Friday, August 28, 2026

Telegram’s t.me Domain Suspended, Breaking Invite and Channel Links Worldwide

Telegram’s core short-link domain, t.me, has been placed under a serverHold status at the .me registry. This action can remove the domain from the global DNS, making all associated links inaccessible.

The incident affects various Telegram features, including invite links, public channel previews, bot URLs, usernames, and shared message links that rely on the t.me domain.

Users trying to access these URLs may experience DNS resolution failures or encounter browser errors, even though Telegram’s messaging application itself may still be operational.

Telegram’s t.me Domain Suspended

WHOIS records show that the domain currently carries eight Extensible Provisioning Protocol (EPP) status flags, which include serverHold, clientDeleteProhibited, and serverDeleteProhibited, as reported by CSN.

The timestamp for the record update is noted as 2026-07-13T19:24:55Z. The domain is registered with GoDaddy.com, LLC and was created on May 20, 2010. It is not set to expire until May 20, 2035, making it unlikely that a missed renewal caused the outage.

Telegram’s nameserver is still pointing to Google Cloud DNS infrastructure, specifically to ns-cloud-b1 through ns-cloud-b4.googledomains.com. However, having functioning nameserver records does not prevent a serverHold action from taking effect.

The serverHold status is a registry-controlled EPP code. Unlike clientHold, which a registrar can apply due to issues such as unverified registrant information, serverHold can only be imposed by the domain registry. For .me domains, registry operations are managed by Identity Digital.

When the registry applies serverHold, it suppresses the domain’s DNS delegation at the top-level domain level. Consequently, the domain’s authoritative DNS zone becomes unreachable from public resolvers, regardless of whether its DNS provider, nameservers, or hosting infrastructure are configured correctly.

Registry-level holds may result from suspected abuse, fraud investigations, court orders, compliance disputes, security concerns, or administrative errors. As of now, Telegram, GoDaddy, the .me registry, and Identity Digital have not publicly explained this action.

The absence of reports indicating a broader outage suggests that this issue is limited to the t.me web and link-redirection ecosystem. Telegram’s core messaging functions may still work through its native clients, alternate domains, and direct service infrastructure.

Nevertheless, this disruption creates significant usability and operational challenges. Organizations, journalists, communities, and even malicious actors often use t.me links to distribute Telegram channels and group invitations. Broken links can hinder legitimate communications and complicate access to public intelligence channels and incident-response resources.

To restore functionality, the registry-level hold must be lifted. Depending on the underlying cause, this process could take anywhere from hours to several days. In the meantime, Telegram users should avoid exclusively relying on t.me URLs and consider using alternative contact methods or in-app search features wherever possible.

Interact with Cyber Threats in Windows, Linux, macOS VMs to Trigger Full Attack Chain - Analyse Malware & Phishing with ANY RUN

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit

A newly analyzed phishing operation is using server-side polymorphism...

Critical WordPress Plugin Flaw Allows Unauthenticated Administrator Account Takeover

A critical authentication bypass vulnerability has been identified in...

ServiceNow Patches Critical Flaws Enabling Unauthenticated RCE and SQL Injection

ServiceNow has issued security advisories for four vulnerabilities, including...

Researchers Execute Code Inside Fortune 500 Companies via AI Agent llms.txt Files

Security researchers have shown that AI coding agents can...

BlueDelta Targets Defense and Diplomatic Organizations With HOOKEDGE Malware

Russian state-linked threat actor BlueDelta has launched a renewed...

Unitree G1 Humanoid Robot Flaws Allow Unauthenticated Root RCE Over Bluetooth

Security researcher Boschko has revealed two vulnerabilities in Unitree’s...

TITAN RaaS Uses AI for Data Classification, Regulatory Analysis and Automated Ransom Calculation

A newly emerged ransomware-as-a-service operation named TITAN is advertising...

Related Articles

Recent News