If you are using a default address to catchall all the invalid and
unrouted emails to your domain, some open relay testing service will
show that your domain is open relay. But in fact it is not open relay.
The test they are performing is flawed in that context.
But in any case we strongly recommend that you DISABLE default address and do NOT use catchall.