@deerfox i'm thinking something about creating a public/private keypair, put the public part inside a DNS TXT record and upload the (...)
@deerfox (...) private part to the instances to verify it