Courseiva

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

You are deploying a new Microsoft 365 tenant for a company that has a single domain, contoso.com. You need to verify domain ownership to enable email routing. Which DNS record type must you add to the public DNS zone?

⚠ Common exam trap

It's easy for candidates to confuse service configuration records (like MX, SPF, or CNAME) with the mandatory verification record, assuming any DNS change proves ownership, but only the TXT record with the specific code satisfies Microsoft 365's domain proof requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

TXT record with a verification code provided by Microsoft 365.

To verify domain ownership in Microsoft 365, you must add a TXT record containing a unique verification code provided by the Microsoft 365 admin center to your public DNS zone. This proves you control the domain, enabling email routing and other services. Other DNS records like CNAME, SPF, or MX are used for service configuration, not ownership verification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    CNAME record with 'autodiscover' pointing to 'autodiscover.outlook.com'.

    Why it's wrong here

    The autodiscover CNAME is a service-location record that Outlook clients use after a domain is already verified to find the Exchange Online Autodiscover endpoint; it is not part of the verification challenge. Domain verification in Microsoft 365 works by having the admin create a TXT record containing a unique verification token that Microsoft can query. A CNAME record only maps one hostname to another and cannot carry that token, so even a correct autodiscover CNAME does not prove ownership of the domain.

  • ✗

    SPF record including Microsoft 365 IP addresses.

    Why it's wrong here

    SPF records are published to allow receiving mail servers to validate that messages originate from authorized outbound IP addresses; they are evaluated by email receivers, not by Microsoft 365's domain verification service. During domain verification, Microsoft 365 queries the public DNS for a TXT record whose exact value matches the generated verification code. An SPF record, even one listing Microsoft 365 IP ranges, contains an IP-allowed list and not that code, so it will not satisfy the verification check, and incorrectly configured SPF may also harm email deliverability.

  • ✗

    MX record pointing to Microsoft 365.

    Why it's wrong here

    An MX record is used for mail routing after a domain is verified: it tells other mail systems to deliver inbound messages to Exchange Online Protection with the specified mail exchanger host. Domain verification precedes that step because Microsoft 365 uses DNS's TXT record type to exchange a verification token, not the MX record type, which is structured as a priority and hostname pair. Until the TXT token is detected, the domain remains unverified and you cannot even finish adding the MX record as part of the domain setup, so this choice is incorrect.

  • ✓

    TXT record with a verification code provided by Microsoft 365.

    Why this is correct

    This is the correct method: in the Microsoft 365 admin center you select the domain you want to verify, copy the unique verification code, and publish it as a TXT record at the root of that domain (for example, MS=123456). Microsoft 365 then performs a DNS query for that exact TXT value; when it resolves, the domain is considered verified because only someone with administrative control of the domain's DNS zone could create that record. TXT records are able to carry arbitrary text, which makes them ideal for storing the verification token, and this same mechanism is used for verifying domains in Microsoft Entra ID as well.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.