However, this page, shows perfectly, so there must have been some differences between this and the domain I remember. Unfortunately, my domain has long since been reissued and I can't reproduce the block. The block also occurred in the latest Thunderbird for windows 7 interestingly.
Let's encrypt already EOLd OCSP
https://publicsuffix.org/
So here is my RFC to correct this deficit.
No public suffix records: suffixes are considered private trust them like you trust this domain. (I would like to invert this to suffixes default public and you mark them private but that conflicts with current practice)
TXT record 'v=PS1' suffixes under domain are considered public, treat as a trust boundary.
TXT record 'v=PS2 domain-fragment domain-fragment ...' suffixes under domain are considered public except for listed subdomains, those are private and under our control
and then let the ietf fight for a few years on why this does not work and how we need a huge recursive mess (cough SPF)