Another one: > If the DPV request does not specify a validation policy, the server > response MUST indicate the one that was used. In such a case, the > client must verify that the one selected by the server is appropriate. I propose: "A server response MUST indicate the validation policy that has been used, and a client MUST verify that it is acceptable."