Keith,
I would write an outbound ACL on you inside interface. something like:-
access-list inside_out permit tcp host any eq 25
access-list inside_out deny tcp x.x.x.x y.y.y.y any eq 25
access-list inside_out permit ip any any
access-list inside_out permit icmp any any
x.x.x.x = internal IP subnet
y.y.y.y = internet subnet mask
HTH>