Courseiva
Network Fundamentals →mediumMultiple Choice

200-901 Network Fundamentals Practice Question

Which DNS record type is used to verify domain ownership for email security (SPF)?

⚠ Common exam trap

The trap is assuming MX records handle email authentication because they are email-related — MX records only route inbound mail, while TXT records carry SPF, DKIM, and DMARC policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

TXT record

TXT record is correct because SPF (Sender Policy Framework) is published as a DNS TXT record containing a list of authorized mail servers for a domain. Receiving mail servers query the TXT record to verify that the sending IP is authorized, helping prevent email spoofing. SPF records follow the format v=spf1 followed by mechanisms like ip4, include, and -all.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A record

    Why it's wrong here

    SPF verification reads a TXT record containing the authorised sending hosts; an A record maps a hostname to an IPv4 address and carries no policy text, so mail systems find nothing to evaluate. A records are the right choice when you need to resolve a name to an address, such as pointing a web hostname at a server.

  • ✗

    CNAME record

    Why it's wrong here

    SPF data must sit in a TXT record at the domain itself; a CNAME aliases one name to another and cannot hold the policy string, so receivers querying the domain retrieve no SPF content. CNAMEs are correct when you need to point a hostname at another canonical name, such as a CDN endpoint.

  • ✗

    MX record

    Why it's wrong here

    MX records direct inbound mail delivery to mail servers; they do not publish authorised sending hosts. It is tempting because SPF relates to email, but SPF is published as a TXT record containing the v=spf1 policy, which receivers query to verify sending domains.

  • ✓

    TXT record

    Why this is correct

    TXT records carry arbitrary text, which SPF publishes as a v=spf1 string listing authorised sending hosts. Domain owners add this record so receivers can verify mail legitimacy, satisfying the stem's ownership-verification requirement for email security.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.