machinewitness

One day in the archive

How a day enters the record, and why it cannot be edited afterwards.

Every 24 hours the same sequence runs. It ends with a single value that anyone can recompute — and that was placed beyond our reach on the day itself. This page draws that sequence, and then draws it backwards, the way an expert would walk it years later.

The daily sequence

The daily recording pipeline At 03:00 UTC the crawler reads the machine-readable declaration files from each domain in the ring — currently 128,347 in total: the 128,293 domains of the EU-suffix list below, the core ring, and domains observed since earlier lists. Each response is stored with its headers, TLS fingerprint and a cryptographic hash. At 23:50 UTC all observations of the day are folded into a single Merkle root, which is anchored with three independent external parties. 03:00 UTC The web, as machines see it spiegel.de lemonde.fr elpais.com 128,344 more European domains, visited once a day What is read robots.txt crawler rules ai.txt AI training permission tdmrep.json rights reservation Small public files no human ever reads Stored, unaltered exact bytes served response headers TLS fingerprint time, in UTC sha256 a3f9c1… one observation We record. We do not interpret or judge. 274,303 observations on 2 Aug 2026, folded into one value 23:50 UTC · the daily seal Merkle root · one value for the whole day 08c2ae22ad98caa5…a16dd256 RFC 3161 OpenTimestamps qualified eIDAS token held here second step pending token held here Change one byte anywhere in the day and this value no longer matches.

recording & sealing — ours anchoring — third parties, not ours dashed = not complete today

On the dashed anchor. OpenTimestamps works in two stages: the root is submitted the same day, but the receipt only becomes self-contained once the Bitcoin confirmation is fetched back into it. We have not yet performed that second step, so the Bitcoin path is currently verifiable only while the calendar servers remain reachable. The RFC 3161 and qualified eIDAS anchors are unaffected and stand on their own. The current state of each anchor, in full.

The same chain, walked backwards

This is the part that gives the record its value: every step can be repeated by a third party from public data. Nothing below requires our cooperation, our servers, or our continued existence.

How an expert verifies a record without our help Four steps: take the stored observation, recompute its hash, recompute the day's Merkle root from the published log, and check that root against the external time-stamps. Every input is public. Step 1 The record The bytes that domain X served on day Y. Step 2 Recompute the hash Standard SHA-256. Must match what we filed. Step 3 Rebuild the day Fold the public log into that day's Merkle root. Step 4 Check the anchors Three independent parties, not us. Everything above is public If any single step fails to reproduce, the record is worthless — and that is the point: the archive is built so it can be checked against us, not only with us.

the step that does not depend on us at all

Which part of the web is covered

The broad ring is every domain in the Tranco top-1M list that carries an EU-27 country code or .eu — 28 endings in all. The list was exhausted rather than capped: these are all of them, not a round number chosen for convenience.

128,293 domains from this list, plus a small hand-curated core ring of dispute-relevant domains observed at a higher cadence.

What an ending does and does not tell you. A country-code ending is a proxy for where a site belongs, not proof of it. A German company publishing under .com is not in this list, and a .de domain may be operated from anywhere. We state the criterion rather than claim to cover “the European web”: what is observed is what the criterion selects, and it is written down so anyone can judge the gap for themselves.

Where to go from here

What we store about a domain walks the same ground field by field, on one worked example. The glossary defines each evidentiary term, including what it does not prove. The public root log lists every sealed day and its anchors. The coverage check answers whether a given domain is observed at all.