You don't say what mode you have your SME box in, I shall have to assume server/gateway not private server/gateway or server.
What you see of your brother being able to send mail only to your domain and no other is correct.
If he couldn't send to your domain neither could anyone else...
If he could send to anywhere else so could anyone else and you would be rapidly found as an open relay. The spammers would then pour their mail through you.
Why the two port scanners report different things, well you'll have to see what each is testing for. Is one just looking for ports with services behind them and the other specifically for an open relay?
Cheers
Dave.