Cyber Security News

Telegram’s t.me Domain Suspended, Breaking Invite and Channel Links Worldwide

Telegram’s core short-link domain, t.me, has been placed under a serverHold status at the .me registry. This action can remove the domain from the global DNS, making all associated links inaccessible.

The incident affects various Telegram features, including invite links, public channel previews, bot URLs, usernames, and shared message links that rely on the t.me domain.

Users trying to access these URLs may experience DNS resolution failures or encounter browser errors, even though Telegram’s messaging application itself may still be operational.

Telegram’s t.me Domain Suspended

WHOIS records show that the domain currently carries eight Extensible Provisioning Protocol (EPP) status flags, which include serverHold, clientDeleteProhibited, and serverDeleteProhibited, as reported by CSN.

The timestamp for the record update is noted as 2026-07-13T19:24:55Z. The domain is registered with GoDaddy.com, LLC and was created on May 20, 2010. It is not set to expire until May 20, 2035, making it unlikely that a missed renewal caused the outage.

Telegram’s nameserver is still pointing to Google Cloud DNS infrastructure, specifically to ns-cloud-b1 through ns-cloud-b4.googledomains.com. However, having functioning nameserver records does not prevent a serverHold action from taking effect.

The serverHold status is a registry-controlled EPP code. Unlike clientHold, which a registrar can apply due to issues such as unverified registrant information, serverHold can only be imposed by the domain registry. For .me domains, registry operations are managed by Identity Digital.

When the registry applies serverHold, it suppresses the domain’s DNS delegation at the top-level domain level. Consequently, the domain’s authoritative DNS zone becomes unreachable from public resolvers, regardless of whether its DNS provider, nameservers, or hosting infrastructure are configured correctly.

Registry-level holds may result from suspected abuse, fraud investigations, court orders, compliance disputes, security concerns, or administrative errors. As of now, Telegram, GoDaddy, the .me registry, and Identity Digital have not publicly explained this action.

The absence of reports indicating a broader outage suggests that this issue is limited to the t.me web and link-redirection ecosystem. Telegram’s core messaging functions may still work through its native clients, alternate domains, and direct service infrastructure.

Nevertheless, this disruption creates significant usability and operational challenges. Organizations, journalists, communities, and even malicious actors often use t.me links to distribute Telegram channels and group invitations. Broken links can hinder legitimate communications and complicate access to public intelligence channels and incident-response resources.

To restore functionality, the registry-level hold must be lifted. Depending on the underlying cause, this process could take anywhere from hours to several days. In the meantime, Telegram users should avoid exclusively relying on t.me URLs and consider using alternative contact methods or in-app search features wherever possible.

Interact with Cyber Threats in Windows, Linux, macOS VMs to Trigger Full Attack Chain - Analyse Malware & Phishing with ANY RUN

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Attackers Exploit MCP RCE, Blind Prompt Injection and Memory Credential Theft Against AI Infrastructure

Attackers are increasingly treating AI infrastructure as a high-value cloud entry point, exploiting exposed Model…

3 hours ago

700 OpenAI Agents Coordinate Attack on Hugging Face and Gain Remote Code Execution

OpenAI’s ExploitGym evaluation environment reportedly became the site of a large-scale, unsanctioned multi-agent campaign after…

4 hours ago

Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit

A newly analyzed phishing operation is using server-side polymorphism to generate a distinct credential-harvesting page…

4 hours ago

Critical WordPress Plugin Flaw Allows Unauthenticated Administrator Account Takeover

A critical authentication bypass vulnerability has been identified in the WPMU DEV Dashboard WordPress plugin,…

5 hours ago

ServiceNow Patches Critical Flaws Enabling Unauthenticated RCE and SQL Injection

ServiceNow has issued security advisories for four vulnerabilities, including critical flaws in its AI platform.…

5 hours ago

Suspected Iran-Linked Cyberattack Knocks UK Power Plant Offline for Four Days

A cyber incident reportedly forced a small UK power generation facility offline for about four…

5 hours ago