tg.pe is a small, free URL shortener run by one person. This page is an honest look at what happens behind every link, and at the people who try to use it for phishing and scams.
It is the short version, about five minutes. The engineering, every definition, and the full data tables are on Methodology.
A stranger reported a scam
A phishing email in German, dressed up as a parcel delivery, reached Stefano with a “Pay now” button pointing at a tg.pe link. He forwarded it to abuse@tg.pe: “this looks like a SPAM Mail and abuse of your service.” Fifty minutes later the link was a 404, the account was banned, and the destination was on the block list. His reply: “Awesome, didn't expect a reply.”
Reporting abuse online usually goes into a black hole. A one-person shortener has no abuse budget; what it has is somebody reading the mailbox.
The numbers
About one link in fifteen turns out to be abuse.
33,093
Short links created
Lifetime, over 6 years 10 months
2,168
Removed for safety or abuse
6.6% of everything created
~4h
Median external report to removal
Fastest on record: 50 minutes
0
Legal requests, ever
In 6+ years of operation
30,442
Active links served
410,482
Clicks served
Since April 2026; the top 10 links are about a third
313
External abuse reports
Lifetime, from CERTs / vendors / individuals
208
Submitters currently banned
All Telegram; a ban clears that user's whole history
“Legal requests” is meant in the broad sense, listed in full under Who runs it below. How each number is defined, and the query behind it, are in Definitions.
How links stay safe
Every link is checked three times: before it goes live, again a moment later, and once more when somebody clicks it.
No single check is reliable on its own, so they overlap and each catches what the others miss. The slow ones run after the page has already been sent back, so nobody waits for them.
Before the link goes livethe submitter waits on these
Unwrap open redirectors
Block list & high-risk list
Shortener shape
Newly-registered domain (RDAP)
Ad-smartlink pattern
Google Safe Browsing
Rate limit
response flushed · the link is live
After the responsenobody waits on these
VirusTotal reputation
urlscan.io evidence capture
AbuseIPDB submitter screen
↓ and then, for as long as the link exists ↓
On every later clickat most once a week per link
Safe Browsing re-check → remove
Refuse or remove
Contain: the link dies by itself in 5 minutes unless the operator clears it
Rewrite or record only
tg.pe runs no ads and sells no data. It sends you to the URL that was submitted, minus the tracking codes platforms bolt on (fbclid, gclid, igshid), and with known redirect chains unwrapped first so the real destination is the one that gets checked.
When somebody reports a bad link, it is usually gone within about four hours.
The right to remove comes from the public Terms every submitter accepts: phishing, malware, scams, CSAM, harassment. Banning one Telegram account removes every link that account ever created.
That four-hour median covers active response only. Links cleared long after the fact are much older: backlog sweeps, and the cascade when a ban wipes an old account's history. Averaging those in would hide the response time instead of describing it, so the chart keeps the two apart.
Active response · 57.1%
Backlog & ban cascade · 42.8%
Under 1 h 62
1 – 24 h 220
1 – 7 d 201
7 d – 1 y 297
Over 1 y 65
845 removals have usable timestamps. A one-time inventory cleanup on 2025-01-06 removed 1,296 links in a single batch; they all share one made-up timestamp, so they are left out.
What the reports look like
313 reports have arrived over the service's life, from national computer-emergency teams, anti-fraud companies, and people who simply received the email. Three senders are about 76% of them: CIRCL, the US IRS, and Netcraft. The rest trickle in one at a time from everywhere else, which is how you can tell tg.pe sits on several watchlists.
The misses are on the record too, and most of them changed something.
2022 Jul
The worst category: a report sent anonymously over Tor flagged a tg.pe link as the way into a child-sexual-abuse archive. Confirmed and removed within 8 hours. It is the only abuse case in 5+ years that was not phishing, and the reason removal, block lists, and bans cover the worst categories too.
2022
The IRS campaign (199 reports in two quarters, more than every other quarter combined) is why a whole hosting network can be banned at once, not just one account.
2021 Apr
A two-week run of cloned Orange France login pages is why IP blocking exists.
2021–2023
European bank clones: Société Générale, Crédit Agricole, La Poste, Deutsche Postbank, Alpha Bank, ČSOB, each reported by a different organisation, each removed within hours.
Per-year volume, median response time, and who reported what are in abuse reports.
Reporting abuse onward
Deleting the short link does not delete the scam page, so tg.pe reports the destination to whoever can actually take it down.
Once a removed destination is confirmed malicious and classified, its address goes onward: 27 reports covering 5 destinations across 11 channels.
Each report goes only to the channels that fit it. A misfiled report costs credibility with that channel. CSAM never goes to these phishing and malware feeds; it is referred out of band to NCMEC, the IWF, or law enforcement.
The eleven channels sit at five levels of the internet, and which level acts decides whether the scam actually goes away:
Browser & takedown vendors14
Netcraft · Google Safe Browsing · Microsoft SmartScreen · phish.report
Threat-intel feeds6
CIRCL MISP · abuse.ch ThreatFox
DNS registration layer4
Registrars via NetBeacon · one registry directly
Infrastructure intermediaries2
Cloudflare · an origin hosting provider
Impersonated brand1
The brand's own security team
One case, three responses
On 13 August 2026 somebody submitted a link to a fake flatmates.com.au login page. It sat on validationreq.top, a domain registered 75 minutes earlier that same morning. The automated checks caught how new the domain was and contained the link, and the destination went out to nine channels. Three of those levels acted, each of them differently:
03:0004:0005:0006:0007:0008:0009:00
tg.pecontained the tg.pe link
at submission
Automated checks flagged the 77-minute-old domain and contained the link before anyone could click it.
Cloudflareblocked one URL path
18 min
Fastest to act, but it blocked one exact address, and the scam kit hands out a new address on every visit. The next one still worked. Fast, at the wrong size.
.TOP registryremoved the domain from DNS
3 h 17 m
Pulled the whole domain out of DNS (serverHold), so every address on it went dark at once. Slower, but at a size the attacker could not route around.
Registrar (via NetBeacon)
no action in window
Had not acted by the time the registry suspension landed. One case, not a pattern: going through a third-party intake can simply be slower.
About 7.5 hours from registration to suspension (ticket #1022402). The full story is on the operator's blog (English / 中文); the hour-by-hour log is on the methodology page.
Two onward reports are confirmed all the way to a suspension. A third came back “no threats found”, because that destination showed a harmless page to the scanner and the real thing to real visitors. Two confirmed is not a pattern, so read none of this as “typically” or “usually”.
Who runs it & your data
One person in Taiwan, no company, no business model. Nothing that identifies a submitter ever leaves the service.
Operator
Sean Wei, an individual in Taiwan 🇹🇼. No legal entity behind it; tg.pe is free and the operator absorbs all costs.
What is stored
the short code and where it points, who submitted it (a Telegram ID, or an IP address and country code from the web form), timestamps, when it was last safety-checked, and a click count. Removed records are kept indefinitely as audit history.
What is shared
nothing that identifies a submitter. Only the destination of a confirmed-malicious link (its URL and domain, never who submitted it) is reported onward to abuse feeds.
Requests
phishing, malware, and CSAM are removed straight away, whoever reports them and with no legal standing needed. A legitimate destination is not removed just because a brand owner dislikes it. Who submitted a link is disclosed only under a Taiwan court order (PDPA). A takedown demand from a government with no legal basis behind it is refused.
Legal interactions to date
zero, no subpoenas, court orders, DMCA / UDRP / URS, or acquisition / policy-change offers in 6+ years. If that changes, a future revision will say so.
Jurisdiction
the operator is under Taiwan law (PDPA); the .pe registry is in Peru, with no contact to date.
What is not measured yet
This report leaves three questions blank instead of guessing at them.
Which brands get impersonated most often.
How often an onward report ends in a confirmed takedown.
How many destinations are brand-new domains across everything submitted, not just the flagged ones.
Each one, and why it is missing, is in what's not here yet. A fourth question, how much registration data is even readable per top-level domain, now has a first measured answer, with its own limits attached.
Where a number in this report rests on a small sample, the sentence around it says so rather than rounding it up into a claim.
Contact
Abuse, or anything in this report:abuse@tg.pe · security.txt (RFC 9116), with OpenPGP via WKD for encrypted reports.
If any of this is useful, for research, for policy work, or because you run something similar and want to compare notes, please get in touch. tg.pe is a small operation, but small operators are part of how URL-level abuse gets contained, and the operator would rather share than sit on it.
The engineering and the data behind all of the above: Methodology.