alot of real users sit behind shared carrier nat, so blunt ip rules can burn good applications too.
the better approach will be risk scoring plus step-up checks. look for device consistency, repeated identitydata, timezone or language mismatach and whether the same device keeps cycling fresh ips. that pattern catches alot more abuse than tip alone, especially against mobile proxy users and basic bot farms