All over the documentation, we mention "domains" while (I think) we mean "fully qualified domain names".
Example: we are not talking about pafdemopublisher.com, but rather about www.pafdemopublisher.com.
Otherwise, there is no way that the "domain" will host an identity endpoint, or it is a very strong constraint to put on participants.
So, I think we should be more explicit in the docs and talk about fully qualified domain names, FQDN in short.