Are you saying you don't have a generic rule in place, and are instead using Little Snitch to approve calls to port 80 for every new domain you visit? If so, that'd certainly work, but it seems more than a little impractical.
Yes. And I do the same with cookies.
I do allow connections (and cookies) permanently to "trusted sites", but that's the exception rather than the rule.