NerdyExplorer
Is it possible to use VPN split tunneling just for grapheneos.org domain,
What you are trying to achieve should be possible with inverse mode VPN split tunneling.
Providers frequently recommended here seem to support it:
https://mullvad.net/en/help/split-tunneling-with-the-mullvad-app
https://www.xda-developers.com/wireguard-split-tunneling/
https://protonvpn.com/support/protonvpn-split-tunneling/#android
I'm not using VPN on a regular base, but can confirm that split tunneling inverse mode works fine with Proton VPN.
Note: Only WireGuard and Mullvad's apps currently seem to be recommended by GrapheneOS Project:
The only apps we can recommend are the official WireGuard app and the official Mullvad app. Mullvad's app is tested on GrapheneOS with hardware memory tagging, unlike the official WireGuard app which has invalid memory accesses detected by memory tagging if it's enabled. We recommend using one of these VPN apps instead of the built-in IPSec VPN support.
source: https://grapheneos.org/faq#vpn-support
NerdyExplorer
Do you know which apps beside the app store do these calls?
The expected default connections by GrapheneOS (including all base system apps) can be found here:
https://grapheneos.org/faq#default-connections