So, dnsdir assigned me reviewing this draft, but I basically failed to find DNS in it :-) And I'm afraid I don't know ACME well, so I'm marking this draft as "Ready" just not to block it on DNS. Maybe I've just missed it, so point me to the DNS aspects, please. Still, let me at least comment around this DNS redirection. The parent RFC 9115 only considers CNAMEs, at a glance. It feels like for future the SVCB/HTTPS records should be considered a well (in a different draft/RFC). They were designed with modern web CDN needs in mind, and among other features they support "redirecting" a zone apex, which seems practically important. For a trivial example, you can't put a CNAME at example.com, only at www.example.com. [SVCB/HTTPS] https://datatracker.ietf.org/doc/draft-ietf-dnsop-svcb-https/