the current code in dirmngr applies @kristianf's CA whenever the keyserver hostname is the default hostname.
But if the default ever changes away from hkps.pool.sks-keyservers.net (e.g. if a distributor patches it), then it is inappropriate to permit @kristianf's CA to authenticate it.