So the DSA Trusted Flaggers list was released recently, and it lacks any mechanism through which to verify that a trusted flagger is really contacting you.
It just gives email addresses in a table that's cut-off by their page design, and well, we all know how secure email is.
I would have expected, given the security and legal implications involved, that the DSA Trusted Flaggers list would include public keys for verification of contact requests, whether GPG or otherwise.
https://digital-strategy.ec.europa.eu/en/policies/trusted-flaggers-under-dsa