I am an assigned INT directorate reviewer for . These comments were written primarily for the benefit of the Internet Area Directors. Document editors and shepherd(s) should treat these comments just like they would treat comments from any other IETF contributors and resolve them along with any other Last Call comments that have been received. For more details on the INT Directorate, see https://datatracker.ietf.org/group/intdir/about/ . Based on my review, if I was on the IESG I would ballot this document as YES. The following are other issues I found with this document that SHOULD be corrected before publication: The example has the wrong value for the token. The authors have already corrected this for future versions of the draft. The duration of authorization is not discussed explicitly in the document. The natural assumption would be that it is limited to the DNS record lifetime, but I could also imagine it being a matter of local policy or being incorporated into the claim. It would be nice if the document said something on this topic, but it's not a showstopper for me. It might be good to have a version in the token format, though the "_splitdns-challenge" label could also be updated in the future if needed, e.g. to "_splitdns-challenge-v2".