Frequently asked questions
Is XCIM a standard?
No. XCIM v0.1 is a draft design under development and has not been submitted or adopted as an IETF standard.
Is the network live?
No production verification infrastructure or trust assertions are active. xcim.net reports the public operational state.
Does XCIM replace SPF, DKIM, or DMARC?
No. Those mechanisms continue to authenticate sending infrastructure and domains. XCIM explores evidence about application-scoped recipient authorization.
Does a valid proof guarantee inbox delivery?
No. The recipient system retains full control over filtering, abuse prevention, trust selection, and delivery.
Does XCIM publish recipient addresses?
The design goal is to avoid exposing plain recipient identifiers in public infrastructure. The precise privacy-preserving representation is not yet normative and remains subject to security review.
Can I implement it now?
You can review the architecture, but interoperable implementation claims should wait for canonical schemas, serialization rules, vectors, and resolver behavior.
How can I contribute?
Review the documents, open questions in status, and the governance process, then use the published contact channel.