---
description: IP Header is meta information at the beginning of an IP packet. It displays information such as the IP version, the packet&#039;s length, the source, and the destination. IPV4 header format is 20 to 60 bytes in length. It contains information need for routing and delivery.
title: "IP Packet Header: Format, Fields"
image: https://www.guru99.com/images/ip-packet-header.png
---

[Skip to content](#main)

**⚡ Smart Summary**

IP header is the metadata placed at the start of every IP packet, carrying fields such as version, header length, total length, time to live, protocol, checksum, and the source and destination addresses that routers read to deliver data.

- 🧭 **Purpose:** IP header stores routing and delivery details so every packet reaches the correct destination across networks.
- 📏 **Size:** An IPv4 header ranges from 20 to 60 bytes, controlled by the Internet Header Length field.
- 🧱 **Key fields:** Core fields include Version, IHL, Type of Service, Total Length, TTL, Protocol, Checksum, and addresses.
- 🔀 **Fragmentation:** Identification, Flags, and Fragment Offset let large datagrams split and reassemble correctly.
- 🆚 **IPv4 vs IPv6:** IPv6 replaces the variable header with a fixed 40-byte header and drops the checksum field.
- 🤖 **AI assistance:** AI packet analyzers parse IP headers automatically to flag anomalies and speed up troubleshooting.

Read More

![IP Packet Header Format and Fields](https://www.guru99.com/images/ip-packet-header.png)

## What is IP header?

IP header is meta information at the beginning of an IP packet. It displays information such as the IP version, the packet’s length, the source, and the destination.

The IPv4 header format is 20 to 60 bytes in length, and it contains the information needed for routing and delivery. It consists of fields such as Version, Header Length, Total Length, Identification, Flags, Checksum, the source IP address, and the destination IP address. Together these fields provide the essential data needed to transmit the packet reliably from one host to another.

[![Site24x7]()](https://guru99.live/d91w54)

[![Site24x7]()](https://guru99.live/d91w54)

## IPv4 Header Components/Fields

The diagram below shows the complete IPv4 header format, with each field drawn in its correct position and bit width:

[![IPv4 packet header format diagram showing all fields and their bit positions]()](https://www.guru99.com/images/2/101920_1015_IPPacketHea1.png)

Following are the various components/fields of the IP packet header:

- **Version:** The first IP header field is a 4-bit version indicator. In IPv4, the value of these four bits is set to 0100, which indicates 4 in binary. If the router does not support the specified version, the packet is dropped.
- **Internet Header Length:** Internet Header Length, shortly known as IHL, is 4 bits in size. It is also called HELEN (Header Length). This IP component shows how many 32-bit words are present in the header.
- **Type of Service:** Type of Service is also called Differentiated Services Code Point, or DSCP. This field provides features related to the quality of service for data streaming or VoIP calls. The first 3 bits are the priority bits. It also specifies how a datagram should be handled.
- **Total length:** The total length is measured in bytes. The minimum size of an IP datagram is 20 bytes and the maximum is 65,535 bytes. HELEN and Total Length can be used to calculate the size of the payload. All hosts are required to be able to read 576-byte datagrams. However, if a datagram is too large for the hosts in the network, the fragmentation method is widely used.
- **Identification:** Identification is a field used to identify the fragments of an IP datagram uniquely. Some have recommended using this field for other purposes, such as adding information for packet tracing.
- **IP Flags:** Flags is a three-bit field that helps you control and identify fragments. The possible configurations are: Bit 0 is reserved and must be set to zero; Bit 1 means do not fragment; and Bit 2 means more fragments.
- **Fragment Offset:** Fragment Offset represents the number of data bytes ahead of a particular fragment in the specific datagram. It is specified in units of 8 bytes and has a maximum value of 65,528 bytes.
- **Time to live:** This is an 8-bit field that indicates the maximum time the datagram may live in the internet system. Every time a datagram is processed, its TTL value is decreased by one. When the value of TTL reaches zero, the datagram is discarded so that packets are not delivered endlessly. The value of TTL can range from 0 to 255.
- **Protocol:** This IPv4 header field denotes which internet protocol is carried in the latter portion of the datagram. For example, the number 6 is used to indicate TCP, and 17 is used to denote the UDP protocol.
- **Header Checksum:** The next component is a 16-bit header checksum field, which is used to check the header for any errors. The IP header is compared against the value of its checksum. When the header checksum does not match, the packet is discarded.
- **Source Address:** The source address is a 32-bit address of the source used for the IPv4 packet.
- **Destination address:** The destination address is also 32 bits in size and stores the address of the receiver.
- **IP Options:** This is an optional field of the IPv4 header, used when the value of IHL (Internet Header Length) is set greater than 5. It contains values and settings related to security, record route, time stamp, and similar options. The list of options usually ends with an End of Options List (EOL) marker.
- **Data:** This field stores the data from the protocol layer that has handed the data over to the IP layer.

## How to Calculate IPv4 Header Length

The Internet Header Length (IHL) field tells a router exactly how long the header is so it knows where the header ends and the data begins. Because the field is only 4 bits wide, it does not store the length in bytes directly. Instead, it counts the header in 32-bit words, where each word equals 4 bytes.

To convert the IHL value into bytes, multiply it by 4:

- **Minimum:** The smallest legal IHL value is 5, so 5 × 4 = 20 bytes. This is a header with no options.
- **Maximum:** The largest IHL value is 15, so 15 × 4 = 60 bytes. The extra 40 bytes hold optional fields.

Consider a worked example. If a packet arrives with an IHL value of 6, the header length is 6 × 4 = 24 bytes, meaning 4 bytes of options are present after the standard 20-byte header. To find the size of the payload, subtract the header length from the Total Length field. If Total Length is 1,500 bytes and the header is 24 bytes, then the payload is 1,500 − 24 = 1,476 bytes.

This calculation matters during fragmentation, because a router must know the header size to work out how much data each fragment can carry without exceeding the network’s Maximum Transmission Unit (MTU).

## IPv4 vs IPv6 Header

The IPv6 header was redesigned to be simpler and faster to process than the IPv4 header. It uses a fixed length and moves rarely used options into separate extension headers, so routers can forward packets at line rate. The table below compares the two headers field by field:

| Feature | IPv4 Header | IPv6 Header |
| --- | --- | --- |
| Header size | 20 to 60 bytes (variable) | 40 bytes (fixed) |
| Number of fields | 13 fields plus options | 8 fields |
| Address length | 32-bit source and destination | 128-bit source and destination |
| Header checksum | Present | Removed |
| Fragmentation fields | In the base header (Identification, Flags, Offset) | Moved to a Fragment extension header |
| Options | Carried inside the header | Carried in extension headers |
| Length field | Total Length (header plus data) | Payload Length (payload only) |

Because IPv6 drops the checksum and the variable-length options, its header contains fewer fields and can be processed in hardware without per-hop recalculation.

[![Site24x7]()](https://guru99.live/d91w54)

[![Site24x7]()](https://guru99.live/d91w54)

## Why the IP Header Is Important

Every field in the IP header exists so that routers and hosts can move a packet across many networks without a permanent connection between them. The header is what makes packet switching work.

- **Routing:** The destination address tells each router where to forward the packet, while the source address allows replies and error messages to return.
- **Loop prevention:** The Time to Live field is decremented at every hop, so a misrouted packet is discarded instead of circling the internet forever.
- **Delivery to the right protocol:** The Protocol field tells the receiving host whether to hand the payload to TCP, UDP, or another protocol.
- **Integrity and reassembly:** The checksum guards the header against corruption, and the Identification, Flags, and Fragment Offset fields let a fragmented datagram be rebuilt in the correct order.

For network engineers, reading these fields in a [TCP/IP](https://www.guru99.com/tcp-ip-model.html) capture is often the fastest way to diagnose dropped packets, routing loops, and misconfigured [IP addresses](https://www.guru99.com/types-of-ip-addresses.html).

## FAQs

🧮 What is the difference between Header Length and Total Length?

Header Length (IHL) measures only the header, in 32-bit words, and ranges from 20 to 60 bytes. Total Length measures the entire datagram — header plus data — in bytes, up to 65,535. Subtracting one from the other gives the payload size.

🧩 What is IP fragmentation and when does it happen?

Fragmentation splits a datagram that is larger than a link’s Maximum Transmission Unit into smaller pieces. The Identification, Flags, and Fragment Offset fields let the destination reassemble the pieces in order. It happens whenever a packet must cross a network with a smaller MTU.

🔟 How many fields does an IPv4 header have?

An IPv4 header has 13 fixed fields — Version, IHL, Type of Service, Total Length, Identification, Flags, Fragment Offset, TTL, Protocol, Checksum, Source Address, Destination Address, plus an optional Options field. The Data section that follows is the payload, not a header field.

🔐 Does the IP header checksum protect the data payload?

No. The IPv4 header checksum covers only the header fields, not the payload. Upper-layer protocols such as TCP and UDP carry their own checksums to protect the data. Because TTL changes at each hop, routers recompute the header checksum on every forward.

⏱️ What happens when a packet’s TTL reaches zero?

When TTL reaches zero, the router drops the packet and returns an ICMP Time Exceeded message to the source. This prevents packets from looping forever in a routing loop. The traceroute tool relies on this behavior to map each hop along a path.

🌐 What does the Protocol field in an IP header do?

The Protocol field identifies which upper-layer protocol should receive the payload at the destination. Common values are 6 for TCP, 17 for UDP, and 1 for ICMP. The receiving host reads this number to pass the data to the correct handler.

🤖 How does AI help analyze IP packet headers?

AI and machine-learning tools parse captured IP headers to detect anomalies such as spoofed source addresses, abnormal TTL values, or fragmentation attacks. They classify traffic and flag threats faster than manual inspection, though an engineer still confirms the findings before acting.

🛠️ Can GitHub Copilot help parse IP headers in code?

[GitHub Copilot](https://github.com/features/copilot) can draft Python or C code that unpacks IP header fields, decodes flags, and validates checksums from a short comment. Review the generated bit-masking logic carefully, since off-by-one offsets are a common source of parsing bugs.

#### Summarize this post with:

ChatGPTPerplexityGrokGoogle AI

[![Site24x7](https://www.guru99.com/images/screenshots/guru99-site24x7-300x600.gif)](https://guru99.live/d91w54)

**Stay Updated on AI** **Get Weekly AI Skills, Trends, Actionable Advice.**

##### Sign up for the newsletter

Subscribe for Free

You have successfully subscribed.  
Please check your inbox.

![AI-Newsletter]() Chosen by over **350,000+** professionals

[Scroll to top](#wrapper)

×

Search for:

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://www.guru99.com/#organization","name":"Guru99","sameAs":["https://www.facebook.com/Guru99Official","https://twitter.com/guru99com"],"logo":{"@type":"ImageObject","@id":"https://www.guru99.com/#logo","url":"https://www.guru99.com/images/guru99-logo-v1-150x59.png","contentUrl":"https://www.guru99.com/images/guru99-logo-v1-150x59.png","caption":"Guru99","inLanguage":"en-US"}},{"@type":"WebSite","@id":"https://www.guru99.com/#website","url":"https://www.guru99.com","name":"Guru99","publisher":{"@id":"https://www.guru99.com/#organization"},"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https://www.guru99.com/images/ip-packet-header.png","url":"https://www.guru99.com/images/ip-packet-header.png","width":"700","height":"250","caption":"IP Packet Header","inLanguage":"en-US"},{"@type":"BreadcrumbList","@id":"https://www.guru99.com/ip-header.html#breadcrumb","itemListElement":[{"@type":"ListItem","position":"1","item":{"@id":"https://www.guru99.com","name":"Home"}},{"@type":"ListItem","position":"2","item":{"@id":"https://www.guru99.com/networking","name":"Networking"}},{"@type":"ListItem","position":"3","item":{"@id":"https://www.guru99.com/ip-header.html","name":"IP Packet Header: Format, Fields"}}]},{"@type":"WebPage","@id":"https://www.guru99.com/ip-header.html#webpage","url":"https://www.guru99.com/ip-header.html","name":"IP Packet Header: Format, Fields","dateModified":"2026-09-03T18:54:53+05:30","isPartOf":{"@id":"https://www.guru99.com/#website"},"primaryImageOfPage":{"@id":"https://www.guru99.com/images/ip-packet-header.png"},"inLanguage":"en-US","breadcrumb":{"@id":"https://www.guru99.com/ip-header.html#breadcrumb"}},{"@type":"Person","@id":"https://www.guru99.com/author/bryce","name":"Bryce Leo","description":"I'm Bryce Leo, an IT Specialist with expertise in network administration and cybersecurity, committed to enhancing IT infrastructure.","url":"https://www.guru99.com/author/bryce","image":{"@type":"ImageObject","@id":"https://www.guru99.com/images/bryce-leo-author.png","url":"https://www.guru99.com/images/bryce-leo-author.png","caption":"Bryce Leo","inLanguage":"en-US"},"worksFor":{"@id":"https://www.guru99.com/#organization"}},{"articleSection":"Networking","headline":"IP Packet Header: Format, Fields","description":"IP Header is meta information at the beginning of an IP packet. It displays information such as the IP version, the packet&#039;s length, the source, and the destination. IPV4 header format is 20 to 60 bytes in length. It contains information need for routing and delivery.","keywords":"network, hacking","speakable":{"@type":"SpeakableSpecification","cssSelector":[".entry-title",".summary"]},"@type":"Article","author":{"@id":"https://www.guru99.com/author/bryce","name":"Bryce Leo"},"dateModified":"2026-09-03T18:54:53+05:30","image":{"@id":"https://www.guru99.com/images/ip-packet-header.png"},"copyrightYear":"2026","name":"IP Packet Header: Format, Fields","subjectOf":[{"@type":"FAQPage","mainEntity":[{"@type":"Question","name":"What is the difference between Header Length and Total Length?","acceptedAnswer":{"@type":"Answer","text":"Header Length (IHL) measures only the header, in 32-bit words, and ranges from 20 to 60 bytes. Total Length measures the entire datagram \u2014 header plus data \u2014 in bytes, up to 65,535. Subtracting one from the other gives the payload size."}},{"@type":"Question","name":"What is IP fragmentation and when does it happen?","acceptedAnswer":{"@type":"Answer","text":"Fragmentation splits a datagram that is larger than a link's Maximum Transmission Unit into smaller pieces. The Identification, Flags, and Fragment Offset fields let the destination reassemble the pieces in order. It happens whenever a packet must cross a network with a smaller MTU."}},{"@type":"Question","name":"How many fields does an IPv4 header have?","acceptedAnswer":{"@type":"Answer","text":"An IPv4 header has 13 fixed fields \u2014 Version, IHL, Type of Service, Total Length, Identification, Flags, Fragment Offset, TTL, Protocol, Checksum, Source Address, Destination Address, plus an optional Options field. The Data section that follows is the payload, not a header field."}},{"@type":"Question","name":"Does the IP header checksum protect the data payload?","acceptedAnswer":{"@type":"Answer","text":"No. The IPv4 header checksum covers only the header fields, not the payload. Upper-layer protocols such as TCP and UDP carry their own checksums to protect the data. Because TTL changes at each hop, routers recompute the header checksum on every forward."}},{"@type":"Question","name":"What happens when a packet's TTL reaches zero?","acceptedAnswer":{"@type":"Answer","text":"When TTL reaches zero, the router drops the packet and returns an ICMP Time Exceeded message to the source. This prevents packets from looping forever in a routing loop. The traceroute tool relies on this behavior to map each hop along a path."}},{"@type":"Question","name":"What does the Protocol field in an IP header do?","acceptedAnswer":{"@type":"Answer","text":"The Protocol field identifies which upper-layer protocol should receive the payload at the destination. Common values are 6 for TCP, 17 for UDP, and 1 for ICMP. The receiving host reads this number to pass the data to the correct handler."}},{"@type":"Question","name":"How does AI help analyze IP packet headers?","acceptedAnswer":{"@type":"Answer","text":"AI and machine-learning tools parse captured IP headers to detect anomalies such as spoofed source addresses, abnormal TTL values, or fragmentation attacks. They classify traffic and flag threats faster than manual inspection, though an engineer still confirms the findings before acting."}},{"@type":"Question","name":"Can GitHub Copilot help parse IP headers in code?","acceptedAnswer":{"@type":"Answer","text":"GitHub Copilot can draft Python or C code that unpacks IP header fields, decodes flags, and validates checksums from a short comment. Review the generated bit-masking logic carefully, since off-by-one offsets are a common source of parsing bugs."}}]}],"@id":"https://www.guru99.com/ip-header.html#schema-1150025","isPartOf":{"@id":"https://www.guru99.com/ip-header.html#webpage"},"publisher":{"@id":"https://www.guru99.com/#organization"},"inLanguage":"en-US","mainEntityOfPage":{"@id":"https://www.guru99.com/ip-header.html#webpage"}}]}
```
