You need to isolate the problems you’re describing. You’re mixing impersonation, data integrity, and discovery into one bridge issue.
Your pubky (a public-key-signed DNS record in Mainline DHT) tells anyone where to find the canonical endpoints for your data. Any app can resolve those endpoints...