You are using a Cloudflare origin certificate, which requires use of the Cloudflare proxy. Your DNS records are currently set to “DNS only” (or you have paused Cloudflare). You need to set the records to “Proxied”… https://cf.sjr.org.uk/tools/check?56eb3e2b58eb412b9f692b91a3676341#dns
You also have multiple SPF and DMARC records whereas there must only be one of each so you will need to fix that too.