On Monday, the .ME domain registry — operated by the government of Montenegro — placed t.me on Server Hold, instantly breaking every short link Telegram has ever generated. No warning, no public explanation, just a flag flipped in a database in Podgorica, and suddenly millions of users couldn’t reach channels, groups, or messages.

The predictable response was already forming before the DNS changes had finished propagating: this was censorship, a coordinated attack on a platform that refuses to play nice with governments. Telegram itself fed that narrative, posting that it was “working to resolve the issue” without clarifying that the “issue” was a registry action, not a DDoS or a technical glitch.

But the censorship story is the wrong story. The real story is more embarrassing — and more instructive.

The Single Point of Failure Wasn’t a Government. It Was a Business Decision.

Telegram chose to build its link-shortening infrastructure on a Montenegrin ccTLD. Not .com, not .org, not a domain under its own control — but a two-letter country code belonging to a nation of 600,000 people. The .ME registry’s terms of service give it broad discretion to suspend domains for any number of reasons, including “inaccurate or incomplete” WHOIS data, failure to respond to registry inquiries, or violation of acceptable-use policies that the registry can revise at will.

This is not a story about censorship. It’s a story about counterparty risk. Telegram, a company that markets itself as resilient to state pressure, voluntarily placed a critical piece of its infrastructure in the hands of a registry that answers to a different set of laws, regulators, and political winds. The suspension may have been triggered by a routine compliance check, a billing dispute, or a request from a third country — we don’t know yet. What we do know is that Telegram had no backup domain, no seamless failover, and no apparent plan for what happens when a small Balkan nation’s domain administrator decides your domain is a problem.

One network engineer at a competing messaging platform put it bluntly in a private Slack channel on Monday afternoon: “If your entire link ecosystem can be killed by a single registry action, you didn’t get censored. You got caught with your pants down.”

The Irony of the Sovereign Internet

There is a deep irony here. Telegram has spent years positioning itself as the platform that cannot be silenced — the app that resists takedown requests, that operates across jurisdictions, that refuses to appoint local representatives. And yet its link infrastructure was more fragile than a small business’s WordPress site. A single administrative hold, and the whole thing collapsed.

This is not an argument for more regulation. It’s an argument for basic operational competence. If your platform’s value proposition is resilience, you don’t route your traffic through a chokepoint controlled by a registry that can be pressured by any government with diplomatic leverage over Montenegro. You don’t build a single point of failure and then act surprised when it fails.

The broader lesson applies well beyond Telegram. Every company that has spent the last decade building on someone else’s infrastructure — cloud providers, domain registries, certificate authorities, app stores — has accumulated a portfolio of unexamined dependencies. Most of them will never be tested. But when one is, the result looks less like a geopolitical drama and more like an outage post-mortem that should have been written years earlier.

What Telegram Should Do Next

Telegram will almost certainly get the domain back. The registry will face pressure, the company will make the right calls, and t.me will return to service. The danger is that the company — and its most vocal supporters — will treat this as a censorship victory rather than an infrastructure failure.

That would be a mistake. The correct response is not a blog post about free speech. It’s a migration plan. Telegram should move its short-link infrastructure to a domain it controls under a TLD with clear, predictable governance — or better yet, to multiple domains across multiple TLDs with automatic failover. It should publish a post-incident review that acknowledges the single point of failure and explains what’s changing. And it should stop pretending that operational negligence is the same thing as persecution.

The platforms that actually resist pressure don’t do it with rhetoric. They do it with architecture. Telegram just learned that lesson the hard way. The question is whether it will learn the right one.

Sources