Email authentication in Australian multi-location and franchised businesses
A national scan of 475 businesses, June and July 2026
A multi-location business runs on email between offices that rarely meet. Invoices move from franchisee to head office, remittances move back, suppliers bill one branch under the name of the whole brand, and staff act on internal email precisely because it is internal. That is the terrain invoice fraud works best in. A forged "our account details have changed" email between a franchisee and head office, or from the brand to a supplier, arrives inside an existing billing relationship where payment is routine. Whether a given brand's domain can be used to send that email is not guesswork. It is a matter of public record, and it can be checked from the outside.
So I scanned the email authentication of 475 Australian multi-location and franchised businesses across June and July 2026. 237 of them, 50 percent, publish nothing that would stop someone forging mail in their name.
Open to forgery means one of two things. The business publishes no DMARC record at all, leaving the domain completely unprotected, or it publishes DMARC set to p=none, which monitors and reports but blocks nothing. Of the 237, 88 have no record and 149 sit at p=none, the more deceptive of the two, because it reads as protection on paper while a spoofed sender still arrives. Only the 238 businesses at p=quarantine or p=reject actually stop the forgery.
| DMARC posture | Businesses | Share |
|---|---|---|
| Enforcing (reject or quarantine) | 238 | 50% |
| Monitor only (p=none) | 149 | 31% |
| No DMARC record | 88 | 19% |
| All businesses | 475 | 100% |
The multi-location structure raises the stakes in a way a single-site business never faces. The brand is shared, so the trust is shared, but the domains often are not. A head office can have its own records in order while a franchisee's separately registered domain has none, and a forged email from that franchisee's domain still spends the brand's trust, with the customer, with the supplier, and with every other branch. The weakest domain in the network sets the exposure for the name on every shopfront.
Forgery is the exposure the business cannot see. There is a second fault it often can. 36 of the 475 publish no SPF record at all, and 28 more publish an SPF record grown past the ten-lookup limit, the point at which many receivers stop checking and fail the record outright. The mail that quietly fails is the remittance advice a franchisee was waiting on, and it does not bounce. It lands in spam, unseen, while the reconciliation it carried slips a week.
Email authentication is the control that fails silently. Nothing bounces, nobody is told, and a business has no way of knowing its domain is the one carrying the forged invoice email between its own branches. The records sit in public DNS the whole time. You can read your own business's in about a minute, and if they need work, that is what the deliverability service is for.
This scan follows the same method as the others, read from public DNS, counted one organisation at a time. How the scans work.
These scans continue sector by sector. If you want the next one when it is published, ask by email. It will come from me when the report is out, and nothing else will follow it.