I’d just add a note, remove DS record at your registrar and disable DNSSEC at Cloudflare.
It seems to me like DNSSEC was enabled before you changed your domain nameservers to Cloudflare.
If you recently changed your domain nameservers, have you checked if the DNSSEC was disabled and any DS records removed at your domain registrar before domain nameservers were changed?
Kindly, I’d suggest you to contact and ask your domain registrar to disable DNSSEC for your domain and remove any of the existing DS records at their interface.
Nevertheless, you might have to wait up to 48 or 72 hours for proper DNS propagation and to clear the DS/DNSSEC entries for your domain name.
Unfortunately, this is a know “issue”, or rather to say it happens. Before we change domain nameservers, we should make sure we disable the DNSSEC feature and remove any of the existing DS type of DNS records for our domain at our domainr registrar.