I have seen this with a few other referrals occasionally. Is there any other steps I can take?
I would ideally prefer to stop these at the Cloudflare level.
For starters, you only need the second rule as it already implies the first one.
Then, these will be most likely direct connections to your server, going around Cloudflare. In that case firewall rules will obviously not fire. You need to make sure your server only accepts connections from the Cloudflare IP addresses at IP Ranges.