Maybe I'm a little slow on the uptake. Are you trying to keep internal mail from being forwarded off of the corporate network, or do you think that someone is forwarding copies of your email to another account? Or do you think that someone is viewing your mail before you get it?
Regardless of which concern, I have to agree with PcLinuxGuru that your logs are your friends. In all cases, there should be information in the mail server logs that indicates which, if any, of these forms of email snatching is occuring.
If someone has compromised your workstation and is sending the email directly to an MTA that is outside of your control, your company's firewall logs should show numerous connections from your computer to that MTA.
pansophic