the reason we do this is, some of the banks we deal with our customers that require whitelisting do a really archaic dns backtrace, and if you dns backtrace netsuite address, in the modern day, you'll reach the equivalent services like aws cloudfront which does a rerouting, so when you do a general retrace of the address coming your door, the retrace will inevitably just knock on the rerouting ip...
sadly calling ourself to maintain a list only solves it case by case basis... and alas isn't great i admit