>One of the default rules maybe. Kerio's 2.1.5 default rules are very open...

I'm just trying Kerio out. The first thing I did was delete
all the filter rules and add a "deny all" rule. I must say,
it's quite tricky. I'm not sure when to allow access both
ways. For example, should my POP email server rule be
marked "incoming" only? If it is, how do the requests get
to the server? Using the SMTP address?

As you can tell, I'm a complete novice, and I don't really
know what I'm doing or talking about.