So you have a linux box running DNS and that's the only way you can finangle stopping traffic? Pray tell how you stop other illicit traffic (p2p stuff, trojan activity, mudders, etc)?
Good luck, man, I think your bosses need to go to security school. :-) That's management though, eh?
If I were you, I would try to convince them of the error of their ways.
Failing that, I would focus on the client desktop. Go right to the root of the problem.
Or go buy zone alarm and use that! Maybe that can buck up the fifty bucks or so?