I’ve done this and it works fine, but i am not sure about the security implications of this. I use the tailscale IP (100.65.0.4) for the A record on cloudflare DNS records.
I am doing this because on linux with networkmanager, my dns is reset to my ISPs DNS instead of tailscales.