If you could block certain ports from addresses that don't resolve, you might be onto something That way you could still offer some functionality to the whole world (like the most basic services, depending on what you're trying to accomplish)...

Out of curiosity, what kind of services are you running that you're concerned about? Besides, an address that does resolve in no way gives them any more trustworthiness...