You can configure DNS filtering to identify DNS requests for disallowed domains. You can either:
Block access to the domain by sending a DNS response that contains the IP address or fully qualified domain name (FQDN) of a sinkhole server. This ensures that when the client attempts to send traffic to the disallowed domain, the traffic instead goes to the sinkhole server.