We don’t use “ph.pool.ntp.org” but rather “pool.ntp.org”. However, we always get 4 addresses ranging from “222.127.1.18 to 222.127.1.27”.
If even one of these 4 addresses could be from another source, such as “asia.pool.ntp.org”, our problem would be resolved.
Is implementing this countermeasure difficult for you?