Cyanogenmod devs need to get PGP keys and start using cryptographic signatures like now. The guy never would have been able to impersonate in the first place if they were doing this, and now it's even more important that the @cyanogenmod.com domain is directing to a different mail server.
Not sure if that's the case. Most people he was impersonating himself to probably don't know enough to find and check PGP signatures; especially since most email does not come with PGP signatures, the lack of a signature is not something that would cause anyone to bat an eyelash.
And at worst, a policy of signing all emails makes it so he can't be framed; someone can't alter mails and claim they were sent in that state, and if this guy thought he was going to be caught and went into the mail server to try and plant the evidence so that when the deals fell through the real Cyanogen was still on the hook, he wouldn't be able to reproduce a valid signature and one would say "Cyanogen was obviously framed, as he would never certify a deal in an email without a cryptographic signature".