# Reporting Abuse

*Last updated: July 27, 2026*

**tmgo.to** is a link shortening and QR code service from Team Moore LLC. Short links are useful precisely because they are short — which also makes them attractive to people who want to hide where a link goes. We take that seriously. This page is how you tell us about a tmgo.to link being used to harm someone, and what happens after you do.

## How to report

Email **abuse@tmgo.to**. For vulnerabilities in the service itself, use **security@tmgo.to**. Both reach a monitored mailbox, and a machine-readable copy of these contacts is published at [/.well-known/security.txt](/.well-known/security.txt).

You do not need an account, and you do not need to be the injured party.

## What to include

The more of this you can give us, the faster we can act:

- **The full short link**, including the code after the slash — for example `https://tmgo.to/abc123`. A report we cannot resolve to a specific link is very hard to act on.
- **What it does** — where it leads, and what makes it harmful.
- **How you encountered it** — an email, a text message, a printed QR code, a social post. If it arrived by email, the full message including headers is the single most useful thing you can send.
- **When** you saw it.

Please do not visit a suspected phishing or malware link to gather detail for us. Send us the link and let us look at it safely. If you have already entered credentials somewhere, change that password now and contact the affected provider — that matters more than reporting to us.

## What we prohibit

The [End User License Agreement](/legal/eula) section 4.3 sets out prohibited uses in full. In short, tmgo.to links and QR codes may not be used for phishing or credential harvesting, impersonation or brand-jacking, cloaking or redirect chains intended to evade detection, malware distribution, unlawful activity, scams, or content that harasses or endangers people.

## What happens after you report

- **We acknowledge** your report to the address you wrote from.
- **We investigate.** For a live phishing or malware link, our first priority is to stop it resolving — which we can do independently of any wider decision about the account.
- **We disable rather than delete.** A disabled link returns HTTP 410 Gone and a notice page. We keep the underlying records so we can answer follow-up questions from you, from an impersonated brand, or from law enforcement.
- **We may suspend or terminate the account** responsible, under EULA sections 4.5 and 7.3.
- **We report onward** where it helps — typically to the Anti-Phishing Working Group, and to the registrar and hosting provider of the destination.

We are a small team. We aim to acknowledge reports within one business day, and to act on credible reports of live phishing or malware considerably faster than that. We would rather state a target we can actually meet than one that sounds better.

We will not share your identity with the account holder.

## What we cannot do

**Static QR codes** encode their destination directly in the printed image. They never contact our servers, so once one is printed we cannot disable it, redirect it, or see it being scanned. If a static QR code is being used maliciously, the destination site's hosting provider is the effective place to report it.

**We do not control destination websites.** Disabling a tmgo.to link stops that link. It does not take down the site it pointed at, which usually needs a report to that site's host or registrar.

## Law enforcement and preservation requests

Send requests to **abuse@tmgo.to** with "Law enforcement" in the subject line. Please include the specific short links or account identifiers at issue, the legal basis for the request, and contact details we can verify. We respond to valid legal process, and we will preserve records on request while a matter is pending.

## Security vulnerabilities

If you have found a vulnerability in tmgo.to, email **security@tmgo.to**. Please give us a reasonable opportunity to fix the issue before disclosing it publicly. We do not currently run a paid bug bounty, but we are glad to credit you if you would like.

Please do not run automated scanning or load testing against the service, do not access, modify, or delete data belonging to other customers, and do not use a finding to disrupt the service for anyone else. Testing against your own workspace is fine.
