@rozzin Maybe I am misunderstanding, but the poisoning prevents people from updating keys to check trust paths. The proposed replacement service https://keys.openpgp.org/ does not link ID ( email address) to the public key, unless asked to. And more importantly from a WoT is does not have any third party signatures. So can't be used to follow a trust path
@rozzin help me out! what am I doing then when I get a new key from someone I've not communicated with, and check the signatures to see if there are any people in common ?