Unsigned addresses carry no evidence
The question is never whether an address looks plausible. It is whether anything connects it to the party who controls the market, and an unsigned string connects to nothing.
What signing establishes
That the holder of a specific key published this specific list. Without it, an address is fifty six characters that somebody typed. It may be correct. Nothing about it demonstrates that, and the effort required to produce a convincing incorrect one is small.
Sources that feel authoritative and are not
- A forum post with a long account history, since accounts are bought and stolen routinely.
- A directory with a professional appearance, including this one.
- A message that arrived during an outage offering a working replacement.
- A search result, which reflects optimisation rather than authenticity.
Why this site says so about itself
Publishing addresses and then telling readers to trust the publisher is the arrangement every phishing operation depends on. A directory that points at the signature instead is telling you how to stop needing the directory, which is the only honest position available to one.
When no signed announcement exists
Then you are relying on continuity rather than proof: an address you have used before, saved before you needed it. That is weaker evidence and it is real. Fresh strings from unfamiliar places during an outage are neither.
The practical rule
Signed and verified is best. Previously saved and unchanged is acceptable. Newly encountered and unsigned is not usable, whatever the source, and the moment it feels most urgent to relax that rule is precisely the moment it exists for.
The one case where continuity substitutes
An address you saved months ago and have used repeatedly since carries evidence of a different kind: it has behaved consistently over time and nothing prompted you to acquire it. That is weaker than a signature and genuinely useful, and it is why keeping a list matters even for people who never intend to run a verification command.