Dnsfire: A proof-of-concept DNS-driven firewall enforcer
github.com
github.com
Without picking a side in that fight, I’m not sure this solution totally solves the problem when shared IP infrastructure is in play. A CDN may use the same IP for a malicious website and a perfectly good one, and the only difference is the incoming hostname being requested.
The result is you annoy dns over https users, but in the end do not gain any control.
The use of host files and direct connections to external IP addresses based upon ip address are rare among user workstations. Any legitimate need to connect directly via IP address could be handled by exception.