Good point, I had forgotten that Rob of Errata Security was given an email to verify and it was proven to be legitimate:
> So as I blogged before, the emails contained DKIM information, which the original reporters could and should have verified. So I eventually got a copy of the email and run DKIM verification on it. It passed:
https://twitter.com/erratarob/status/1322007153415200768
I think he's pretty active (and well-respected) on HN.