Assessing a risk of a message is disclosed. A sender specified by the message is identified. A measure of authenticity that the sender specified by the message is an actual sender of the message is determined using at least one sender model associated with the sender. The sender model was at least in part automatically generated using one or more previously observed messages. The measure of authenticity is utilized to perform a risk assessment of the message.