EMZETT.
Login

TTL

In short: “Time To Live” — indicates how long a value (e.g. a DNS record or a network packet) remains valid before it must be discarded or queried again.

In more detail: For DNS records, the TTL is a time span in seconds that determines how long a resolver may cache the result before asking the authoritative name server again. For IP packets, by contrast, the TTL is a counter that is decreased by 1 at every router it passes through, and the packet is discarded once it reaches 0 — this prevents packets from circling the network endlessly.

In Depth

Despite sharing a name, the two meanings of TTL are technically fundamentally different — but both serve the same overarching purpose: preventing outdated or misrouted data from haunting the system indefinitely.

DNS TTL: a time span

For DNS records, the TTL is a genuine time span in seconds, e.g. 3600 (one hour) or 86400 (one day). It determines how long a resolver may cache the result of a query before it has to ask the authoritative name server again. Choosing the TTL is a classic trade-off:

  • Low TTL (e.g. 300 seconds): changes reach everywhere quickly, but resolvers have to ask more often — more load on the name servers, minimally higher latency for users, since a “cold” lookup is needed more often.
  • High TTL (e.g. 86400 seconds): noticeably relieves the name servers and improves perceived speed for returning users, but delays the propagation of changes accordingly.

Before planned DNS moves (e.g. changing hosting providers), you therefore typically lower the TTL to a low value days in advance — once the actual change goes live, it propagates within minutes instead of hours, because most resolvers already have to ask again anyway due to the expired old TTL.

IP packet TTL: a counter

For IP packets, by contrast, the TTL is not a time value but a pure counter (value range 0–255 for IPv4, called “Hop Limit” in IPv6), which is decreased by exactly 1 at every router it passes through. Once the counter reaches 0, the packet is immediately discarded and an ICMP error message (“Time Exceeded”) is sent back to the original sender. Without this mechanism, a misrouted packet caught in a routing loop (two routers endlessly forwarding a packet to each other) could theoretically circle the network forever while continuously wasting bandwidth.

The starting value of the TTL is set by the sending operating system and traditionally differs by system (Linux/macOS often start at 64, older Windows versions at 128) — this difference is occasionally even used for rough operating system detection (“OS fingerprinting”), by comparing the TTL actually arriving at the receiver against the usual starting values and calculating back the number of hops traversed.

Practical use: traceroute

The counter mechanism is deliberately exploited by diagnostic tools like traceroute (Windows: tracert) to make the complete route to a destination visible:

$ traceroute emzett-digital.com
 1  router.local (192.168.1.1)  1.2 ms
 2  10.0.0.1 (10.0.0.1)  8.4 ms
 3  core-router.isp.net (203.0.113.1)  12.1 ms
 4  emzett-digital.com (198.51.100.42)  24.7 ms

The tool sends packets with a deliberately low, gradually increasing TTL (first 1, then 2, then 3, …) to the same destination. The packet with TTL=1 already dies at the first router along the way and provokes a “Time Exceeded” message back to the sender there — this is how traceroute learns the address of this first hop. The next packet with TTL=2 makes it one hop further before it dies, revealing the second router, and so on — until the packet eventually reaches the actual destination.

See also: Caching, DNS Records