I use Razor in conjuction with SpamAssassin on my home computer and I have two ports open in the firewall as prescribed 7, 2702 and 2703 but cloudmark.com is also, according to the logs, trying to access many other ports such as 5272, 5321, 5273 and so on.
The log entries are like this:
Jul 01 21:30:14 to Jul 01 21:30:14 ABORTED eth0 2 tcp packets from 66.151.150.22 (shock.cloudmark.com) to 192.168.n.n (localhost1) port 5321 (-)
Are there other ports I should have open?