When external notifications are configured, a specific URL is included in the notification. This URL contains a 2-day valid token that allows adding the hostname to a custom URL Group without requiring a backend login.
It would be useful to introduce an option to disable this behavior on a per-notification-mechanism basis.