CHFI Application, Email and Cloud Forensics Practice Question
Which TWO of the following are valid email header fields that can be used to detect email spoofing? (Select 2)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Received-SPF
SPF and DKIM are email authentication mechanisms that help detect spoofing. SPF checks if the sending server is authorized, DKIM verifies the email integrity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Subject
Why it's wrong here
The Subject header is a user-specified field that describes the message's topic and is displayed in mail clients. It carries no cryptographic or sender-verification data, and any sender can set it arbitrarily, making it trivial to spoof. Email authentication mechanisms such as SPF, DKIM, and DMARC deliberately ignore the Subject line when computing their validation results, so it cannot be used to authenticate an email.
- ✓
Received-SPF
Why this is correct
The Received-SPF header is specifically designed for authentication and is inserted by the receiving mail system after it evaluates the envelope sender against the publishing domain's SPF policy. The header records the check result (e.g., pass, fail, softfail), the HELO identity, and the client IP, providing traceable evidence of the SPF verdict. This makes Received-SPF a modern, standards-based email header that is valid for verifying and auditing sender authorization.
- ✗
Content-Type
Why it's wrong here
The Content-Type header informs the recipient's MUA how to interpret the message body, such as text/plain or multipart/alternative, and determines the character set and boundary parameters. It plays no part in authenticating the origin of the email, because it is independent of the envelope sender and any cryptographic checks. Authentication relies on headers like Received-SPF and DKIM-Signature, while Content-Type purely serves content presentation.
- ✗
MIME-Version
Why it's wrong here
The MIME-Version header indicates that the message conforms to MIME version 1.0, enabling proper decoding of structured multipart content. It is a protocol declaration, not a security or authentication mechanism, and it does not bind the message to any domain identity or signing key. Consequently, MIME-Version is irrelevant for verifying the sender's legitimacy and cannot be considered an authentication header field.
- ✓
DKIM-Signature
Why this is correct
The DKIM-Signature header contains a base64-encoded digital signature over selected header fields and the body hash, as defined in RFC 6376. This signature is created with the private key of the sending domain and validated by the receiver using the public key fetched via DNS, thereby providing integrity and sender authentication. As a core authentication mechanism, DKIM-Signature is a valid email header field for verifying that the domain actually authorized the message.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.