Earlier quoted context omitted.
Do you have a concrete suggestion for the list maintainer to better vet the list? Can you prove that your site did not use the reverse proxy service at any point while the vulnerability was live?
> Can you prove that your site did not use the reverse proxy service at any point while the vulnerability was live? This is a scenario where it's impossible to prove innocence. Even if somebody provided you with the logs of their DNS server to show that the website never pointed to CloudFlare, I doubt these logs were stored in a way that their authenticity could be proved. In any case, the onus of proof should almost…
Your last idea is a good idea but more work for the list editor. I'm not sure the motivations of the list editor, but if he or she is just an impartial volunteer (important assumption), it seems like it's really Cloudflare's responsibility to deliver a comprehensive report of affected sites, so that we don't have to guess?