The records must name the server that actually sends.
SPF still on the old IP, a DKIM key the panel generated and DNS never published, DMARC at p=reject before either of those works. Alignment is the job.
Set in that order
One record. The IP or include of the machine that sends, plus a webmail host if mail is split. A second SPF is a permanent fail. ~all until we have seen a pass, then -all if you want it.
The selector from Exim, Postfix or the panel, published as a TXT. Hestia can show the key as active while Cloudflare still has the old value.
p=none and a report address first. Reject comes after the reports show pass. Setting reject on day one blocks mail you did not know was sent from elsewhere.
Reverse DNS lives at the provider, on the IP
Gmail can still defer a message with perfect SPF if the PTR is missing or names another host. We request it from Hetzner, OVHcloud or whoever owns the address. We cannot set it in Cloudflare.
€55 an hour for one domain. A fleet is quoted.
Minimum 1 hour. We need the DNS zone, not the mailbox password. A blocklist delist is not included and is not guaranteed.
Mail rejected for SPF or DKIM after a move?
Send the domain and one bounce line. No mailbox password in the first message.
