I'm curious whether IP blocking is actually enough to comply with the
spirit of a trade embargo.
Surely, the point of "not trading with Iran" is to avoid, through one's economic activity, enriching the citizens or corporations of Iran; and has nothing to do with preventing access to people who just happen to currently be within the geographic boundaries of Iran. (So: email blocking by detection of Iranian-ISP mail host = sensible; Iranian IP blocking = not-so-much.)
Unless, I suppose, you expect that a tourist accessing your service through an Iranian ISP, will be enriching the Iranian ISP to exactly the degree that you are serving them, and therefore, you are legally required to not serve the tourist, lest they enrich the ISP thereby. (That would be a hard point to prove.)
But actually, even if it was just the letter of the sanctions that you had to obey, I would expect that "not trading with Iran" would be a lot harder than it sounds—it would require, for example, that you do not trade with an Iranian citizen who is currently geographically located in, say, Mexico. How would you know? Your random IM webapp would need a KYC process (submission of ID documents, etc.) to be "sanction-compliant", wouldn't it?