@MetalSamurai @sashafox @dalias @sam @atomicpoet @fediversenews
There are a couple of mitigations for this...
A magic word of 45:£5-+ffguj (non dictionary)
A OTP magic word with an expiry. (Has some DDOS attack surfaces)
Etc. Etc.
I'm sure we should be talking to @jpmens for creative ways to use DNS for validation...