You could let the traffic egress NSX and let a Palo Alto Networks (or other) firewall white list based on domain name of the destination.
You could integrate a PAN into your NSX environment I believe (right?) and do the DNS destination white listing there.
Are there any other options available to get this functionality with NSX 6.3 or 6.4? NSX-T is not going to be
an option in this environment for quite some time evidently.