in my case it was a IRC server which was built identically to another 2 nodes in other parts of the world- When I looked into why I found no good reason so I dug in to it and was presented with a GCHQ/NSA project called "Tempora".
I ran a bunch of tests using the popular `openvpn` software suite and a bunch of VPS providers who were cheap enough (tilaa, vultr, linode and AWS) and the common trend was exactly what I described.
If I pinned the ciphers then the data would not be tampered, if I allowed a weaker cipher then my "response" would say the server was only capable of TLS1.0 despite me connecting to the same server minutes earlier on a different port with TLS1.2.
I will do a write-up on this and submit to HN as I assume this is still in place and all references to what I describe seem to have been removed from google.
I'm beginning to feel like one of those tin-foil hat people since I spent considerable time looking at documents surrounding this before and it's just vanished. :(