The Administrative log category should show all logins (webmail and protocols included) including the IP address the logon originated from. There isn't a webmail-specific log though, no.
If you're seeing only the username getting blocked by outside actors you may have the Brute Force by IP Address configured to fire later than the Brute Force by Email rule and those should be reversed so the outside actor is blocked before the account becomes blocked.
Kyle Kerst
IT Coordinator
SmarterTools Inc.
www.smartertools.com