the current code in dirmngr applies @kristianf's CA whenever the keyserver hostname is the default hostname.
But if the default ever changes away from hkps.pool.sks-keyservers.net (e.g. [if a distributor patches it](https://github.com/NixOS/nixpkgs/pull/63952), then it is inappropriate to permit @kristianf's CA to authenticate it.