I go into a little more detail about the idea in the note below. But I would change what I said about relays signing all the content they send to clients. Instead, once per WSS connection, some sort of proof could be sent by the relay to the client to show it's the relay belonging to the public key that the client is using to track it.