I have to allow someone, who is using xDSL broadband line where the IP address is dynamically allocated each time when he connects to his ISP, to a computer. Even though I have used a 3rd party service, no-ip.com, to create a permanent FQDN, I still have to modify the ip address in the aliase each time.
It is not possible to filter traffic using domain names (as you have mentioned they may change frequently and resolving DNS entries for each packet would decrease firewall perfomance greatly).