It would seem that FQDNs that resolve as NXDOMAIN are not blocked. Since finding out that a name resolves that way involves a full recursive query all the way to the authoritative servers, would it not be faster blocking names as submitted before attempting to resolve them?