Have you considered Anubis? It's self-hosted, so you put it in front of the services you want to protect, while other services can be left without it if it doesn't matter. If you try to do the same with gray DNS on CloudFlare, where only some names in the zone are proxied, then eventually malicious bots will walk your zone and find your origin IP address and go to it directly, circumventing CF's proxies. This then requires back-verification where the origin asks CF if this is from their proxy.
In some setups, Anubis is a lot simpler. But it has its own set of drawbacks - mostly that old, slow devices will sit at the challenge for noticeable time.
Anubis is also open source.