One way could be to require signing with a TLS certificate whose hostname resolves to the source IP(s).
Edit: If the server creates the certificate with a three way handshake, it will use the remote IP address. So the client doesn't have to know it's IP address
Seems far simpler to send a physical mail to the service operator who then hardcodes the IP in the server.
Or, maybe do a handshake once and cache it for X amounts of time whatever makes sense for that service.