> Optional: verify public key on Keybase.<p>For organizations publishing employee keys via Web Key Directory can also be an additional signal that the key is trustworthy.<p>It's also quite simple: for example exporting the key 5C090ED7318B6C1E (binary, <i>not</i> armored) and putting it on this exact URL: <a href="https://datadoghq.com/.well-known/openpgpkey/hu/964aj6q73iatngoya1q7qs4r6utpmb4g" rel="nofollow">https://datadoghq.com/.well-known/openpgpkey/hu/964aj6q73iat...</a> is enough to discover the key using e-mail address.<p>This post goes into more detail: <a href="https://spacekookie.de/blog/usable-gpg-with-wkd/" rel="nofollow">https://spacekookie.de/blog/usable-gpg-with-wkd/</a><p>WKD is used by Linux distros (ArchLinux, Gentoo, Debian...) and kernel.org itself: <a href="https://www.kernel.org/category/signatures.html#using-the-web-key-directory" rel="nofollow">https://www.kernel.org/category/signatures.html#using-the-we...</a> as well as some OpenPGP sites (e.g. ProtonMail).