I just got this email and also my site was running really slow at that point.
When I logged into CF, the site wasn’t deleted and I couldn’t find anything in the logs.
(Today) One thing I did change was I turned on CF Proxy for my A records (it was DNS only before).
(2-3 Days Ago) I added TXT entry for Brevo domain authentication.
Nameservers are still pointing to CF and I didn’t change anything in the last 20+ days.
The parent name servers for the .HR TLD responds with exactly those name servers.
There’s also a Brevo (as well as a MS) TXT verification record on the apex (e.g. naked domain), like you indicated.
So everything does look perfectly fine, according to the information provided.
Could you by any chance have (had) a secondary Cloudflare account, where the domain could have been attached to, but since it wasn’t active there, now has been deleted?
Otherwise I would just take it as the email have been the result of a temporary glitch.