That leads to my technique in discovering origin servers when pen testing CloudFlare customers: brute force all the DNS names and record types, map out all the blocks, scan them for open ports, ID the web server ports, attempt to find the vhosts on those ports in requests with the hosts header
You'll almost always find the origin web server (sans protection) and also dev/staging instances of apps.