Having to do a DNS lookup for each firewall rule is going to suck. Not to mention blackholing traffic when cached DNS replies are out of sync with the actual IP.
Plus blackholing temporarily due to a stale cache is better than blackholing permanently due to a stale rule pointing to an old IP.
the don't know the router lost its connection