Both. Akismet will first send a pingback attempt to its API to check it, the same way it would evaluate a would-be spam comment. If the pingback clears the check, the real IP would be passed along.
Requiring moderation won't help. Pingbacks get verified as part of receiving them, because we need the information in a pingback in order to provide you the source and excerpt (the pingback "author" and pingback "content"). Everything we do here happens to be per the pingback specification.