This has already been touched on in the article and the comments. DKIM isn't any good when it tells you that the email from fraudulent mybankk.com is verified just because the phishers were clever enough to set up DKIM on their site.
I'm not sure how PGP would help though, as the user also has to check, if the email from his bank was signed with the correct key. Checking the exact domain name is something he can already do and I guess is also easier to understand.