DNS-based blocking is the way (possibly via conditional VPN if you can tolerate the minimal latency bump).