Knot resolver can't handle CNAME on root level?

Indeed. And I trust that the root cause is the conflict of DNS settings at different locations Turris OS 3.11 in RC! and that is not documented/clear which DNS setting takes precedence over which