MS-102 Deploy and manage a Microsoft 365 tenant Practice Question
You are deploying a new Microsoft 365 tenant for a company that has a single domain, contoso.com. You need to verify domain ownership to enable email routing. Which DNS record type must you add to the public DNS zone?
⚠ Common exam trap
It's easy for candidates to confuse service configuration records (like MX, SPF, or CNAME) with the mandatory verification record, assuming any DNS change proves ownership, but only the TXT record with the specific code satisfies Microsoft 365's domain proof requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
TXT record with a verification code provided by Microsoft 365.
To verify domain ownership in Microsoft 365, you must add a TXT record containing a unique verification code provided by the Microsoft 365 admin center to your public DNS zone. This proves you control the domain, enabling email routing and other services. Other DNS records like CNAME, SPF, or MX are used for service configuration, not ownership verification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
CNAME record with 'autodiscover' pointing to 'autodiscover.outlook.com'.
Why it's wrong here
The autodiscover CNAME is a service-location record that Outlook clients use after a domain is already verified to find the Exchange Online Autodiscover endpoint; it is not part of the verification challenge. Domain verification in Microsoft 365 works by having the admin create a TXT record containing a unique verification token that Microsoft can query. A CNAME record only maps one hostname to another and cannot carry that token, so even a correct autodiscover CNAME does not prove ownership of the domain.
- ✗
SPF record including Microsoft 365 IP addresses.
Why it's wrong here
SPF records are published to allow receiving mail servers to validate that messages originate from authorized outbound IP addresses; they are evaluated by email receivers, not by Microsoft 365's domain verification service. During domain verification, Microsoft 365 queries the public DNS for a TXT record whose exact value matches the generated verification code. An SPF record, even one listing Microsoft 365 IP ranges, contains an IP-allowed list and not that code, so it will not satisfy the verification check, and incorrectly configured SPF may also harm email deliverability.
- ✗
MX record pointing to Microsoft 365.
Why it's wrong here
An MX record is used for mail routing after a domain is verified: it tells other mail systems to deliver inbound messages to Exchange Online Protection with the specified mail exchanger host. Domain verification precedes that step because Microsoft 365 uses DNS's TXT record type to exchange a verification token, not the MX record type, which is structured as a priority and hostname pair. Until the TXT token is detected, the domain remains unverified and you cannot even finish adding the MX record as part of the domain setup, so this choice is incorrect.
- ✓
TXT record with a verification code provided by Microsoft 365.
Why this is correct
This is the correct method: in the Microsoft 365 admin center you select the domain you want to verify, copy the unique verification code, and publish it as a TXT record at the root of that domain (for example, MS=123456). Microsoft 365 then performs a DNS query for that exact TXT value; when it resolves, the domain is considered verified because only someone with administrative control of the domain's DNS zone could create that record. TXT records are able to carry arbitrary text, which makes them ideal for storing the verification token, and this same mechanism is used for verifying domains in Microsoft Entra ID as well.
Visual reference
Go deeper
Related to this question
Learn chapter
App Consent Policies and Admin Consent
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
Key term
DNS record
A DNS record is a set of instructions stored on a DNS server that tells clients how to interact with a domain, most commonly by mapping a human-readable domain name to an IP address.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.