Could you add some additional check if that domain is used? (Possibly with browser fingerprinting, or other req fingerprinting)
Possibly something even that just wastes a little time and makes them know you're aware of the behaviour.