As a best practice, use address objects in the
Destination Address field to enable
access to specific servers or groups of servers only,
particularly for services such as DNS and SMTP that are commonly
exploited. By restricting users to specific destination server
addresses, you can prevent data exfiltration and command and
control traffic from establishing communication through
techniques such as DNS tunneling.