Who can receive which key?
The central question is not merely whether a message is encrypted, but which endpoints receive the key. New devices, recovery and group entry need explicit rules.
Key verification helps only when warnings are visible and people compare changes through an independent channel.
