Update: serverHold status has been removed from t.me after Telegram removed the sanctioned company’s channel. t.me links are all working now.

Original Article Continues Below
Telegram’s short-link domain, t.me, stopped resolving worldwide on July 13, 2026. Not a traditional outage but instead gone from the global DNS infrastructure and a WHOIS record that now reads serverHold, a status the domain’s own registry applies (in this case, Identity Digital), not GoDaddy or any other domain registrars.
If you clicked a t.me/username link yesterday afternoon and got a browser error instead of a chat preview, this is why. The app kept working. The channels, the bots, the group invites, all of it still exists inside Telegram’s own infrastructure. What broke was the piece of the internet that translates “t.me” into an address a browser can actually reach. As a temporary workaround, telegram has switched from t.me to telegram.me inside its app.
Here’s everything confirmed so far, what serverHold does at the protocol level, and the theories currently circulating for why the .me registry pulled the trigger on one of the most-clicked domains on the internet.

What is serverHold
serverHold is one of the EPP (Extensible Provisioning Protocol) status codes ICANN defines for how registries manage domain lifecycle and enforcement. It sits in a different category from the “Prohibited” flags most people have seen before. A clientTransferProhibited status just means nobody can move the domain to a new registrar without unlocking it first. serverHold is not a lock. It’s a kill switch.
From ICANN’s own Definition:
This status code is set by your domain’s Registry Operator. Your domain is not activated in the DNS.
If you provided delegation information (name servers), this status may indicate an issue with your domain that needs resolution. If so, you should contact your registrar to request more information. If your domain does not have any issues, but you need it to resolve in the DNS, you must first contact your registrar in order to provide the necessary delegation information.
When a registry applies serverHold, it removes the domain’s delegation from the parent zone, meaning the name servers that would normally answer “where does t.me point?” simply stop being listed. No amount of correct configuration on Telegram’s end changes this. DNS resolution for the domain fails at the root of the lookup chain, before any request ever reaches Telegram’s servers. It’s the digital equivalent of a phone company deleting a number from the directory. The phone still works. Nobody can dial it.
Registries generally reserve serverHold for a narrow set of situations: court orders, law enforcement requests, active fraud or malware distribution, or a registry-level compliance dispute with the registrant. It’s rare enough, and severe enough, that seeing it applied to a domain with roughly a decade of registration runway left immediately reads as something other than routine housekeeping.
This is the same TLD that Twitter/X’s own domain infrastructure has run into trouble with before, and it’s not the first time a major platform’s shortlink domain has gone down over a registrar or registry-side technical issue rather than any content decision. The difference here is that serverHold specifically points at a registry, not a registrar-side accident.
📬 Stay Ahead of Cyber Threats
Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.
Subscribe to the Newsletter →
Why the app kept working
Telegram’s actual service, meaning the servers that store messages, route them between clients, and handle the mobile and desktop apps, doesn’t touch t.me at all once you’re inside the app. The domain exists purely as a convenience layer: a shareable, clickable way to point someone at a username, channel, group, or bot without them needing the app already installed and configured with a deep link.
Cut that domain out of DNS and here’s what still functions:
- The Telegram app itself, fully, on every platform
- Existing chats, channels, and groups you’re already in
- The telegram.org marketing site and the telegram.me alias domain, both confirmed still resolving as of this writing
- In-app search and native invite mechanisms that don’t route through the browser
Here’s what breaks:
- Any t.me/username or t.me/joinchat link shared outside the app (social media, websites, email signatures, QR codes)
- Link previews generated by third-party platforms that fetch t.me metadata
- New-user onboarding flows that rely on a browser-clickable invite link before the app is installed
If your channel growth or bot signups depend on people clicking a raw t.me URL from outside the Telegram app, that funnel is currently broken regardless of how well your own infrastructure is configured. This is the exact failure mode security teams plan for when they build redundancy into anything customer-facing: a single point of failure sitting one layer above your own stack, controlled by a third party you have no operational relationship with.
Who has the power to fix this and who doesn’t
A lot of the noise in comment threads yesterday assumed GoDaddy could just flip a switch. It can’t. GoDaddy is the registrar, the company Telegram (or whoever manages the domain on Telegram’s behalf) pays and interfaces with directly. Registrars handle renewal, contact records, nameserver configuration, and client-side status flags like clientHold. But serverHold sits above that layer entirely. It’s applied directly by the registry operator, in this case Identity Digital acting for doMEn, and no registrar action can override it. GoDaddy could terminate its relationship with the registrant entirely and t.me would still be sitting in serverHold, because the hold isn’t a registrar setting.
That leaves exactly two paths back to normal: the registry lifts the hold on its own initiative, or whatever triggered the hold (a court order, a compliance action, a dispute) gets resolved and the registry is instructed to release it. Neither path runs through Telegram’s engineering team, which is part of why “the app itself still works” and “the links are still broken a day later” can both be true at once. This isn’t a bug Telegram can patch.
Just in: We now have confirmation that an OFAC order lead to suspension of the t.me domain. It isn’t as simple as it seems. Details explained below.
The OFAC connection, and what it says
This is the part that changes the story, and it’s the first piece of this whole timeline backed by an actual primary source instead of a screenshot or a trade-press paraphrase.
OFAC published a Recent Actions entry dated July 13, 2026, the same day the serverHold status appeared, titled “Cyber-related Designations; Cuba Designations; Issuance of Cuba-related Frequently Asked Question.” The accompanying Treasury press release is headlined “Treasury Sanctions Malware and Infrastructure Providers Supporting Ransomware Attacks Against Americans.” Most of that day’s action is unrelated to Telegram entirely: a batch of Cuba-program designations against state enterprises and government bodies, plus two individuals added to the SDN list under the CYBER4 program (Dmytro Rashevskyi, based in Dnipro, Ukraine, and Yevgeniy Silayev, based in Belarus).
Buried in that same entity list is the actual connection: FIRST VPN SERVICE, also known as 1VPNS or FVPNS, a Dnipro-based operation OFAC designated under the CYBER4 program. The SDN entry lists its identifying infrastructure, including several standalone websites (1vpns.com, 1vpns.net, 1vpns.org, 1jabber.com) and one more entry alongside them: an alternate website listed as t.me/FirstVPNService.

Read that carefully, because the distinction matters. OFAC did not designate the t.me domain. It designated a company, First VPN Service, an outfit that fits the classic bulletproof-hosting profile: infrastructure that ransomware crews rent to stay online while evading takedowns. One of the several identifiers OFAC listed for that company happens to be a Telegram channel path sitting under the t.me domain, the same way 1vpns.com is a website identifier for the same entity.
Here’s the problem that likely follows from that listing. Sanctions compliance works at the level of “don’t do business with this specific designated party.” That’s straightforward when the identifier is its own domain like 1vpns.com; a registrar or registry can suspend that exact name without touching anything else. It doesn’t work cleanly when the identifier is a subpath of somebody else’s domain, because DNS delegation, and the serverHold status specifically, operates at the domain level, not the path level. There’s no EPP status code for “block one Telegram channel.” There’s only one for “remove this entire domain from resolution.”
If a U.S.-jurisdiction party in the resolution chain, and GoDaddy is a U.S. company, treated the OFAC listing of t.me/FirstVPNService as requiring action against the domain it sits on, the only lever available would be a hold on all of t.me, not a scalpel aimed at one channel. That would explain the serverHold status, the same-day timing, and why nobody involved has issued a clean public explanation: “we took down Telegram’s entire shortlink infrastructure because of one sanctioned channel operator’s Telegram handle” is not a sentence anyone wants to be the first to say on the record, even if it’s mechanically what happened.
To be clear about where the evidence stops: OFAC’s own filing does not mention t.me, the serverHold status, or Telegram at all. Nobody at Treasury, Identity Digital, doMEn, or Telegram has confirmed this is the actual trigger. What’s confirmed is the SDN listing itself, the same-day timing, and the mechanical reality that domain-level enforcement tools can’t isolate a single subpath. Everything connecting those dots into causation is still inference, just inference resting on a document instead of a rumor.
This also retroactively explains something I got wrong in an earlier version of this analysis: the claim that “t.me is on an OFAC list”. It was directionally right and imprecisely worded. t.me the domain isn’t sanctioned. A specific channel living at t.me/FirstVPNService, belonging to a sanctioned entity, is named in a federal designation, and that distinction may be the entire reason a global platform’s shortlink domain went dark.
Other Noteworthy Incidents:
- The French investigation. Durov has been under judicial supervision in France since his August 2024 arrest at Le Bourget on charges tied to insufficient moderation of illegal content on Telegram. He sat for another round of questioning by French investigators on July 11, 2026, two days before the serverHold status appeared. His lawyers maintain the prosecution still hasn’t produced evidence supporting the original charges. I found no link between that case and the domain action, and the OFAC timing now looks like the far stronger lead. Some non-English coverage floated a rumor that Durov had been arrested again around the same time; I could only corroborate the interrogation session, not an arrest, so treat “arrested again” as unverified.
- Ongoing regulatory pressure in Russia and India. Telegram is separately dealing with scrutiny in Russia over extremism allegations and in India over allegations the platform was used to leak exam materials. Nothing ties either to this specific domain action. Given the OFAC filing, this looks like coincidental timing rather than a cause.
- A registry-side abuse action unrelated to sanctions. Still mechanically possible in the abstract, but with a dated, sourced federal sanctions action landing the same day, it’s a much weaker explanation than it looked yesterday.
What domain owners should take from this
Set the Telegram drama aside for a second, because there’s an operational lesson here that applies to anyone running infrastructure on a third-party-controlled TLD, and cybersecurity teams should be paying attention regardless of whether they’ve ever touched Telegram.
A serverHold status is a reminder that domain resolution is a trust relationship with a party you don’t control and usually don’t even think about. Registrars get scrutinized. Registries mostly don’t, until something like this happens. If your organization’s link-sharing, SSO redirects, or webhook callbacks depend on a single domain sitting under a ccTLD with commercialized general use (like .me, .io, .ai, or .co), you’re one registry-level decision away from the exact failure Telegram is dealing with right now, and there is no amount of your own infrastructure hardening that changes that exposure.
Practical takeaways if you’re auditing this on your own stack:
- Don’t put critical, revenue-touching redirect infrastructure on a single ccTLD domain with no fallback
- Know the difference between your registrar and your registry, and understand that only one of them can actually help you if something like this happens
- Build in a secondary domain path (Telegram’s telegram.me/telegram.org fallback is a decent real-world example of this working as designed)
- Monitor WHOIS/RDAP status flags on domains your business depends on, not just uptime pings on the resolved IP

What happens next
If the OFAC connection is actually the trigger, the fastest realistic fix isn’t a court process at all. It’s Telegram removing or disabling the @FirstVPNService channel, whoever administers the resolution chain confirming the sanctioned identifier no longer resolves through t.me, and the registry releasing the hold on the rest of the domain once that specific risk is gone. That’s a plausible fast resolution, days rather than months, if this is really what’s going on.
If it isn’t, or if there’s a second issue layered underneath it, this could drag out considerably longer. Either way, Telegram migrating more of its shortlink traffic toward telegram.me, or a domain sitting outside .me entirely, would be a rational thing to do regardless of how this specific incident resolves.
Just in: Telegram has pushed a commit to change t.me to telegram.me inside its apps. So, at least in its app, links will work fine again.

I’ll update this piece once Telegram, doMEn, Identity Digital, or Treasury actually confirms what happened on the record. Until then, if you need to share a Telegram link, do it from inside the app.
Just In: Identity Digital has confirmed placing t.me on hold due to OFAC compliance.

Frequently Asked Questions
Is Telegram down?
No. The Telegram app is fully functional on every platform. Only the t.me shortlink domain is affected, and only for links opened outside the app.
What does serverHold mean on a domain?
It’s an EPP status code applied by a domain registry that removes the domain’s delegation from DNS, making it unreachable from any standard browser or client regardless of how the underlying servers are configured.
Can GoDaddy fix the t.me outage?
No. GoDaddy is the registrar, not the registry. The serverHold status is applied and controlled by Identity Digital and doMEn, the operators of the .me registry, not by the registrar.
Why does the .me domain matter to Telegram specifically?
t.me has served as Telegram’s primary shortlink domain since early in the platform’s history. Usernames, channels, groups, and bots are all conventionally shared as t.me/name links.
Update: As a temporary workaround inside the app, telegram has updated its apps to change t.me to telegram.me
Has Telegram said why this happened?
Not as of this writing. No statement has been issued by Telegram, doMEn, or Identity Digital explaining the cause of the serverHold status.
Update: Identity Digital has now confirmed placing t.me on hold due to OFAC compliance.
Is t.me on an OFAC sanctions list?
Not the domain itself. A July 13, 2026 OFAC designation of a Ukraine-based entity called First VPN Service lists a Telegram channel, t.me/FirstVPNService, as one of that entity’s identifiers. The domain-wide serverHold status appeared the same day, which is a strong lead, not a confirmed cause. OFAC’s filing does not mention t.me or serverHold directly.









