I did that.
Or at least I think I did. I could see in tcpdump that they were getting "DNS Refused", but that wasn't enough to tell them to reconfigure their resolver. Using iptables to tell it the host isn't there seems to be working rather better.
I've taken to emailing the IP range owner (these email addresses *must* work: the IP registries get upset when they don't!). This also seems to stop things. On the most recent ones, I've asked them to also tell whoever they got the address.
Slowly but surely.
If I get bored of this, I *will* be setting up *. to resolve to some black hole.
Q:Is it proper to eat cheeseburgers with your fingers?
A:No, the fingers should be eaten separately.