Candidatures / .xmr / X2689T-T73877 · publié par l'ICANN le 7 octobre 2026 · instantané du 2026-10-08
.xmr
StandardActiveCake Labs LLC, KN Q1·Q25
Contrôle ultime déclaré : Vikrant Sharma, Sunali Sharma Q108 · Fiche ICANN ↗
§ 1 — Sens de la chaîne Q118·Q120
xmr - the name of its existing Web3 counterpart
xmr
§ 2 — Mission et objet Q133
.xmr exists to give the Monero ecosystem — one of the longest-running, most widely used privacy-focused open-source cryptocurrency projects, in continuous production since 2014 — a dedicated, community-aligned namespace of its own. The mission is to operate .xmr as naming infrastructure reflecting Monero's foundational commitment to financial privacy as a basic right, while meeting the
same technical, security, and consumer-protection standards ICANN requires of every gTLD registry.
Today, Monero ecosystem participants — the Core Team, wallet providers, exchanges, mining/node operators, community forums, and merchants — have no shared, ecosystem-specific namespace, relying on general-purpose TLDs that carry no signal of ecosystem legitimacy. That makes it harder to distinguish an authentic Monero-affiliated service from an imitation, a persistent risk since privacy-focused projects are frequent phishing targets. A dedicated namespace addresses that gap; the protocol's privacy properties remain a matter for the Monero network itself, not the registry.
Intended Registrants and Users
The Registry Operator anticipates registrants and users drawn from:
● The Monero Core Team, Monero Research Lab, and affiliated open-source development projects;
● Cryptocurrency exchanges, custodial and non-custodial wallet providers, and payment processors that support Monero;
● Mining pool operators, full-node operators, and infrastructure providers serving the Moneronetwork;
● Community organizations, forums, and educational or research initiatives focused on Monero and privacy-preserving technology; and
● Merchants, service providers, and developers who accept or build on Monero.
Related Activities
Cake Labs LLC intends to operate .xmr in parallel with .xmr, its existing Web3 TLD counterpart on Unstoppable Domains' Web3 naming infrastructure, consistent with the framework ICANN's Technical
Study Group on New gTLD Integrations with Alternative Naming Systems is developing: the two namespaces will maintain strict parallel control, so a name registered in one is only available in the other to the same registrant. Additional detail is provided in response to Question 222.
Because privacy-focused projects are frequent phishing targets, the Registry Operator will maintain a standing collaboration with cybersecurity researchers and community-nominated Monero contacts to identify and act on impersonating domains, and will establish a stakeholder input channel with recognized Monero community organizations [names TO BE CONFIRMED] to inform eligibility and abuse policy.
Monero, as a privacy-preserving cryptocurrency, operates in a regulatory environment that continues to evolve jurisdiction by jurisdiction. .xmr's privacy commitment operates strictly at the registry-service-design level — data minimization and ICANN-accredited privacy/proxy services within Consensus Policy — not the Monero protocol itself or any registrant's conduct. The Registry Operator will apply the same legal-compliance obligations to .xmr as to every other applied-for string, including sanctions screening and cooperation with lawful authorities, and does not intend .xmr to facilitate evasion of applicable law.
Sustainability
Demand for .xmr is anchored in an active, long-running community rather than speculative activity. Monero has maintained continuous mainnet operation and development for over a decade, with a stable base of exchanges, service providers, and community projects requiring durable, renewable naming infrastructure — typically maintained indefinitely rather than registered speculatively. This gives .xmr a registrant base with a structural incentive to renew, supporting the TLD's operation over the full term of the Registry Agreement and beyond.
§ 3 — Engagements et sauvegardes Q164–Q188
| Confiance accrue, risque pour le consommateur, secteur réglementé, déclarations à l'État, préjudice, fonction régalienne Q164–Q169 | Non à chacune |
|---|---|
| PIC de sauvegarde volontaires Q170·Q171 | Aucun · 90 candidatures de la ronde en proposent |
| Registry Voluntary Commitments Q172·Q173 | Aucun · 5 en proposent |
| Exemption du Code de conduite demandée Q185·Q188 | Non |
§ 4 — Toutes les autres réponses publiées
Toutes les autres réponses que l'ICANN a publiées pour cette candidature, dans l'ordre du formulaire. Les coordonnées (Q17–Q24) sont laissées à la fiche ICANN.
Q212Q4.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. If financial statements are provided by a Qualified Parent Entity (QPE), the CEO, President, CFO, and/or equivalent officer of the QPE must co-sign the certification document. The self-certification document must represent and warrant: SC4.2-1.1 - The applying entity and/or a QPE will fund the startup and long-term operation of all applied-for gTLD strings and (if applicable) currently operated gTLDs of a QPE. SC4.2-1.2 - The applying entity or QPE has at a minimum of US$50,000 plus 25% of the application base fee for each applied-for gTLD string in Cash and Cash Equivalents on the balance sheet of the provided financial statements, up to a maximum of US$300,000, designated to support the startup and operation of all of the applying entity’s applied-for gTLD strings. SC4.2-1.3 - The applying entity and/or its officers are bound by law in its jurisdiction to represent financial statements accurately and the applying entity is in good standing in that jurisdiction.
Q4.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. If financial statements are provided by a Qualified Parent Entity (QPE), the CEO, President, CFO, and/or equivalent officer of the QPE must co-sign the certification document. The self-certification document must represent and warrant: SC4.2-1.1 - The applying entity and/or a QPE will fund the startup and long-term operation of all applied-for gTLD strings and (if applicable) currently operated gTLDs of a QPE. SC4.2-1.2 - The applying entity or QPE has at a minimum of US$50,000 plus 25% of the application base fee for each applied-for gTLD string in Cash and Cash Equivalents on the balance sheet of the provided financial statements, up to a maximum of US$300,000, designated to support the startup and operation of all of the applying entity’s applied-for gTLD strings. SC4.2-1.3 - The applying entity and/or its officers are bound by law in its jurisdiction to represent financial statements accurately and the applying entity is in good standing in that jurisdiction.
Réponse fournie sous forme de document. L'ICANN ne publie pas les pièces jointes.
Q220Q5.1-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.1-1.1 - The applying entity will appropriately protect confidentiality of data and prevent unauthorized access to data and services. SC5.1-1.2 - The applying entity will maintain a mature, appropriately funded and staffed security program, following a recognized, modern security framework based on risk management (such as the ISO27000 series, COBIT, HITRUST CSF, legally required security frameworks, or equivalent). The security program must be in place prior to delegation, and exist through at least the period of the registry agreement. SC5.1-1.3 - The applying entity is aware of and has designed its systems and business to comply with the relevant privacy and security regulations for all countries in which it operates.
Q5.1-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.1-1.1 - The applying entity will appropriately protect confidentiality of data and prevent unauthorized access to data and services. SC5.1-1.2 - The applying entity will maintain a mature, appropriately funded and staffed security program, following a recognized, modern security framework based on risk management (such as the ISO27000 series, COBIT, HITRUST CSF, legally required security frameworks, or equivalent). The security program must be in place prior to delegation, and exist through at least the period of the registry agreement. SC5.1-1.3 - The applying entity is aware of and has designed its systems and business to comply with the relevant privacy and security regulations for all countries in which it operates.
Réponse fournie sous forme de document. L'ICANN ne publie pas les pièces jointes.
Q221Q5.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.2-1.1 - The applying entity will, no later than delegation of the Top Level Domain (TLD), establish a dedicated abuse point of contact responsible for addressing matters requiring expedited attention and providing a timely response to abuse complaints concerning any name registered in the TLD. SC5.2-1.2 - The applying entity will, no later than delegation of the TLD, establish, publish, and provide to ICANN the location of a mechanism for members of the public to submit reports of abuse in accordance with the current obligations of the Base RA and any Consensus Policies. SC5.2-1.3 - The applying entity has developed proposed measures for removal of orphan glue records for names removed from the zone when provided with evidence in written form that the glue is present in connection with malicious conduct (see Specification 6). SC5.2-1.4 - The applying entity has or will have at time of delegation, established policies for handling complaints regarding abuse. Such policies are to be maintained and posted publicly so that anyone can review the policies via the Internet and any other means deemed appropriate by the applying entity. The applying entity’s policies at a minimum should contain appropriate confirmation of the receipt of the abuse report, the process of review of the report, and actions that will be taken if the applying entity confirms the report is legitimate. SC5.2-1.5 - The applying entity understands that DNS Abuse is Phishing, Malware, Botnets, Pharming and Spam (when used to deliver other forms of DNS Abuse). The applying entity understands and is prepared to contribute to the mitigation or disruption of DNS Abuse in domains in the TLD zone. SC5.2-1.6 - The applying entity’s abuse response capabilities are resourced appropriately to ensure a timely and adequate investigation and response to reports of DNS Abuse. This includes capabilities to receive and evaluate evidence of DNS Abuse in reports, and to take action to stop or disrupt the DNS Abuse. SC5.2-1.7 - The applying entity is prepared to conduct periodic scans of its zone to identify if domains are being used to perpetrate DNS Abuse, and to maintain statistical reports of the scans, the findings, and actions taken.
Q5.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.2-1.1 - The applying entity will, no later than delegation of the Top Level Domain (TLD), establish a dedicated abuse point of contact responsible for addressing matters requiring expedited attention and providing a timely response to abuse complaints concerning any name registered in the TLD. SC5.2-1.2 - The applying entity will, no later than delegation of the TLD, establish, publish, and provide to ICANN the location of a mechanism for members of the public to submit reports of abuse in accordance with the current obligations of the Base RA and any Consensus Policies. SC5.2-1.3 - The applying entity has developed proposed measures for removal of orphan glue records for names removed from the zone when provided with evidence in written form that the glue is present in connection with malicious conduct (see Specification 6). SC5.2-1.4 - The applying entity has or will have at time of delegation, established policies for handling complaints regarding abuse. Such policies are to be maintained and posted publicly so that anyone can review the policies via the Internet and any other means deemed appropriate by the applying entity. The applying entity’s policies at a minimum should contain appropriate confirmation of the receipt of the abuse report, the process of review of the report, and actions that will be taken if the applying entity confirms the report is legitimate. SC5.2-1.5 - The applying entity understands that DNS Abuse is Phishing, Malware, Botnets, Pharming and Spam (when used to deliver other forms of DNS Abuse). The applying entity understands and is prepared to contribute to the mitigation or disruption of DNS Abuse in domains in the TLD zone. SC5.2-1.6 - The applying entity’s abuse response capabilities are resourced appropriately to ensure a timely and adequate investigation and response to reports of DNS Abuse. This includes capabilities to receive and evaluate evidence of DNS Abuse in reports, and to take action to stop or disrupt the DNS Abuse. SC5.2-1.7 - The applying entity is prepared to conduct periodic scans of its zone to identify if domains are being used to perpetrate DNS Abuse, and to maintain statistical reports of the scans, the findings, and actions taken.
Réponse fournie sous forme de document. L'ICANN ne publie pas les pièces jointes.
Q121As per Section 3(d) of Specification 11 of the Base Registry Agreement, a registry operator of a “generic string” may not impose eligibility criteria for registering names in the TLD that limit registrations exclusively to a single person or entity and/or that person’s or entity’s “Affiliates” (as defined in Section 2.9(c) of the Registry Agreement). “Generic String” means a string consisting of a word or term that denominates or describes a general class of goods, services, groups, organizations or things, as opposed to distinguishing a specific brand of goods, services, groups, organizations or things from those of others. Confirm that the applied-for string is not a “generic string” in which the applying entity intends to limit registrations exclusively to a single person or entity.
As per Section 3(d) of Specification 11 of the Base Registry Agreement, a registry operator of a “generic string” may not impose eligibility criteria for registering names in the TLD that limit registrations exclusively to a single person or entity and/or that person’s or entity’s “Affiliates” (as defined in Section 2.9(c) of the Registry Agreement). “Generic String” means a string consisting of a word or term that denominates or describes a general class of goods, services, groups, organizations or things, as opposed to distinguishing a specific brand of goods, services, groups, organizations or things from those of others. Confirm that the applied-for string is not a “generic string” in which the applying entity intends to limit registrations exclusively to a single person or entity.
true
Q222If the applying entity wishes to provide any additional information or supporting materials that the applying entity believes may be of interest to the public or relevant to the application, please include them here.
If the applying entity wishes to provide any additional information or supporting materials that the applying entity believes may be of interest to the public or relevant to the application, please include them here.
Cake Labs LLC provides this supplementary information on the relationship between the applied-for TLD .XMR and its existing Web3 TLD counterpart, .XMR, on Unstoppable Domains' Web3 naming infrastructure. It does not modify, and is not incorporated into, the applying entity's binding commitments elsewhere in this application.
Parallel Operation of the TLD and its Web3 TLD Counterpart
The TLD .XMR will operate in parallel with its Web3 counterpart, .XMR, kept synchronized so that a Domain Name registered in one is, wherever practicable, held by the same registrant in the other. A name registered in only one namespace is blocked from third-party registration in the other, available only to the existing registrant.
Technical Compatibility of the Web3 Namespace
The Web3 TLD .XMR is constrained to avoid technical incompatibility with the DNS or ICANN's labeling rules:
● No registration string is permitted in the Web3 namespace that would violate ICANN's labeling rules — no emoji, no strings exceeding DNS label-length limits, none that would fail standard Punycode (xn--) conversion, and no non-ASCII characters a compliant IDNA implementation would reject.
● The Web3 namespace is a separate, non-DNS naming and resolution system; it neither publishes nor depends on DNS resource records.
● Where IPFS content addressing is used with the Web3 namespace, it is limited to file storage and retrieval; the applying entity does not use IPFS to host the Web3 name-resolution service itself.
Alignment with the Technical Study Group and the RSEP Process
ICANN's Technical Study Group on New gTLD Integrations with Alternative Naming Systems is examining the security/stability implications of integrating new gTLDs with alternative (e.g., blockchain-based) naming systems. Once awarded the TLD, the applying entity intends to pursue this parallel operation model through ICANN's RSEP process, consistent with whatever framework that work
produces, and will keep its policies compatible with the finalized framework rather than treating this description as fixed.
Any future RSEP framework here may be designed around matching-string pairs, as .XMR and .XMR are, so this response is intended to fall within it once available. For any other applied-for strings whose TLD and Web3 counterpart do not share a string, the applying entity will still apply the same registrant
matching and mutual-blocking approach voluntarily, outside the RSEP.
Pre-Existing Rights Protection in the Web3 Namespace
The Web3 TLD .XMR has been preemptively screened against WIPO/TMCH brand lists, with matching names blocked from registration there. Separately, Unstoppable Domains' Terms and Conditions already prohibit knowingly claiming or purchasing a Web3 Domain Name identical to a third party's brand or trademark. Any unresolved rights conflict can be addressed under that prohibition.
Launch Sequencing
Immediately after the TMCH Sunrise period, all then-existing Web3 Domain Names in .XMR will be blocked from registration in the TLD, pending the sequence below:
● A valid Sunrise application matching an existing Web3 Domain Name will be reviewed, and the Web3 registration removed in favor of the Sunrise applicant unless both share common control, per the prohibition above.[https://unstoppable.ai/terms]
● Once Sunrise concludes — including resolution of any name contention — all remaining Web3 Domain Names will be registered as corresponding Domain Names in the TLD, to the same registrant.
● Where a Web3 registrant's data does not meet the TLD's registrant-data standards, that registrant will be asked to update it before, or promptly after, the corresponding Domain Name is registered in the TLD.
Q223By submitting this Application, the applying entity confirms that it is submitting this Application with a good faith (“bona fide”) intent to operate the gTLD for which it has applied, and that the applying entity has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.
By submitting this Application, the applying entity confirms that it is submitting this Application with a good faith (“bona fide”) intent to operate the gTLD for which it has applied, and that the applying entity has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.
true
Q224By submitting this Application, the applying entity confirms that it has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.
By submitting this Application, the applying entity confirms that it has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.
true