Well, no fragments make it through here and I even told pfSense to remove invalid DF bits just in case that was relevant.
Then again, that test appears to be designed for testing servers so may not pass over NAT. Although my understanding was that the router should be responsible for re-assembling the packets so they are not not fragmented after passing over NAT, so maybe that upsets how that test works?
Anyway, everything seems to be explained better
here. Although I think their claim of most people using an MTU of 1500 is flawed as most connections running over PPP most certainly are not and that can't be a small number of people.