Telegram t.me Domain Placed on serverHold — Links Fail, Registry Blocks DNS (Updated)
Telegram’s core short-link domain, t.me, was placed under a serverHold status at the .me registry on 2026-07-13, an action that can effectively remove the domain from the global Domain Name System and render all dependent links inaccessible.
WHOIS records captured by observers show eight Extensible Provisioning Protocol (EPP) status flags on the registration, including serverHold, clientDeleteProhibited and serverDeleteProhibited, with the latest update timestamped 2026-07-13T19:24:55Z.
The domain is registered through GoDaddy.com, LLC and was created on 20 May 2010; its registration does not expire until 20 May 2035, making a simple renewal oversight an unlikely cause.
Telegram t.me Domain Placed on serverHold
Despite DNS nameserver records still pointing to Google Cloud DNS (ns-cloud-b1 through ns-cloud-b4.googledomains.com), a registry-applied serverHold suppresses DNS delegation at the top-level domain and prevents public resolvers from reaching the domain’s authoritative zone regardless of nameserver health.
At a technical level, serverHold is a registry-controlled EPP status that differs from registrar-controlled holds such as clientHold.
Whereas clientHold can be applied by a registrar over issues like unverified registrant information, serverHold is applied by the registry operator, in this case Identity Digital for .me domains, and can be used for a range of administrative or legal reasons.
When the registry sets serverHold, it causes the domain to be removed from the TLD zone file or otherwise blocked at the registry layer, producing DNS resolution failures.
Users attempting to follow t.me links will typically see NXDOMAIN responses or browser error pages instead of the expected redirection or channel preview.
Notably, the messaging backend and native Telegram clients may continue operating via IP-addressed endpoints, other domains, or built-in connectors, which explains reports that core messaging functions were not uniformly impacted.
The practical scope of the outage extends beyond simple inconvenience. The t.me short-link ecosystem supports invite links, public channel previews, bot endpoints, username redirections, and shared-message links that many organizations, incident response teams, journalists, researchers and communities rely on for distribution and discovery.
Broken t.me links can sever access to public intelligence channels, disrupt coordinated incident communications, and complicate threat-hunting workflows that depend on persistent channel URLs.
The issue also affects adversary infrastructure: threat actors frequently use t.me links to host command-and-control callbacks and distribution points for malware or phishing content, meaning a registry hold can unintentionally disrupt malicious operations while simultaneously obscuring traces that investigators rely on for attribution.
Registry-level holds can be applied for a variety of reasons including suspected abuse or fraud, active investigations, court orders, compliance disputes, or administrative error.
As of publication neither Telegram nor GoDaddy nor Identity Digital have provided a public explanation for the serverHold action, and there are no definitive public indicators attributing the hold to a legal injunction, investigation, or administrative mistake.
Recovery procedures require the registry to remove the serverHold flag, a process whose duration depends on the underlying cause and the speed of communications between the registry, registrar and registrant; this could take hours or several days.
In the interim, security teams and regular users should avoid sole reliance on t.me links for critical communications, publish alternative access methods (such as direct domain links, in-app search names, or documented channel fingerprints), and validate channel ownership via known fingerprints or official pages.
Incident responders should capture and preserve nonfunctional t.me URLs and associated metadata for later analysis. Finally, this episode underscores how a single registry-level control can create outsized operational impact across both legitimate and malicious ecosystems, highlighting the need for resilient link distribution strategies and a clear communications path between major platform operators and registries.
No Comment! Be the first one.