200-901 Network Fundamentals Practice Question
Which DNS record type is used to verify domain ownership for email security (SPF)?
⚠ Common exam trap
The trap is assuming MX records handle email authentication because they are email-related — MX records only route inbound mail, while TXT records carry SPF, DKIM, and DMARC policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
TXT record
TXT record is correct because SPF (Sender Policy Framework) is published as a DNS TXT record containing a list of authorized mail servers for a domain. Receiving mail servers query the TXT record to verify that the sending IP is authorized, helping prevent email spoofing. SPF records follow the format v=spf1 followed by mechanisms like ip4, include, and -all.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A record
Why it's wrong here
SPF verification reads a TXT record containing the authorised sending hosts; an A record maps a hostname to an IPv4 address and carries no policy text, so mail systems find nothing to evaluate. A records are the right choice when you need to resolve a name to an address, such as pointing a web hostname at a server.
- ✗
CNAME record
Why it's wrong here
SPF data must sit in a TXT record at the domain itself; a CNAME aliases one name to another and cannot hold the policy string, so receivers querying the domain retrieve no SPF content. CNAMEs are correct when you need to point a hostname at another canonical name, such as a CDN endpoint.
- ✗
MX record
Why it's wrong here
MX records direct inbound mail delivery to mail servers; they do not publish authorised sending hosts. It is tempting because SPF relates to email, but SPF is published as a TXT record containing the v=spf1 policy, which receivers query to verify sending domains.
- ✓
TXT record
Why this is correct
TXT records carry arbitrary text, which SPF publishes as a v=spf1 string listing authorised sending hosts. Domain owners add this record so receivers can verify mail legitimacy, satisfying the stem's ownership-verification requirement for email security.
Visual reference
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.