Transparency Report

Service usage · Abuse handling · Legal interactions

Last updated: August 2026 · Author: Sean Wei

tg.pe is a small, free URL shortener run by one person. This is an honest look at what it does behind every link, and how it handles the people who try to weaponise it for phishing and scams.

This page is the short version, about five minutes. The engineering, the measurement instrument, every definition, and the full data tables are on Methodology.

A stranger reported a scam

A German-language parcel-delivery phishing mail reached Stefano with a “Pay now” button on a tg.pe link. He forwarded it to abuse@tg.pe: “this looks like a SPAM Mail and abuse of your service.” 50 minutes later the link was a 404, the account banned, the destination block-listed. His reply: “Awesome, didn't expect a reply.” The default experience of reporting abuse online is a black hole; what makes the difference here is not budget, it is that someone is paying attention.

The numbers

33,093
Short links created
Lifetime, over 6 years 10 months
2,168
Removed for safety or abuse
6.6% of everything created
~4h
Median external report to removal
Fastest on record: 50 minutes
0
Legal requests, ever
In 6+ years of operation
30,442
Active links served
410,482
Clicks served
Since April 2026; the top 10 links are about a third
313
External abuse reports
Lifetime, from CERTs / vendors / individuals
208
Submitters currently banned
All Telegram; a ban clears that user's whole history

“Legal requests” covers the lot: law-enforcement requests, court orders, DMCA / UDRP / URS notifications, and acquisition or policy-change inquiries. Zero across the board in 6+ years. How each figure above is defined, and the queries behind it, are in Definitions.

How links stay safe

Every link is checked before it goes live, checked again in the background moments later, and then re-checked when it is clicked, at most once a week per link, not on every click. None of these checks is perfect; each catches what the others miss. The slow ones run after the response is flushed, so nobody waits while they finish.

Before the link goes live the submitter waits on these
  • Unwrap open redirectors
  • Block list & high-risk list
  • Shortener shape
  • Newly-registered domain (RDAP)
  • Ad-smartlink pattern
  • Google Safe Browsing
  • Rate limit
response flushed · the link is live
After the response nobody waits on these
  • VirusTotal reputation
  • urlscan.io evidence capture
  • AbuseIPDB submitter screen
↓ and then, for as long as the link exists ↓
On every later click at most once a week per link
  • Safe Browsing re-check → remove
  • Refuse or remove
  • Contain: created with a 5 or 30-minute fuse, operator notified
  • Rewrite or record only

tg.pe runs no ads and sells no data; it redirects to the URL submitted, after stripping platform trackers (fbclid, gclid, igshid) and unwrapping known open redirectors.

Each stage's data source, fail mode, thresholds, and the reasoning behind the non-obvious choices are in the safety pipeline.

When something gets through

Removal authority comes from the public Terms every submitter accepts: phishing, malware, scams, CSAM, harassment. One Telegram ban soft-deletes every link that user ever created. The verified figure is a ~4-hour median from external report to removal. That median describes active response, not all removals: backlog cleanup and ban-cascade sweeps run against links that are much older, and mixing them in would pull the number out of shape. So the distribution is split in two.

Active response · 57.1%
Backlog & ban cascade · 42.8%

845 removals with usable timestamps. Excludes 1,296 links soft-deleted in one batch on 2025-01-06, a one-time inventory cleanup whose synthetic timestamps would distort the distribution.

What the reports look like

313 external reports have arrived over the service's life, from national CERTs, anti-fraud vendors, and ordinary recipients; CIRCL, the US IRS, and Netcraft are about 76% of the volume, and the long tail confirms tg.pe sits on multiple watchlists.

The candid part is the misses, and what each one changed. The worst category (July 2022): a Tor-routed report flagged a tg.pe link as the entry point to a child-sexual-abuse archive; the operator confirmed and removed it within 8 hours. It is the only non-phishing abuse case in 5+ years, and the reason takedown, block list, and bans apply equally to the worst categories, not just phishing. The 2022 IRS campaign (199 reports in two quarters, more than every other quarter combined) is why ASN-level banning exists. A two-week run of cloned Orange France login pages in April 2021 is why IP blocking does. European bank clones (2021–2023), Société Générale, Crédit Agricole, La Poste, Deutsche Postbank, Alpha Bank, ČSOB, each reported by a different organisation, each removed within hours.

Per-year volume, median response time, and who reported what are in abuse reports.

Reporting abuse onward

Removing a link from tg.pe does not remove the threat from the internet. When the operator confirms a removed destination is malicious and classifies it, the indicator is reported onward so the underlying page can be acted on wherever else it is reaching people: 27 reports covering 5 destinations across 11 channels. Each report goes only to the channels that fit it; a mis-routed report burns reporter reputation, which is the scarce resource here. CSAM is never sent to these phishing/malware feeds; it is referred out of band to NCMEC, the IWF, or law enforcement.

The eleven channels sit at five different layers of the ecosystem, and which layer acts decides whether the threat actually goes away:

One case, three responses

On 13 August 2026 a link to a phishing page impersonating flatmates.com.au on validationreq.top, a domain registered 75 minutes earlier that same morning, was submitted. The automated checks flagged the hours-old destination and contained the link, and the destination was reported onward to nine channels. Three of those layers responded differently, and the difference is the whole lesson:

  1. tg.peat submission
    Automated checks flagged the 77-minute-old domain and contained the link before anyone could click it.
  2. Cloudflare18 min
    Fastest to act, but the block was URL-level and the kit rotates its path on every visit, so sibling URLs stayed live. Fast at the wrong granularity.
  3. .TOP registry3 h 17 m
    Applied serverHold, removing the domain from DNS entirely. Slower, but at the granularity the attacker could not rotate around.
  4. Registrar (via NetBeacon)no action in window
    Had not acted by the time the registry suspension landed. One data point, not a pattern: routing through a third-party intake can simply be slower.
02:12domain registered 06:29reports filed 09:46suspended

About 7.5 hours from registration to suspension (ticket #1022402). Fast at the wrong granularity, slower at the right one, and not yet at all: one case showing all three responses at once. A narrative write-up is on the operator's blog (English / 中文), and the hour-by-hour log is on the methodology page.

Read this as one case, not a rate. Two outbound reports are confirmed all the way to suspension and one cloaked smartlink came back “no threats found”, because monetisation redirectors serve benign content to datacentre scanners. That is n=2 closed and n=1 not. Nothing here should be read as “typically” or “usually”.

Who runs it & your data

What is not measured yet

Three things this report deliberately does not claim: which brands are impersonated most often, what fraction of onward reports end in a confirmed takedown, and the registration-age split at population scale. Each is listed with the reason it is not there yet in what's not here yet. A fourth, RDAP coverage per TLD, now has a first measured pass published with its own limits attached.

Where a number in this report rests on a small sample, the sentence around it says so rather than rounding it up into a claim.

Contact

Abuse, or anything in this report: abuse@tg.pe · security.txt (RFC 9116), with OpenPGP via WKD for encrypted reports.

If anything here is useful (for research, for policy work, or if you run a similar service and want to compare notes), please reach out. tg.pe is a small operation, but small operators are part of how URL-level abuse gets contained, and the operator would rather share than keep it private.

The engineering and the data behind all of the above: Methodology.