If you use a proxy service, the protection depends on the origin staying unknown.
HOW ORIGIN ADDRESSES LEAK
Mail sent directly from the server, whose headers contain the address Subdomain records left unproxied, such as an old cpanel or ftp record pointing directly at the server Historic DNS records archived by lookup services from before you enabled the proxy Error pages or application output revealing the address Scripts making outbound connections that identify the source
WHAT TO DO
Proxy every record that can be proxied Send mail through a dedicated sending provider rather than the server, so headers do not expose it Remove unnecessary subdomain records pointing directly at the origin Consider whether the address has already been archived, in which case only a change of address restores the protection
THE REALISTIC POSITION
A determined attacker can often find an origin address. Proxying raises the effort required substantially, which deters most automated attacks.
Do not rely on concealment alone. Keep software updated, authentication strong and backups current regardless.