Methodology · Continuity

How we measure continuity

The strongest evidence that a website is what it claims to be is that it has quietly been the same thing for years. AboutUs measures that from a WHOIS and DNS snapshot archive reaching back to 2007 — one an adversary cannot buy into and cannot retroactively rewrite, because we hold it. The only way to earn continuity is to keep the same infrastructure, in our record, for years.

Not all stability is equal

“Same for ten years” means very different things depending on what stayed the same. Each stable value earns credit proportional to three things: how long it has held (tenure), how densely our archive actually confirms that (a value seen in eighty snapshots is stronger than one seen twice a decade apart), and how much identity the value carries. A dedicated server IP is distinctive; a shared CDN address is not. A named company is distinctive; a privacy proxy is not. We weight accordingly.

The lines we track

Each with its own distinctiveness weight

Stable valueIdentity weightWhy it is weighted that way
Registrant organizationNamed org 1.00 · named individual 0.85 · privacy service 0.35A named organization holding a domain for a decade is strong identity. A privacy proxy held for a decade tells you about the proxy, not the owner — so it is discounted, and a redaction that happened during the 2018 GDPR wave is treated as a format change, not an ownership change.
IP addressDedicated 0.90 · small-shared 0.60 · mass-shared/CDN 0.15Ten years on a dedicated IP is real operational continuity. Ten years on a CDN edge IP shared by millions of sites says almost nothing — the same address is not the same operator.
Nameserver operatorSelf-hosted 0.90 · managed provider 0.50 · parking 0.10Running your own nameservers for years is a deliberate commitment; sitting on a managed provider is normal; sitting on a domain-parking service is the opposite of an active site.
Mail (MX) providerSelf-hosted 0.90 · provider 0.50An organization that has operated the same mail for years is a real, running business — and mail being removed after years of presence is one of the clearest signals of a change of hands.
Registrar0.35 (all)Which registrar you use is weak identity evidence — millions of domains share each one — so registrar tenure alone can never carry much weight, and can never on its own vouch for continuity.

Correlated lines are not double-counted: a domain that runs its nameservers and hosting through the same provider gets credit for one operational commitment, not two. And the whole low-identity group — registrar, privacy proxy, shared IP — is capped, so a domain parked quietly for years can never accumulate more than a point or two of authority on tenure alone.

Change forensics

Whose years are these?

The hard problem is the aged-domain market: someone buys a domain with twenty years of history and inherits its reputation. So the model reads the pattern of changes across snapshots. A single change is routine. Several control-plane changes bunched into one window — the domain moving hosts, nameservers, and mail together — is the signature of a change of hands, and the clock resets. History before a reset is attributed to the previous operator, stated as a dated fact, never as a verdict.

What the archive showsHow the model reads it
One line changes (new host, new nameservers)Routine migration. That line's tenure clock restarts; everything else keeps its years. No ownership conclusion.
Nameservers + hosting + mail all change in one windowAn ownership-change fingerprint. Tenure is counted only from the change — the previous operator's years belong to the previous operator.
Registrant organization changes to an unrelated nameRecorded as a dated fact — “registrant organization changed between <dates>” — never as a penalty or an accusation. History before the change is attributed to the prior operator.
Domain expired, was deleted, and re-registeredA hard reset (the drop-catch rule): a freshly re-registered domain's decades of archive history vouch for whoever held it before, not the current owner. Continuity counts from re-registration.
A whole cohort changes the same field at onceRecognized as an industry artifact (a GDPR redaction wave, a registrar acquisition) and struck — it is not evidence about any one domain.

What a patient attacker cannot fake

Continuity can move Authority by at most a bounded amount — it breaks ties and validates a real history, but it can never manufacture prominence. A buyer who parks a bought domain and changes nothing tops out near the parked-domain floor. A buyer who repoints hosting and mail trips the change forensics and resets the clock. And because we hold the archive, no amount of money buys backdated snapshots. The one thing an attacker can do — buy a domain and genuinely keep everything the same for years — costs exactly what the signal claims: years.

Stated limits

Continuity corroborates our other history evidence (registration age, first web-archive snapshot, first certificate) — its total weight is deliberately capped below theirs, so stability supports the picture but never dominates it. A quiet buyer who changes nothing observable for years is, by construction, indistinguishable from continuity; we treat years of unchanged infrastructure as earned, and bound what it can be worth. Pre-2007 history is credited only lightly, because our record does not reach it.

Constants are published: gap-damping 3y · accrual τ 1.75y · commodity cap 0.25 · corroboration needs ≥2 distinct identity clusters over ≥3 years.