First, I apologize for the late review. It appears that you may have already had a secdir review from the revision notes, but I could not find the review in my archive.    In general it seems the document is in good shape and understandable. I think the document is ready with nits.  Here are a few minor issues: 1) it might be useful to add something about what is in scope and out of scope for this document.  What I have in mind is to state the assumption that the TZ data has been securely transmitted from the contributors to the publishers to the root provider with its integrity intact and that the servers are expected to maintain the integrity of the data.  2) It might be useful to qualify the 3rd paragraph as applicable when discovery is done through DNS SRV records.   Cheers, Joe