Transparency Report

Service usage · Abuse handling · Legal interactions

Last updated: August 2026 · Author: Sean Wei

tg.pe is a small, free URL shortener run by one person. This page is an honest look at what happens behind every link, and at the people who try to use it for phishing and scams.

It is the short version, about five minutes. The engineering, every definition, and the full data tables are on Methodology.

A stranger reported a scam

A phishing email in German, dressed up as a parcel delivery, reached Stefano with a “Pay now” button pointing at a tg.pe link. He forwarded it to abuse@tg.pe: “this looks like a SPAM Mail and abuse of your service.” Fifty minutes later the link was a 404, the account was banned, and the destination was on the block list. His reply: “Awesome, didn't expect a reply.”

Reporting abuse online usually goes into a black hole. A one-person shortener has no abuse budget; what it has is somebody reading the mailbox.

The numbers

About one link in fifteen turns out to be abuse.

33,093
Short links created
Lifetime, over 6 years 10 months
2,168
Removed for safety or abuse
6.6% of everything created
~4h
Median external report to removal
Fastest on record: 50 minutes
0
Legal requests, ever
In 6+ years of operation
30,442
Active links served
410,482
Clicks served
Since April 2026; the top 10 links are about a third
313
External abuse reports
Lifetime, from CERTs / vendors / individuals
208
Submitters currently banned
All Telegram; a ban clears that user's whole history

“Legal requests” is meant in the broad sense, listed in full under Who runs it below. How each number is defined, and the query behind it, are in Definitions.

How links stay safe

Every link is checked three times: before it goes live, again a moment later, and once more when somebody clicks it.

No single check is reliable on its own, so they overlap and each catches what the others miss. The slow ones run after the page has already been sent back, so nobody waits for them.

Before the link goes live the submitter waits on these
  • Unwrap open redirectors
  • Block list & high-risk list
  • Shortener shape
  • Newly-registered domain (RDAP)
  • Ad-smartlink pattern
  • Google Safe Browsing
  • Rate limit
response flushed · the link is live
After the response nobody waits on these
  • VirusTotal reputation
  • urlscan.io evidence capture
  • AbuseIPDB submitter screen
↓ and then, for as long as the link exists ↓
On every later click at most once a week per link
  • Safe Browsing re-check → remove
  • Refuse or remove
  • Contain: the link dies by itself in 5 minutes unless the operator clears it
  • Rewrite or record only

tg.pe runs no ads and sells no data. It sends you to the URL that was submitted, minus the tracking codes platforms bolt on (fbclid, gclid, igshid), and with known redirect chains unwrapped first so the real destination is the one that gets checked.

What each stage checks, and why it is set that way: the safety pipeline.

When something gets through

When somebody reports a bad link, it is usually gone within about four hours.

The right to remove comes from the public Terms every submitter accepts: phishing, malware, scams, CSAM, harassment. Banning one Telegram account removes every link that account ever created.

That four-hour median covers active response only. Links cleared long after the fact are much older: backlog sweeps, and the cascade when a ban wipes an old account's history. Averaging those in would hide the response time instead of describing it, so the chart keeps the two apart.

Active response · 57.1%
Backlog & ban cascade · 42.8%

845 removals have usable timestamps. A one-time inventory cleanup on 2025-01-06 removed 1,296 links in a single batch; they all share one made-up timestamp, so they are left out.

What the reports look like

313 reports have arrived over the service's life, from national computer-emergency teams, anti-fraud companies, and people who simply received the email. Three senders are about 76% of them: CIRCL, the US IRS, and Netcraft. The rest trickle in one at a time from everywhere else, which is how you can tell tg.pe sits on several watchlists.

The misses are on the record too, and most of them changed something.

2022 Jul

The worst category: a report sent anonymously over Tor flagged a tg.pe link as the way into a child-sexual-abuse archive. Confirmed and removed within 8 hours. It is the only abuse case in 5+ years that was not phishing, and the reason removal, block lists, and bans cover the worst categories too.

2022

The IRS campaign (199 reports in two quarters, more than every other quarter combined) is why a whole hosting network can be banned at once, not just one account.

2021 Apr

A two-week run of cloned Orange France login pages is why IP blocking exists.

2021–2023

European bank clones: Société Générale, Crédit Agricole, La Poste, Deutsche Postbank, Alpha Bank, ČSOB, each reported by a different organisation, each removed within hours.

Per-year volume, median response time, and who reported what are in abuse reports.

Reporting abuse onward

Deleting the short link does not delete the scam page, so tg.pe reports the destination to whoever can actually take it down.

Once a removed destination is confirmed malicious and classified, its address goes onward: 27 reports covering 5 destinations across 11 channels.

Each report goes only to the channels that fit it. A misfiled report costs credibility with that channel. CSAM never goes to these phishing and malware feeds; it is referred out of band to NCMEC, the IWF, or law enforcement.

The eleven channels sit at five levels of the internet, and which level acts decides whether the scam actually goes away:

One case, three responses

On 13 August 2026 somebody submitted a link to a fake flatmates.com.au login page. It sat on validationreq.top, a domain registered 75 minutes earlier that same morning. The automated checks caught how new the domain was and contained the link, and the destination went out to nine channels. Three of those levels acted, each of them differently:

  1. tg.pecontained the tg.pe link
    at submission
    Automated checks flagged the 77-minute-old domain and contained the link before anyone could click it.
  2. Cloudflareblocked one URL path
    18 min
    Fastest to act, but it blocked one exact address, and the scam kit hands out a new address on every visit. The next one still worked. Fast, at the wrong size.
  3. .TOP registryremoved the domain from DNS
    3 h 17 m
    Pulled the whole domain out of DNS (serverHold), so every address on it went dark at once. Slower, but at a size the attacker could not route around.
  4. Registrar (via NetBeacon)
    no action in window
    Had not acted by the time the registry suspension landed. One case, not a pattern: going through a third-party intake can simply be slower.
02:12domain registered 06:29reports filed 09:46suspended

About 7.5 hours from registration to suspension (ticket #1022402). The full story is on the operator's blog (English / 中文); the hour-by-hour log is on the methodology page.

Two onward reports are confirmed all the way to a suspension. A third came back “no threats found”, because that destination showed a harmless page to the scanner and the real thing to real visitors. Two confirmed is not a pattern, so read none of this as “typically” or “usually”.

Who runs it & your data

One person in Taiwan, no company, no business model. Nothing that identifies a submitter ever leaves the service.

What is not measured yet

This report leaves three questions blank instead of guessing at them.

  • Which brands get impersonated most often.
  • How often an onward report ends in a confirmed takedown.
  • How many destinations are brand-new domains across everything submitted, not just the flagged ones.

Each one, and why it is missing, is in what's not here yet. A fourth question, how much registration data is even readable per top-level domain, now has a first measured answer, with its own limits attached.

Where a number in this report rests on a small sample, the sentence around it says so rather than rounding it up into a claim.

Contact

Abuse, or anything in this report: abuse@tg.pe · security.txt (RFC 9116), with OpenPGP via WKD for encrypted reports.

If any of this is useful, for research, for policy work, or because you run something similar and want to compare notes, please get in touch. tg.pe is a small operation, but small operators are part of how URL-level abuse gets contained, and the operator would rather share than sit on it.

The engineering and the data behind all of the above: Methodology.