I do sort of the opposite. I block all traffic outgoing on 25 and make an explicit exception for the mail server. Same for all common protocols, really. Even though NAT rules aren't defined for any services, it's just too easy and prevents too many exploits not to do. Then again, I am pretty draconian in my blocking of zip files. If it's under 500k, it's blocked.