Yes, but my apologies, my first reply is wrong, my bad.
Let me rephrase that...you cant do it as source or dst, you do it under service/application tabs...need more coffee :)). So once you had created that custom app/site, you have a rule like this, just tested it in my lab:
source -> any
destination -> Internet
vpn -> any
services & application -> custom app/site object you create (I named it sundication.exoclick and in "match by" I simply added *syndication.exoclick* and yes, 100% covers anything or any sub domain for that. Its literally if you wanted to block anything facebook under the sun, you could do the same *facebook*. I tried it many times and works like a charm.
action -> block
track -> log
If you have any issues, hit me up and we can do remote.