One of the long-standing issues with the "Block outside intrusion into LAN" list is that it can not protect against DNS rebinding attacks.
This new feature allows one to create a rule blocking connections to domains which resolve to localhost or IPs on your LAN. Classes A, B, and C are supported.
