Hello,
no, we do not provide DNS blocking like this. The reason for that is that we enforce DNSSEC and the global DNS tree should remain intact. You can find various debates around this on here.
What we have is filtering by proxy which has many advantages. Besides not breaking DNSSEC, it will show the user a clear indication that they have visited a potentially malicious website.
Alternatively you can use the Intrusion Prevention System to filter any malware and so on.