AFAIK the latter is correct.
Well does it? If the policy propagation goes _Site_ - Domain - OU - Nested OU is it possible, (though probably no-one ever though much about it because most people, myself included, all tend to see the heirarchy as Domain - Site - OU etc.), that it could be set at the site level which would over-ride the Domain?

Just throwing it out there... I'm not going to try it on my production network....