Specifically, it doesn't work with Comcast's DNSSEC-enabled recursive nameservers, which Comcast will eventually move all of its customers to:
% dig +noall +comments +stats pzxc.com.
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 14316
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 0
;; Query time: 161 msec
;; SERVER: 75.75.75.75#53(75.75.75.75)
;; WHEN: Sat May 28 02:38:43 2011
;; MSG SIZE rcvd: 26
joyeur.com, Joyent's blog, has the same problem:
% dig +noall +comments +stats joyeur.com.
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 57255
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 0
;; Query time: 133 msec
;; SERVER: 75.75.75.75#53(75.75.75.75)
;; WHEN: Sat May 28 02:40:38 2011
;; MSG SIZE rcvd: 28
Both pzxc.com and joyeur.com have CNAME records.
So, yeah, using CNAMEs on your domains works great, except for all those times it doesn't work at all, like with the largest residential ISP in the United States.