If tunneled DNS becomes prevalent, these hostname/domain approaches won't work. So it'll come down to blocking at IP level. And that will likely be harder.
That doesn't really have anything to do with the tunneling of DNS. Authentication + ignoring the local resolver do.
Edit: So that's tunneled DNS.
You could also call it encrypted DNS, I suppose. But then, you could say something similar about VPNs, instead of calling them tunnels.
Hard-coded authenticated DNS would be hard too, but it's at least possible that you could see what resolver it's using.