Right now, DHCP server's dynamic-dns-update mechanism completely trusts the client that the hostname is in the domain where it's supposed to be.
However, nothing prevents a client from sending an entry like vyos.net to the server and poisoning its hostname database.
I believe there should be an option to specify permitted domains and reject updates where hostnames do not belong to any of those.