Until your tooling automatically makes a request to a now-untrusted server and trusts its response...
Any tool that automatically assumes that a URL in a Go module import is 'trusted' is just a broken tool.
If you haven't added a replace directive to your go.mod, then you certainly haven't replaced all instances of the old URLs with updated ones.