tg.pe is a small, free URL shortener run by one person. This is an honest look at what it does behind every link, and how it handles the people who try to weaponise it for phishing and scams.
This page is the short version, about five minutes. The engineering, the measurement instrument, every definition, and the full data tables are on Methodology.
A stranger reported a scam
A German-language parcel-delivery phishing mail reached Stefano with a “Pay now” button on a tg.pe link. He forwarded it to abuse@tg.pe: “this looks like a SPAM Mail and abuse of your service.” 50 minutes later the link was a 404, the account banned, the destination block-listed. His reply: “Awesome, didn't expect a reply.” The default experience of reporting abuse online is a black hole; what makes the difference here is not budget, it is that someone is paying attention.
The numbers
33,093
Short links created
Lifetime, over 6 years 10 months
2,168
Removed for safety or abuse
6.6% of everything created
~4h
Median external report to removal
Fastest on record: 50 minutes
0
Legal requests, ever
In 6+ years of operation
30,442
Active links served
410,482
Clicks served
Since April 2026; the top 10 links are about a third
313
External abuse reports
Lifetime, from CERTs / vendors / individuals
208
Submitters currently banned
All Telegram; a ban clears that user's whole history
“Legal requests” covers the lot: law-enforcement requests, court orders, DMCA / UDRP / URS notifications, and acquisition or policy-change inquiries. Zero across the board in 6+ years. How each figure above is defined, and the queries behind it, are in Definitions.
How links stay safe
Every link is checked before it goes live, checked again in the background moments later, and then re-checked when it is clicked, at most once a week per link, not on every click. None of these checks is perfect; each catches what the others miss. The slow ones run after the response is flushed, so nobody waits while they finish.
Before the link goes livethe submitter waits on these
Unwrap open redirectors
Block list & high-risk list
Shortener shape
Newly-registered domain (RDAP)
Ad-smartlink pattern
Google Safe Browsing
Rate limit
response flushed · the link is live
After the responsenobody waits on these
VirusTotal reputation
urlscan.io evidence capture
AbuseIPDB submitter screen
↓ and then, for as long as the link exists ↓
On every later clickat most once a week per link
Safe Browsing re-check → remove
Refuse or remove
Contain: created with a 5 or 30-minute fuse, operator notified
Rewrite or record only
tg.pe runs no ads and sells no data; it redirects to the URL submitted, after stripping platform trackers (fbclid, gclid, igshid) and unwrapping known open redirectors.
Each stage's data source, fail mode, thresholds, and the reasoning behind the non-obvious choices are in the safety pipeline.
When something gets through
Removal authority comes from the public Terms every submitter accepts: phishing, malware, scams, CSAM, harassment. One Telegram ban soft-deletes every link that user ever created. The verified figure is a ~4-hour median from external report to removal. That median describes active response, not all removals: backlog cleanup and ban-cascade sweeps run against links that are much older, and mixing them in would pull the number out of shape. So the distribution is split in two.
Active response · 57.1%
Backlog & ban cascade · 42.8%
Under 1 h 62
1 – 24 h 220
1 – 7 d 201
7 d – 1 y 297
Over 1 y 65
845 removals with usable timestamps. Excludes 1,296 links soft-deleted in one batch on 2025-01-06, a one-time inventory cleanup whose synthetic timestamps would distort the distribution.
What the reports look like
313 external reports have arrived over the service's life, from national CERTs, anti-fraud vendors, and ordinary recipients; CIRCL, the US IRS, and Netcraft are about 76% of the volume, and the long tail confirms tg.pe sits on multiple watchlists.
The candid part is the misses, and what each one changed. The worst category (July 2022): a Tor-routed report flagged a tg.pe link as the entry point to a child-sexual-abuse archive; the operator confirmed and removed it within 8 hours. It is the only non-phishing abuse case in 5+ years, and the reason takedown, block list, and bans apply equally to the worst categories, not just phishing. The 2022 IRS campaign (199 reports in two quarters, more than every other quarter combined) is why ASN-level banning exists. A two-week run of cloned Orange France login pages in April 2021 is why IP blocking does. European bank clones (2021–2023), Société Générale, Crédit Agricole, La Poste, Deutsche Postbank, Alpha Bank, ČSOB, each reported by a different organisation, each removed within hours.
Per-year volume, median response time, and who reported what are in abuse reports.
Reporting abuse onward
Removing a link from tg.pe does not remove the threat from the internet. When the operator confirms a removed destination is malicious and classifies it, the indicator is reported onward so the underlying page can be acted on wherever else it is reaching people: 27 reports covering 5 destinations across 11 channels. Each report goes only to the channels that fit it; a mis-routed report burns reporter reputation, which is the scarce resource here. CSAM is never sent to these phishing/malware feeds; it is referred out of band to NCMEC, the IWF, or law enforcement.
The eleven channels sit at five different layers of the ecosystem, and which layer acts decides whether the threat actually goes away:
Browser & takedown vendors14
Netcraft · Google Safe Browsing · Microsoft SmartScreen · phish.report
Threat-intel feeds6
CIRCL MISP · abuse.ch ThreatFox
DNS registration layer4
Registrars via NetBeacon · one registry directly
Infrastructure intermediaries2
Cloudflare · an origin hosting provider
Impersonated brand1
The brand's own security team
One case, three responses
On 13 August 2026 a link to a phishing page impersonating flatmates.com.au on validationreq.top, a domain registered 75 minutes earlier that same morning, was submitted. The automated checks flagged the hours-old destination and contained the link, and the destination was reported onward to nine channels. Three of those layers responded differently, and the difference is the whole lesson:
tg.peat submission
Automated checks flagged the 77-minute-old domain and contained the link before anyone could click it.
Cloudflare18 min
Fastest to act, but the block was URL-level and the kit rotates its path on every visit, so sibling URLs stayed live. Fast at the wrong granularity.
.TOP registry3 h 17 m
Applied serverHold, removing the domain from DNS entirely. Slower, but at the granularity the attacker could not rotate around.
Registrar (via NetBeacon)no action in window
Had not acted by the time the registry suspension landed. One data point, not a pattern: routing through a third-party intake can simply be slower.
About 7.5 hours from registration to suspension (ticket #1022402). Fast at the wrong granularity, slower at the right one, and not yet at all: one case showing all three responses at once. A narrative write-up is on the operator's blog (English / 中文), and the hour-by-hour log is on the methodology page.
Read this as one case, not a rate. Two outbound reports are confirmed all the way to suspension and one cloaked smartlink came back “no threats found”, because monetisation redirectors serve benign content to datacentre scanners. That is n=2 closed and n=1 not. Nothing here should be read as “typically” or “usually”.
Who runs it & your data
Operator: Sean Wei, an individual in Taiwan 🇹🇼. No company, no legal entity, no business model; tg.pe is free and the operator absorbs all costs.
What is stored: short code + destination URL, submitter identifier (Telegram ID, or IP + country code for Web), timestamps, last Safe-Browsing check time, click count. Removed records are kept indefinitely as audit history.
What is shared: nothing that identifies a submitter. Only the destination of a confirmed-malicious link (its URL and domain, never who submitted it) is reported onward to abuse feeds.
Requests: phishing / malware / CSAM removed immediately regardless of who reports (no legal standing needed); a legitimate destination is not removed just because a brand owner dislikes it; submitter-identification only via a Taiwan court order under the PDPA; government takedowns without a legal basis are not honoured.
Legal interactions to date: zero, no subpoenas, court orders, DMCA / UDRP / URS, or acquisition / policy-change offers in 6+ years. If that changes, a future revision will say so.
Jurisdiction: the operator is under Taiwan law (PDPA); the .pe registry is in Peru, with no contact to date.
What is not measured yet
Three things this report deliberately does not claim: which brands are impersonated most often, what fraction of onward reports end in a confirmed takedown, and the registration-age split at population scale. Each is listed with the reason it is not there yet in what's not here yet. A fourth, RDAP coverage per TLD, now has a first measured pass published with its own limits attached.
Where a number in this report rests on a small sample, the sentence around it says so rather than rounding it up into a claim.
Contact
Abuse, or anything in this report:abuse@tg.pe · security.txt (RFC 9116), with OpenPGP via WKD for encrypted reports.
If anything here is useful (for research, for policy work, or if you run a similar service and want to compare notes), please reach out. tg.pe is a small operation, but small operators are part of how URL-level abuse gets contained, and the operator would rather share than keep it private.
The engineering and the data behind all of the above: Methodology.