Separate webmail.domain.tld and mail.domain.tld

When i now visit either webmail.domain.tld or mail.domain.tld i see roundcube login.
How can I have webmail.domain.tld for roundcube and mail.domain.tld for imap/smtp only?

I use Cloudflare and I would love to be able to proxy webmail.domain.tld for security reasons.
Ofcourse mail.domain.tld will stay unproxied. I have setup waf- and pagerules to skip any let’s encrypt related stuff but it doesn’t help preventing the validation error..