Host IPS 7.0 will cache a domain lookup for 30minutes, the HIPS services are restarted, or until the next McAfee Agent policy enforcement (interval depends on your configuration). If the domain lookup resolves a different IP within these timeouts, it will be blocked (as you found).
There is no way to force HIPS to perform a DNS lookup beyond the above parameters. Possibly you could force a policy enforcement with "cmdagent.exe /e", to see if that works. Submit a Product Enhancement Request though, if you'd like.
Many thanks for this detailed information... May I ask you where you gathered info regarding this? These things you mention are mentioned nowhere in the userguides, as far as i know?