NAT and Source Address

Say I want to block a website at If I am using NAT on my network how would I define that traffic? What would the source addres be?  Would I have to block with a firewall or access list before the traffic is NATed?
If users are accessing it via DNS name (like for HTTP/s or FTP) then simply make a bogus A record and blackhole it...    Easier than messing with routers..
on external router interface create a deny ip access list and on the internal router creat a loopback adapter and point all internal traffic to this address.

this will break communication in both directions.

