Assuming that particular domain that they need access to resolve to 200.1.1.1, and you only need HTTP access to that domain, you can configure the following:
access-list 101 permit tcp host host eq 80
access-list 101 permit tcp host host eq 80
...
...
access-list 101 permit tcp host host eq 80
access-list 101 deny ip host any
access-list 101 deny ip host any
...
...
access-list 101 deny ip host any
access-list 101 permit ip any any
The last line (permit ip any any), I assume that you would like to allow access for other hosts to the internet.
Assuming gig0/0 is the internal router interface where the hosts are connected to:
interface gi0/0
ip access-group 101 in
Hope that helps.