Your site ID is public. It is in the snippet on your own pages, so anybody who views source can read it.
What that means, stated plainly
Nothing can authenticate a beacon sent from a public page. Skomi checks the Origin header, but that check is not authentication and cannot be: any client can send any value it likes. So it is possible for someone to post hits to a real site's endpoint.
The cost is not a surprise bill, because going over your allowance is opt-in and capped. The cost is polluted reports, and credits spent on visits nobody made.
Domain verification does not fix this. It would prove who owns the domain, which is a different question from whether a particular request came from it.
What Skomi does instead
It notices, and it hands you the one fact you can act on: the address.
When a single address sends implausible volume in a short window, Skomi records an alert holding the address, how many hits it sent, and which product counted them. Eighty hits a minute means something very different for page views than for feedback submissions.
From the alert you can add the address to your exclusion list in one step. After that the hits are dropped at ingestion and stop reaching your reports or your bill. See excluding traffic for how those rules behave.
About the address it shows you
This is the only place Skomi shows you a visitor's IP address.
The address is stored with every visit, and the privacy policy says for how long, but it appears in no report, no breakdown and no export. This panel is the exception, and it is deliberate: an alert that will not tell you which address to block is an alert nobody can act on.
An alert is bounded in two ways. Only an address that is already over the threshold reaches one, and the rows expire on their own.
What an alert is not
It is not a judgement that the traffic is malicious. A misconfigured script on your own staging host looks the same from here, and so does a proxy that many real visitors share. Look at the address before you exclude it.
Related: excluding traffic, installing the snippet.