Security News Telegram has applied for the .gram TLD, which could allow username-to-domain sites and elevate brand impersonation and phishing risks.

Khushal

Level 16
Thread author
Verified
Top Poster
Well-known
Apr 4, 2024
703
5,212
1,469
TL;DR
Telegram has applied for the .gram top-level domain through ICANN’s 2026 round. If approved, Telegram usernames could become web-addressable domains with AI-generated websites.
This creates a new namespace for phishing, impersonation, and threat actor self-promotion, operated by a platform already deeply embedded in the threat landscape.
Telegram would become the registry operator, making it the gatekeeper for abuse reports and takedowns across potentially a billion domains.
The July 2026 t.me serverHold incident showed what happens when Telegram depends on someone else’s domain infrastructure. Owning .gram would flip that dynamic but also transfer compliance liability onto Telegram.
Security teams should start monitoring the ICANN approval process, treat Telegram username squatting as a brand protection issue, and prepare to add .gram to their detection pipelines.

 
Important distinctions

This should be treated as a proposal or report about an application, not as evidence that .gram has been approved or delegated. An ICANN application does not guarantee approval, registry operation, or eventual public availability.

Several points also require independent confirmation:

  • Telegram usernames would not automatically become working .gram domains. That would depend on the final registry policy, eligibility rules, technical deployment, and DNS delegation.
  • The applicant, registry operator, and entity responsible for abuse handling may not be identical in every arrangement. Those responsibilities should be confirmed from ICANN’s official application and registry documents.
  • A reported “July 2026” t.me incident cannot currently be used as established historical evidence if the date is in the future or has not been independently documented.
  • The number of possible domains should not be equated with the number of Telegram accounts or usernames. Many names may be reserved, unavailable, duplicated across systems, or never activated.

If the application is genuine and eventually succeeds, .gram could create a meaningful additional phishing and impersonation surface. Security teams could monitor official ICANN application and delegation records, reserve or watch relevant brand terms where possible, and add the new suffix to detection rules only after it is actually delegated and usable.

Any specific .gram domain should still be assessed using normal evidence: registration and DNS history, certificate details, hosting infrastructure, page behavior, authentication indicators, and reputable malware/phishing feeds. The TLD alone would not establish that a site is malicious or trustworthy.

The most reliable next step is to verify the claim against ICANN’s official 2026-round materials and registry records before treating the reported operational details as confirmed.
 

You may also like...