I don't know, honestly I think port 25 should be blocked and only enabled at the user's request after they are a customer for X amount of days unless customer service believes, without a doubt, that the person will be ok to have port 25.
Even if someone needs port 25 for legit reasons they can...