Report Abuse

tg.pe is a free URL shortener run by one person in Taiwan. If a tg.pe link points at phishing, malware, or a scam, email abuse@tg.pe. Reports get read in minutes; bad links are taken down immediately.

313external abuse reports received (lifetime, from CERTs, vendors, and individuals)
2,152links removed for safety & abuse (6.8% of everything created here)
~4 hmedian report-to-removal (active response)
206submitters currently banned

Figures from the Transparency Report (June 2026).

One report, fifty minutes

A parcel-delivery phishing mail reached a stranger, its “Pay now” button hiding behind a tg.pe link. He forwarded it to abuse@tg.pe: “this looks like a SPAM Mail and abuse of your service.” Fifty minutes later the link was a 404, the account behind it was banned, and the destination was block-listed. His reply: “Awesome, didn't expect a reply.”

Reporting abuse online usually means a black hole. What makes the difference here is not budget or headcount; it is that someone is paying attention.

How to report

abuse@tg.pe

Send the tg.pe link and, if you have it, where you saw it; a forwarded email or a screenshot is plenty. No form, no account, no legal standing required. Phishing, malware, and scam links come down no matter who reports them.

Prefer encryption? An OpenPGP key is published in security.txt. For vulnerabilities in tg.pe itself rather than a bad link, use security@tg.pe instead.

What happens to your report

Reports are one layer of several

Every link is checked before it goes live (Google Safe Browsing, RDAP registration-age checks, curated block lists), again in the background moments later (VirusTotal, urlscan.io, AbuseIPDB), and re-checked when clicked (at most weekly per link). The 2,152 removals above are the combined result of that pipeline, external reports, and manual review.

The stage-by-stage pipeline, removal timing, and real cases including the misses are in the Transparency Report. Machine-readable contact details are in security.txt (RFC 9116).