Permavault › Are Screenshots Admissible in Court?
Are Screenshots Admissible in Court?
Often, yes. An unchallenged screenshot comes in routinely when a witness with knowledge testifies that it fairly depicts what they saw. The problem is the contested screenshot: an image file carries no record of what URL it shows, when it was taken, or whether it was edited, and courts have excluded them on exactly that gap.
Screenshots are the most common form of digital evidence and the most commonly excluded. Both things are true at once, and the reason they are not a contradiction is the whole answer to the question.
This page covers when screenshots come in, when they do not, what courts have actually said, and what to capture instead when the content matters. It is about United States federal practice. Other jurisdictions authenticate evidence differently, and you should not assume this framework transfers.
The short answer
Screenshots are not automatically inadmissible. There is no rule against them. They are ordinary documentary evidence, and they get admitted all the time.
They are also not self-proving. A screenshot is an image file. It carries no reliable record of what URL it shows, when it was captured, who captured it, or whether anything was changed afterward. Anyone with free software and five minutes can produce a convincing one.
So the answer turns entirely on whether anyone objects:
- Nobody contests it. It comes in. Most screenshots in most matters are never challenged.
- A witness with knowledge can vouch for it. Under Rule 901(b)(1), testimony from someone with personal knowledge that the item fairly depicts what they saw is enough to authenticate it. This is the ordinary route and it works.
- It is contested and nobody can say who captured it, when, or how. This is where screenshots die, and courts have been excluding them on this basis for well over a decade.
The practical upshot: a screenshot is a fine record of something nobody will fight about, and a poor one for anything that might matter. You usually cannot tell in advance which you have.
What admissibility actually requires
“Admissible” is not one question. A screenshot has to clear several hurdles, and authentication is only the first.
Authentication. Rule 901(a) sets a low bar in principle: the proponent must produce evidence “sufficient to support a finding that the item is what the proponent claims it is.” Low, but not zero, and the gap is where contested screenshots fail.
Hearsay. If you are offering the content of the page for its truth, the hearsay rules apply to that content, entirely separately from whether the image is authentic. Authenticating a screenshot of a defamatory post proves the post existed; it does not make everything in the post admissible for its truth.
The original document rule. Rules 1001 through 1004 govern when a duplicate or a description stands in for the original. For electronically stored information, a printout or readable output that accurately reflects the data is generally treated as an original, which usually helps rather than hurts.
Relevance and the rest. Everything else in the rules still applies.
Getting past authenticity is the entry ticket, not the verdict. It is worth being precise about this, because a lot of writing on the subject implies that solving authentication solves admissibility. It does not.
When screenshots get excluded
The cases fall into three distinct patterns, and they fail for different reasons. Treating them as one problem is how people fix the wrong thing.
Nobody can vouch for the capture. In Iglesia Ni Cristo v. Cayabyab, No. 5:18-cv-00561-BLF (N.D. Cal. Mar. 31, 2020), the plaintiff offered screenshots of the defendants’ websites and social media pages at summary judgment. The court declined to consider them: the supporting declaration “had not provided any information as to who took the screenshots, or when.” The content may well have been genuine. It never got that far. The same reasoning runs through Lorraine v. Markel American Insurance Co., 241 F.R.D. 534 (D. Md. 2007), where Judge Paul Grimm denied both sides’ summary judgment motions because their electronic exhibits had no evidentiary foundation at all.
Nobody can prove who wrote it. In United States v. Vayner, 769 F.3d 125 (2d Cir. 2014), the government offered a printout of a social media profile bearing the defendant’s name and photo. The Second Circuit vacated the conviction: the mere existence of a page with someone’s name on it “does not permit a reasonable conclusion that this page was created by the defendant or on his behalf.” State courts have said the same in Griffin v. State, 19 A.3d 415 (Md. 2011) and Commonwealth v. Mangel, 181 A.3d 1154 (Pa. Super. 2018), and Facebook screenshots failed for want of supporting circumstantial evidence in Moroccanoil v. Marc Anthony Cosmetics, 57 F. Supp. 3d 1203 (C.D. Cal. 2014).
The image itself is fake. In Rossbach v. Montefiore Medical Center, No. 1:19-cv-05758 (S.D.N.Y. 2021), a plaintiff produced an image of text messages she said her supervisor had sent. The defense expert took it apart on its own internal evidence: an emoji version the claimed phone could not display, a subtly wrong font, a contact bar formatted incorrectly, and missing metadata indicating it was not a photograph at all. Judge Denise Cote’s conclusion ran to five words: “This image is a fabrication.” The case was dismissed with prejudice with a reported sanction of $157,026.27, and the Second Circuit affirmed the dismissal at 81 F.4th 124 (2d Cir. 2023).
The distinction between the first two matters enormously and is widely missed. A rigorous capture solves the first problem completely and the second not at all. A perfect capture of an impersonated account is a perfect capture of a fake, and you will still need circumstantial evidence tying the content to its author. What a good capture buys you is that the argument happens on authorship, where your investigation can win it, rather than on authenticity, where a weak exhibit loses before anyone reaches the merits.
The third pattern is the one that should worry an honest practitioner most, because Rossbach is what a judge has in mind when your phone screenshot is challenged. The forensic playbook that exposed that fabrication runs against genuine screenshots too, and a genuine screenshot has very little with which to answer it. Our guide to what opposing counsel looks for in screenshot metadata walks through the examination in detail.
When screenshots get in
The cases above are the cautionary ones, and reading only those gives a distorted picture. Screenshots and social media evidence are admitted routinely, and the successful cases have a consistent shape worth learning from.
In United States v. Lewis, No. 24-20235 (5th Cir. 2025), Instagram posts and screenshots of the defendant’s account saved by a victim were all admitted and the convictions affirmed. The authentication was entirely circumstantial: an agent identified the account by searching the defendant’s name and nickname, the posts showed him over two years in places accessible only to him, several were taken in selfie mode, and a victim testified independently that he posted under that username. As the Fifth Circuit put it, quoting its earlier decision in Jackson, “the standard for authentication is not a burdensome one.”
Other circuits have said the same plainly. United States v. Lamm, 5 F.4th 942 (8th Cir. 2021) holds that the government “may authenticate social media evidence with circumstantial evidence linking the defendant to the social media account.” In United States v. Barnes, 803 F.3d 209 (5th Cir. 2015), Facebook messages were authenticated because a witness had seen the defendant use Facebook, recognised the account, and confirmed the messages matched his manner of communicating. And in United States v. Farrad, 895 F.3d 859 (6th Cir. 2018), Facebook photos came in under Rule 901 because they showed the defendant, his tattoos, and “(perhaps most probatively) distinctive features of Farrad’s apartment, as confirmed by police investigation.”
The pattern is short enough to memorise. Evidence gets in when a witness with knowledge can speak to it, or when the item carries distinctive internal characteristics tying it to its source, ideally corroborated by independent investigation. It fails when the proponent has only the picture.
Farrad also carries a warning about the shortcut. The government had obtained a certification from Facebook, and the Sixth Circuit held it was error to treat the photos as self-authenticating business records on that basis. The error was harmless only because Rule 901 authentication succeeded independently. A platform’s certificate confirms that an account posted something at a time; it does not confirm the content is what you say it is.
What changed in 2017
On December 1, 2017, two new categories of self-authenticating evidence were added to Rule 902, and they matter more to web evidence than to anything else.
Rule 902(13) covers a record generated by an electronic process or system that produces an accurate result, shown by a certification from a qualified person. The output of an automated capture tool is squarely within it.
Rule 902(14) covers data copied from an electronic device, storage medium, or file, authenticated by a process of digital identification. In practice the process of digital identification is a cryptographic hash. The Advisory Committee notes put it plainly: “If the hash values for the original and copy are the same, it is highly improbable that the original and copy are not identical.”
Together they let a written certification, prepared in advance and served with notice, replace the live authentication witness. For a solo practitioner this is often the difference between using a piece of evidence and quietly dropping it, because flying in a forensic technician to authenticate one exhibit is not proportionate to most matters. We compare the two rules in FRE 902(13) vs 902(14).
These are not theoretical. In United States v. Dunnican, 961 F.3d 859 (6th Cir. 2020), a 902(14) certification from a qualified examiner, describing the extraction software and a hash showing the copy was “successful, complete, and accurate,” carried the authentication of phone data on appeal. The reverse lesson is United States v. Wood, 109 F.4th 1253 (10th Cir. 2024), where a substantively sound certificate was disclosed too late and the Tenth Circuit reversed the convictions: the notice requirement is not a formality.
Two caveats worth stating every time. Self-authentication establishes authenticity only; hearsay and relevance objections survive intact. And these are federal rules. Many states have adopted parallel provisions, but adoption is not universal and the details differ, as Mangel shows a Pennsylvania court applying its own authentication case law.
The self-collection problem
There is a quieter issue underneath all of this: who took the screenshot.
When you personally capture the page that matters to your case, you become the only person who can testify to what you did. ABA Model Rule 3.7 says a lawyer “shall not act as advocate at a trial in which the lawyer is likely to be a necessary witness,” with narrow exceptions. Nothing forbids you from capturing evidence. But if the capture is challenged and you are its only voucher, you may face a choice between your exhibit and your seat at counsel table. Iglesia Ni Cristo is the cautionary tale twice over: the failed declaration came from the plaintiff’s attorney, and when she later tried to cure it by declaring she had taken the screenshots herself, the court refused to consider it.
A capture made by a neutral automated system that documents its own process keeps every interested party out of the chain of custody.
What to capture instead
If the content might be contested, a screenshot should be the bookmark, not the exhibit. A capture that can carry the weight needs four properties:
- A recorded URL, timestamp, and process, written by the capture system rather than asserted afterward by a witness. This is exactly what the Iglesia Ni Cristo declaration lacked.
- Cryptographic hashes computed at capture, before anything could touch the files. A hash computed three weeks later proves only that nothing changed after the hash.
- A neutral, automated capture process, so no interested party sits inside the chain of custody.
- Independent verifiability, so the other side can check the record without trusting you or your vendor, and so the proof does not die if the vendor does.
The step by step version, including what the certification has to contain and the notice requirement people most often forfeit, is in our guide to authenticating a website screenshot in court.
And if the page is live right now, capture first and refine later. A rough copy of a live page beats a perfect method applied to a deleted one.
Variations on the question
Text messages and WhatsApp. Screenshots of messages raise everything above plus an attribution problem that is usually harder: proving who was holding the phone. Rossbach is a messaging case, and it is the reason messaging screenshots draw scrutiny. Where the account is a party’s, discovery and platform records are generally a stronger route than an image.
Social media posts. Posts have permalinks, which means there is a page to capture properly rather than a feed to photograph. See how to preserve social media evidence.
Web pages that have since changed. A screenshot of a page that no longer says what it said is the hardest exhibit to defend, and the easiest problem to have prevented. See web archiving for evidence.
England and Wales. Everything above is US federal practice, and the FRE 902 certification route has no direct equivalent there. But “it does not transfer” is not the same as “there is no answer,” and the English position is close to the inverse of the American one.
In civil proceedings, CPR 32.19 provides that “a party shall be deemed to admit the authenticity of a document disclosed to him under Part 31 unless he serves notice that he wishes the document to be proved at trial,” and that notice must be served by the latest date for witness statements or within seven days of disclosure, whichever is later. Authenticity is presumed unless someone objects, on time.
Noel Clarke v Guardian News and Media Ltd [2025] EWHC 2193 (KB) shows what that means in practice. An allegation was made in closing submissions that the date on a Snapchat message had been falsified. No notice to prove had been served “by that date, or at all,” and Steyn J held that “if the allegation was going to be made that the date on Ms Seltveit’s Snapchat account had been falsified, proper notice should have been given so that the Guardian would have had an opportunity to refute it.” The screenshot and its metadata stood.
Criminal proceedings work differently again, with the hearsay provisions of the Criminal Justice Act 2003 and, for machine output, section 129, which preserves “the presumption that a mechanical device has been properly set or calibrated.”
The practical consequence is worth drawing out. Because English courts lean on presumptions rather than an authentication gate, a challenge, when it comes, is fought over chain of custody and metadata rather than over a rule. That is the same evidence a sealed capture produces automatically. We will cover the England and Wales position properly in its own guide.
Other jurisdictions. Check local rules rather than assuming either framework applies.
Where Permavault fits
Permavault captures the page, not a picture of it. Paste a URL and a neutral automated system preserves the full page as it rendered, records the URL, timestamp, and process, fingerprints every file with cryptographic hashes at capture, and stores the result on a permanent decentralized network of roughly 300 independent nodes, funded by a long-term storage endowment. You and your client stay out of the chain of custody, and anyone, including the examiner on the other side, can verify the capture without trusting us.
Each capture is $4.99, with an optional Certificate of Authenticity from $9. The Legal tier adds a qualified electronic timestamp from Disig a.s., an EU-listed qualified trust service provider, applied to the signed capture manifest, plus an independent Bitcoin-anchored timestamp and a declaration template designed to support authentication under FRE 902(13) and 902(14). Under eIDAS Article 41, a qualified electronic timestamp carries a presumption of the accuracy of its date and time in EU courts.
A screenshot asks the court to take your word for it. A capture does not have to.
This article is general information about the Federal Rules of Evidence, not legal advice for any specific matter. Case outcomes depend on their facts, and admissibility always depends on the facts, the jurisdiction, and the judge.