Cloudflare has worked providers to make sure they can efficiently route. If you find case where this isn’t the case please let us know.
CF saying “we break standard DNS geo routing but work with providers to route things right” isn’t very inspiring.
Please send me details (silverlock at cloudflare) here - AWS has our geofeed.
If you can include resolution details - e.g. dig @1.1.1.1 <cloudfront-host> +nsid - with the incorrect CF results, we can provide them to AWS.
Folks did geo-routing with DNS long before ECS was included, and there’s a privacy trade-off to be had. We’re exploring ways to make this better but there is no free lunch.