Courseiva
Network Fundamentals →mediumMultiple Choice

200-901 Network Fundamentals Practice Question

Which DNS record type is used to verify domain ownership for email security (SPF) and is stored as a text string?

⚠ Common exam trap

200-901 often tests whether candidates confuse MX records (which route inbound mail) with TXT records (which store SPF/DKIM/DMARC policies), causing them to pick MX when the question mentions email security.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

TXT record

TXT records store arbitrary text strings and are the record type used for SPF (Sender Policy Framework), DKIM, and domain verification. SPF is published as a TXT record containing a list of authorized sending hosts, allowing receiving mail servers to verify that email originates from approved sources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    TXT record

    Why this is correct

    TXT records hold arbitrary text strings, which is exactly how SPF policies are published: a domain owner adds a TXT record containing the authorised sending hosts. This satisfies the stem's requirement for verifying domain ownership for email security while being stored as text.

  • ✗

    CNAME record

    Why it's wrong here

    CNAME records alias one hostname to another; they cannot hold arbitrary text and are prohibited at a domain apex where SPF is typically published. It is tempting because CNAMEs are DNS records, but SPF requires a TXT record containing the policy string, not an alias.

  • ✗

    A record

    Why it's wrong here

    A records map a hostname to an IPv4 address; they store no text string and publish no sender policy. It is tempting because A records are common DNS entries, but SPF verification depends on a TXT record whose value is the v=spf1 policy, which an A record cannot carry.

  • ✗

    MX record

    Why it's wrong here

    MX records direct inbound email to mail servers; they carry no SPF policy text and cannot verify domain ownership. It is tempting because MX is email-related, but SPF specifically uses a TXT record holding the authorised-sender string, so MX fails the text-string requirement entirely.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.