to build a chronology a lawyer can actually use.
Key takeaways
- Preserve first, judge later. Capture material before deciding whether it matters, because deletion and edits are often permanent and cannot be undone later.
- A usable evidence file needs more than a screenshot: the source URL, a capture timestamp, account context, and a record of how the material was collected.
- Organize captures into a dated chronology, not a folder of files. The sequence is what turns isolated incidents into a visible pattern.
- Hashing and timestamping do not decide legal questions. They support an inspectable, tamper-evident record that a lawyer can review with confidence.
- Hand off observations and your own conclusions separately. Label what you observed, what you were told, and what you are inferring, and let counsel apply the legal analysis.
What counts as evidence of online harassment?
Definition
Online harassment evidence is any record, with intact source context, that shows what happened, when, where it happened, and who was involved.
That includes posts, comments, direct messages, profile states, platform reports, and the metadata around each of them. A cropped screenshot with no URL or date is a claim about what happened. The same screenshot with its source link, capture time, and account context attached is a record someone else can check.
The distinction matters because harassment rarely lives in one post. It is usually a pattern: a comment here, a fake account there, a direct message a week later, a repost of something you thought was deleted. Evidence work is the discipline of capturing each piece with enough context that, laid side by side later, the pattern becomes visible to someone who was not there when it happened, including a lawyer meeting your case for the first time.
Definition
A "captured record" is a screenshot or file plus its source URL, capture timestamp, and a note on how it was collected. A screenshot alone, without those three things, is a claim rather than a record.
This guide walks through what to capture, how to capture it across the platforms where harassment typically happens, what the underlying technical concepts (timestamps, metadata, hashes) actually mean, and how to turn scattered captures into a chronology a lawyer can use.
Why does preserving first matter more than judging first?
Online material is unusually volatile. Posts get deleted by the person who wrote them once they draw attention. Accounts get renamed or suspended. Platforms remove content through their own moderation process. Reposts and quote-posts strip away the context that connects a piece of content to its original source. Each of these events can happen within hours of publication, and each one permanently reduces what you or a lawyer can later establish.
The practical answer is to preserve first and decide relevance later. Capturing something that turns out not to matter costs you a few minutes. A missing capture, once the source is gone, cannot be recreated. This is why the workflow below leads with capture steps before it gets to organizing or judging the material.
Key point
If you are unsure whether something matters, capture it anyway. You can discard captures later; you cannot go back and capture something that has already disappeared.
This does not mean documenting everything indiscriminately. It means treating capture as a low-cost, reversible action and treating deletion or "cleaning up later" as an irreversible one. When in doubt, the file gets bigger, not smaller.
What should you capture, platform by platform?
The core capture habit is the same everywhere: full-page screenshot or recording, source URL, timestamp, and account context. But each platform has quirks that change what is worth grabbing and how quickly it disappears.
Instagram and Facebook
Meta platforms allow full-page screenshots of posts, comments, and profiles, and both apps let you request a copy of your own account data, including messages you have sent or received. For harassment on these platforms:
- Screenshot the post or comment uncropped, including the account handle, timestamp, and the surrounding comment thread.
- Screenshot the offending account's profile: bio, follower count, and any visible link, since impersonation and harassment accounts often edit these within days.
- Save story content immediately. Stories typically expire within 24 hours and rarely leave a public trace afterward.
- For direct messages, screenshot the full thread with visible sender names and timestamps, not just the message you are reporting.
- Use the platform's own data-download feature where relevant, and keep it alongside your manual captures rather than as a replacement for them.
X (formerly Twitter)
- Capture the post with its permalink URL (the individual post URL, not the profile feed), the visible timestamp, and the reply count at capture time.
- Screenshot quote-posts and reposts separately, each with its own URL. A quote-post is a distinct piece of content with its own audience and its own evidentiary value.
- If an account is suspended or a post is removed, a prior capture is often the only record left. There is no reliable way to retrieve deleted posts after the fact.
TikTok
- Screenshot or screen-record the video itself, plus the caption, sound credit, and comment section, since context often lives in the caption and top comments rather than the clip alone.
- Screen recordings capture more than static screenshots for video content: they preserve the audio, on-screen text timing, and any effects that a still frame would miss.
- Duets and stitches build on an original video and often outlive it. Capture both the original and any duet or stitch that reuses it, with separate source URLs.
Direct messages and private chat apps
- Screenshot the full conversation thread, not an isolated message, so the context before and after is visible.
- Where the app supports it, export the conversation as a file rather than relying on screenshots alone; this preserves timestamps in a form that is harder to dispute.
- Note which device and account captured the thread, since this becomes part of the custody record if the material is later questioned.
Anonymous or pseudonymous accounts
- Capture everything about the account as it currently exists: handle, display name, avatar, bio, and posting pattern, since anonymous accounts are frequently renamed or deleted after drawing attention.
- Record any details that might connect the account to a real identity later: writing style, shared images, cross-posted content, or timing patterns. Note these as observations, not conclusions; connecting an anonymous account to a person is an inference that belongs to a later stage of review, not to the capture itself.
- If the same account (or an account you suspect is connected) appears on multiple platforms, capture each instance separately with its own source and timestamp.
For a structured, repeatable version of this workflow across all of these platforms, see the online-harm evidence pack checklist.
What do metadata, timestamps, and hashes actually mean?
These three words come up constantly in evidence work, and they are simpler than they sound.
Metadata is data about the data: the account that posted something, when it was posted, what device or app produced a file, and similar details attached to the content itself rather than visible in it. A screenshot loses most of this unless you separately record it. That is why capturing the visible timestamp and account handle in the same frame as the content matters: it keeps a piece of metadata attached to the record instead of losing it.
Timestamps record when something happened, but "when" splits into several distinct moments that are easy to conflate: when the post was published (the platform-visible time), when you captured it (your capture time), and when a lawyer or reviewer later looks at it (review time). Keeping these separate, and recording which clock and time zone you used, is what makes a timestamp useful rather than misleading later.
Definition
A SHA-256 hash is a fixed digital fingerprint of a file. If even one bit of the file changes, the hash changes completely. Recording a hash at the moment you capture a file lets anyone later verify that the file they are looking at is exactly the file that was captured, unaltered.
A hash does not prove a post was true, who wrote it, or that a legal threshold has been met. It proves one specific thing: that the file has not been silently changed since the hash was recorded. Combined with a timestamp and a source URL, it gives a lawyer a way to trust that what they are reviewing is what actually existed at the time you captured it, which is the foundation of a tamper-evident record.
How do you build a chronology a lawyer can use?
A folder of screenshots answers one question reliably: did something happen? It fails at every other question a lawyer will ask, including when, in what order, and how each piece connects to the others. A chronology answers those questions by turning individual captures into a dated sequence.
A working chronology needs, for each entry:
- A date and time, in a consistent format and time zone.
- A short, factual description of what happened, written without interpretation.
- The source URL or platform where it happened.
- A reference to the capture file (a file name or evidence ID) so anyone reading the chronology can find the underlying record.
- A label for the basis of the entry: observed directly in the capture, reported by you or someone else, or inferred from a pattern.
"The account posted a threatening comment on 3 March (observed in capture EF-014)" is a different class of statement than "I believe the same person runs both accounts (inferred from posting times and writing style)." Mixing these without labels is one of the fastest ways to lose a reviewer's confidence in the whole file. Keep them visibly separate, entry by entry.
Once the chronology exists, gaps become visible too: a week with no captures, an unexplained jump between platforms, a period where you remember something happening but did not capture it. Mark those gaps explicitly rather than filling them from memory. A gap a reviewer finds on their own is more damaging to the file's credibility than a gap you flagged yourself.
Caution
Resist the urge to write the chronology as a narrative of what you believe happened. Write it as a dated list of what the captures show, with your own account kept in a clearly separate section.
When and how should you hand the file to a lawyer?
There is no single trigger point for involving a lawyer. Some people bring in counsel after the first serious threat; others wait until a pattern is well established or an escalation forces the issue. What consistently helps, whenever that moment comes, is arriving with an organized file rather than an unsorted collection of screenshots.
A handoff that is useful to a lawyer typically includes:
- A short summary of who is involved, what kind of conduct is alleged, and the date range covered.
- The chronology described above, in date order, with each entry linked to a capture.
- The capture files themselves, organized and named consistently, ideally with hashes recorded where you were able to compute them.
- A note on what has already been reported to platforms or authorities, and what response, if any, you received.
- A clear separation between what you observed and captured, and what you believe or suspect. Let the lawyer draw their own conclusions from the factual record.
If your situation involves credible threats to physical safety, treat that as urgent and separate from the evidence-organizing process described here. Evidence preservation supports a later legal or platform response; it is not a substitute for an immediate safety response where one is needed.
For a walkthrough of how a law firm actually processes incoming material like this, see turning screenshots into evidence files and for law firms. If you are documenting this on your own before involving anyone else, for individuals covers where to start.
What mistakes weaken a harassment evidence file?
Most of the weaknesses in self-collected evidence repeat across cases, and nearly all of them are avoidable at the point of capture.
- Cropped screenshots that cut off the URL bar, timestamp, or surrounding thread. A cropped image looks cleaner but removes exactly the context a reviewer needs.
- Screenshots of screenshots, forwarded through a chat app, which strip out whatever metadata the original file carried.
- No record of when a capture was made. A screenshot without a documented date is a claim, not a record.
- Deleting material you decide is "irrelevant." Relevance is a judgment for a later reviewer, not something to decide at capture time.
- Blending your account of events with what the captures actually show, without labeling which is which.
- Waiting to capture until the harassment escalates. By the time something feels serious enough to document, earlier material has often already disappeared.
None of these mistakes are unusual or a sign you did something wrong. They are simply the default failure modes of collecting evidence under stress, without a system. The point of the chain of custody for online evidence reference and the workflow above is to replace ad hoc collection with a small set of habits that hold up under scrutiny.
Where this fits with cyberstalking and threat cases specifically
Harassment sometimes escalates into cyberstalking or credible threats, where the pattern across time and the connections between accounts matter as much as any single incident. If your situation has moved in that direction, the cyberstalking and threat evidence workflow covers the additional steps that pattern-based cases need, including tracking related accounts and documenting escalation over time.
Frequently asked questions
What counts as evidence of online harassment?
Anything that shows what was said or done, when, and by whom. Posts, messages, profile states, and the surrounding context all count. A single screenshot is a starting point; a usable evidence file adds the source URL, a capture timestamp, and a record of how the material was collected.
Do I need special software to preserve online harassment?
No. A full-page screenshot or screen recording, saved with the source URL and the date, is a reasonable starting point. What matters most is capturing material before it changes or disappears, then keeping the originals unedited and organized by date.
Should I delete harassing messages after reporting them to a platform?
No. Keep the original message, thread, and any reply, along with your platform report and its outcome. Deleting material, even after reporting it, removes a record a lawyer or reviewer may need later, and platform reports rarely include a copy of what was actually reported.
How soon should I involve a lawyer?
There is no fixed point, but preserving material early means you have something useful whenever you do. Many people build a chronology first and bring it to a lawyer once a pattern is clear, an escalation happens, or they simply want to understand their options.
Will screenshots hold up if this goes to court?
Courts and platforms decide case by case, and no evidence type is guaranteed to be accepted. Well-preserved material, with an intact source URL, timestamp, and custody record, is consistently more useful to counsel than a bare screenshot with none of that context.
References