I am not sure why this was not among the white listed domains.
It's actually a little bit more complex. wikimediafoundation.org is not in WMF infrastructure and doesn't go through our varnish/LVS/other bits (don't get me started). It also used to load outside modules T201022: Third party resources loaded by wikimediafoundation.org so it's a little bit scary to allow this as the website might have reflective XSS vulnerabilities and abuses can got hidden through URL shortener. I leave the decision to CPT and Secuirty though.
@Ladsgroup: Which outside modules are you referring to? As noted in the ticket you linked to, the ones previously identified have been disabled since August 2018.
I defer to Security and CPT on adding URL shortener to this domain, but want to make sure we are discussing it accurately. Are there additional external modules you are concerned about which are not discussed in T201022: Third party resources loaded by wikimediafoundation.org?