Both are issued by "COMODO RSA Domain Validation Secure Server CA" with organizationalUnitName "PositiveSSL Domain Control Verified" and are generating "Incomplete chain" error according to SSL Labs.
We are sending "COMODO RSA Certification Authority", but not "COMODO RSA Domain Validation Secure Server CA", which is http://crt.comodoca.com/COMODORSADomainValidationSecureServerCA.crt
I think we only have PositiveSSL DV certs ([Citation needed]), so maybe rename Comodo to PositiveSSLDV with the correct CA cert? (There are OV CA, EV, and Comodo ECC CA. What a mess)