To be clear, I'm not an expert on security. If your life or livelihood depends on secure communications, please be sure to explore trusted resources published by experts.
From what I understand, one should use this method only if you're running an existing version of GPG Tools that you trust. Here are the steps I took:
- Went to https://gpgtools.org/ and downloaded the latest version
- Clicked on the link for the "please download and import our updated key"
- Got a big screen of scramble, and copied the URL from the browser window
- In Terminal, I used that URL to import the key: