Diagnosing broken email.
THE TWO CAUSES
MX records did not import when the domain was added to Cloudflare. The mail hostname A record was proxied.
Both produce mail failing the moment nameservers change.
CHECKING MX RECORDS
Cloudflare DNS panel. Confirm MX records exist and point at the correct hostname.
Compare against cPanel > Email Deliverability, which shows what we expect.
CHECKING THE PROXY STATE
The A record for your mail hostname must be DNS only, shown as a grey cloud.
Orange means proxied, which breaks mail.
OTHER RECORDS TO CHECK
SPF, as a TXT record. A missing SPF record means your outgoing mail starts failing authentication. DKIM, also a TXT record. DMARC, if you use one.
All three are commonly missed during import.
AFTER FIXING
Test both directions: send from a mailbox and receive to it.
Check cPanel > Track Delivery for anything sent while it was broken.
IF EMAIL ROUTING WAS ENABLED
Cloudflare Email Routing replaces your MX records. Disable it if you use hosting mailboxes.