I have made a Access Rule to block any service on any port and a rule

Blocking urls microsoft.com, windows.com, and msn.com , for cetain
sercurity and privacy reasons -> (XP Client). The ACL for msn is
working ,
when I call up the site from a web Browser, and for the other services
the msn site it is working. The main problem is for microsoft.com and

windows.com. upon a browser request, I still get the site
microsoft.com ,
What I noticed after looking on the named screen on the server console
that, it seems to me that the dns address is being forwarded, by some

other server ( I can post the domains later, if needed). But I cant
beleive that I should have to go through and add each Domain that
microsoft.com would be forwarded through.

Any ideas ?