@zrb The normal way is installing postfix, and possibly proxying outbound connections thru a VPS on a reputable hosting provider if your port 25 is blocked or bad-rep.
This does not give the VPS host access to your outbound mail contents if you're forcing STARTTLS* because TLS is terminated on your side.
I'm running custom software far simpler than postfix on mine.
(* unless they're actively MITM'ing with a forged certificate and either the recipient server isn't using DANE or you're not validating it)