Telegram’s t.me domain was placed on serverHold at the .me registry, removing it from global DNS resolution and breaking t.me short links worldwide. Reports said the disruption affected invite links, channel previews, and shared message URLs, while WHOIS records showed additional status flags including clientDeleteProhibited and serverDeleteProhibited. The domain registration remained active through 2035, indicating the outage was not caused by expiration.
The action appeared to originate at the registry level rather than through Telegram’s registrar account, with WHOIS data showing an update timestamp of 2026-07-13T19:24:55Z. No public explanation had been issued by Telegram, the .me registry, or Identity Digital at the time of reporting. Telegram’s core messaging service appeared to remain largely operational through its primary domains and IP-based connections, limiting the impact mainly to the platform’s link-sharing and discovery functions.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
After t.me was placed on serverHold, the domain was removed from global DNS resolution, breaking Telegram short links, invite links, channel previews, and shared message URLs worldwide. Reporting said Telegram's core messaging service appeared to remain largely operational through primary domains and IP-based connections.
DomainME said it had placed Telegram's t.me domain on hold for OFAC compliance and later restored it, bringing the shortlink domain back online after roughly a day of disruption. The report says telegram.me remained operational during the incident.
WHOIS data showed Telegram's t.me domain carrying serverHold along with clientDeleteProhibited and serverDeleteProhibited, with an update timestamp of 2026-07-13T19:24:55Z. The registration remained active through 2035, indicating the change was not caused by expiration.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecyberaccord.com
Open sourcethecybersecguru.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.