in the end I went with CanSpace as registrar, and I’m using CloudFlare to actually run the nameservers.
The transfer was kind of a PITA because since the domain transferred from Google to Squarespace to Canspace to then being hosted on CF’s nameservers (but still on Canspace) the DNSSEC meant that CF couldn’t actually get it connected until like 48 hours later. Was quite worried that I’d screwed up somewhere.
I know a lot of people are cranky about digital IDs, but realistically there’s no avoiding it at this point: we need real, government-backed, links-to-a-specific-human-with-a-birth-certificate unique digital IDs. Then service providers can (optionally) demand it in order to register, and can prevent you from creating multiple accounts, and can ban you from their service permanently, and can vouch for you to other services that you are indeed a Real Unique Human Being.