Providers may change the selector and remove the old selectors public key from DNS, a few years ago I noticed that for gmail. It would be nice it it was possible to import keys to DKIM verifier in such a case, but there should be a warning that it was provided by the user.
(Yes, I am aware that DNS can be faked as well, but that is not as easy as importing a key.)
btw: It would also be nice to have a trustworthy archive for (retired) DKIM keys, but that another thing.