Even more so, while slightly advanced, you can set up a OTP verification on the front end before rendering things. JS code calls your backend which receives a OTP code (generated through some private key), and verifies this using public key. If obfuscated/minified properly, it would take some effort to reverse engineer properly.
Additionally you can do sneaky things like make a request to your backend trigger on some random large time interval, where the Origin header is passed, so you can see which domain the client site got rendered from, and then return some displayed warnings about using a fake copied website.