Then you write router-level firewall rules for the IPs you know are safe to fully block. You can do that selectively so you don’t break other devices.

I already do this for local DNS circumvention, which is probably a lot more common than hardcoded IPs.

Right, but Pi-Hole can't help with this.