A server name has nothing to do with the resources the server name provides i.e. .rar or .zip are not TLD, they are file extensions for the resources provided by the server name. Generally server names end with .com, .net, .biz, .org etc...
What you probably want to do is turn on intercepts in the WWW Proxy Server --> Sessions for port 80 and then use either the ban list or advanced criterions of the WWW Proxy Server like "HTTP URL" or "Resources".
Another thing to consider is how the WWW Proxy Server is setup to interact with the System Policies; they could be set in one of the three following ways:
"Must also be granted": If the e.g. WWW Proxy Server allows access to this service, then it must also be checked in the System Polices before it is allowed.
"May be used instead": If the e.g. WWW Proxy Server denies the request, then check if the System Policies allow it; if it does, allow the user to access.
"Are ignored": Do not check the System Policies to check if this user is allowed to access.
