Hey,
Sure you could add some mechamism to prove you own the domain where you
want the rc updates to be sent, but things can get rather complex.
Google uses, or at least used to use, the following to do exactly that:
On request provide a auth file to the user which includes some unique identifier. Require this file to be made available via the domain in question. Have the user point to the location where it is made available and check if it is actually there. If so, domain authenticated.
That seems rather simple to create.
Cheers
-- Jeroen De Dauw http://www.bn2vs.com Don't panic. Don't be evil. --