It’s DNS so they just have to accept the query and redirect it to a local server that answers for anything and returns the 451 error. However, it’s also worth noting that Cloudflare is a giant MitM proxy who already decrypts everything and retransmits it. No communication with any domain fronted by Cloudflare is secure.