your kind help is needed: we have got the zone files from the hosting provider where some of the cname uses _xxxxxx.acm-validations.aws which are only in “DNS only” and cannot be proxied. Also, manual addition of these acm.aws cname throws an error “DNS Validation Error (Code: 1004) This record type cannot be proxied”
This is a feature, not a bug. If the record is Proxied, then AWS cannot actually validate the record. By forcing you to make them Cloudflare are ensuring that the validation will actually work.