All news
regulationcybersecuritysaas

Telegram's t.me Domain Suspended Over OFAC Sanctions Link

16 Jul 2026

Telegram's ubiquitous t.me shortlink domain—used for everything from group-join links to channel invites—went offline Monday and didn't return until early Tuesday, after registrar-level records show it briefly carried a "serverHold" status, a flag that blocks domain resolution entirely.

The outage coincided with the same-day U.S. Treasury sanctioning of First VPN, whose OFAC listing included a link to First VPN's Telegram group using a t.me shortlink. DomainME CEO Predrag Lešić confirmed Tuesday that the domain was back online and stated it had been "on hold due to the OFAC compliance, but it is back online now," adding that an official statement would follow.

What happened

  • Monday: The t.me domain goes offline; the U.S. Treasury sanctions First VPN the same day.
  • Monday: Pavel Durov posts on X that t.me links have stopped working.
  • Early Tuesday: The serverHold block is lifted and t.me returns.
  • Tuesday: DomainME's CEO confirms restoration, citing OFAC compliance as the trigger.

During the roughly one-day window, users could not rely on t.me shortlinks to join public Telegram groups—a core mechanic for the platform's growth and onboarding.

The domain, by the numbers

  • Registered: May 20, 2010
  • Set to expire: May 20, 2035
  • WHOIS last updated: July 13, 2026
  • Registered with GoDaddy.com, LLC, using Google Domains name servers

Why the link to sanctions matters

U.S. sanctions law (enforced by OFAC) can compel domain registrars and registries—which are themselves U.S. companies subject to steep fines for noncompliance—to freeze or hold domains connected, even indirectly, to sanctioned entities. In this case, the trigger appears to be that a sanctioned party's Telegram group was reachable via a t.me shortlink, not that Telegram itself was the sanctions target.

It remains unclear whether the serverHold was directly caused by the First VPN listing or reflected a broader compliance review, and no detailed official statement from Telegram beyond Durov's post has been provided. It's also unclear whether other Telegram-owned domains were affected.

Why founders should care

This incident suggests a few risk patterns worth weighing, expressed with appropriate uncertainty:

  • Single point of failure risk: Products that route core functionality (like group-join links) through one external domain may be more likely to face availability risk if that domain becomes entangled in a compliance action—even one unrelated to the platform's own conduct.
  • Indirect sanctions exposure: Platforms that host or link to user-generated content could plausibly face registrar-level disruptions triggered by third-party sanctions actions, even without the platform itself being targeted.
  • Recovery speed: The roughly one-day resolution may indicate that compliance-driven holds, once identified and addressed, can often be resolved relatively quickly—though this is based on a single case and may not generalize.
  • Contingency planning: Startups relying on shortlink or custom domains for essential product flows might benefit from evaluating backup access paths or registrar diversification, given that a hold like this could recur.

Open questions

Several details remain unresolved: the precise mechanism connecting the registrar's action to OFAC rules, whether the hold was narrowly tied to the First VPN listing or part of a wider review, and whether any other Telegram infrastructure was implicated. Founders operating platforms with heavy reliance on third-party domains or hosting user-generated links should treat this as a reminder to map out where similar compliance chokepoints might exist in their own stack.

Sources