Earlier quoted context omitted.
Your router doesn't care about their DNS settings. IP addresses are very easy to tie back to countries. The reason they say it's not reliable is because it's trivial to spoof the country, but even so, a lot of attackers don't even bother. It's sort of like the Nigerian prince scam calls: if you're wise enough to block Russia, you're not worth their time. Your firewall vendor should supply you with country lists, just…
I wonder if adding the US is now sensible.
Eventually, my lets encrypt cert expired and it turns out certbot is run from USA, so the auto renewal failed me.