Cosmically I feel like the HTTPS certificate on Cloudflare.pay should provide sufficient info to confirm it's the same entity behind Cloudflare.com
The cert itself only has CN=cloudflare.pay. It lacks an org, an address, or any other identifying info. It's not OV/EV, so no details there, either.
The domain's whois is also devoid of identifying details:
https://rdap.nominet.uk/pay/domain/cloudflare.pay
Registered through 101domain, with nothing except a registrar abuse contact.
I mean, great that this is legit, but CF could have done a better job with making it actually _look_ legit. This looks sketchy as fuck.
edit - gawd, nevermind. they don't even have anything useful for cloudflare.com. Same GTS cert, redacted whois info. lol. how did we even get here.