It's also possible that your ISP offers a backdoor for using SMTP ports.
Let me explain...
ZoneEdit has my domain, in that I configured the 1st MX record to myself and the 2nd to my ISP's mail-detour, this is done to prevent black-list risks. The mail goes to me, there is no port 25 found on my server (BLOCKED) and it starts working on the 2nd MX record; Finds my ISP's server and pushes it there. That server has the weird feeling it shouldn't receive this and starts checking the DNS and discovers my settings. It is an internal network for my ISP so they DO see my port 25 and it tries to loose asap the mail to my addy. Works pretty well after having a lot of discussions how to make it work. Now they even publish that it's impossible to have your own mailserver... yeah right... fool the rest, not me...
BUT...
I'm not aware of what options you have to forward ports to other sections from your DNS. I know that QMail has a backdoor function on port 825. How to handle this exactly without using the default system is somthing I never researched, but for my needs (AVMailGate) it was the solution.
Good luck...
Harro