@vampirdaddy I think checking the sig should be enough, yes.
Since this is a likely non-sensitive newsletter, it wouldn’t even have to be encrypted. The initial subscription mail just has the intention of telling the receiver mailserver that the newsletter address is genuine.