I have wondered how to streamline the process of converting blocked messages into blocked senders, but I have been discouraged by the difficulties involved, and my process remains manual and cumbersome.
Depending on the situation, I may want to block the From address, the SMTP Mail From address, the HELO domain, the Reverse DNS domain, the IP address, the IP CIDR, or the Reply-To address. The decision also requires knowing which identifiers are verifiable, or at least credible, and which ones are impersonated and therefore irrelevant.
When blocking a server, blocking the IP address seems minimally effective. The block should typically hit the whole server organization or not at all. So I block on a host domain or a CIDR. Before I can block on either, I need to understand whether the server organization is likely to send messages for acceptable clients in the future, and whether an abuse report would be effective. To map an IP to a CIDR and an abuse reporting address, I use ipinfo.io. To find an abuse report from a domain name, I use abuse.net. When I think the effort will be worthwhile, I send an abuse report rather than blocking the hosting service completely.
All of this has come to a head because of the bot network that uses IP addresses on many different hosting services, using many different domain names and many content variations. Blocking on Source IP has helped a little, but the best defense has been sending unknown senders to quarantine. With that defense in place, I don't need to create a block on a domain or IP that they will abandon tomorrow, and I don't need to anticipate the domain name that they will begin using when today's name is discarded.