UDP
The smallest transport: ports and a checksum, nothing else.
A UDP datagram
The whole header fits in one row. Everything after it is somebody else's business.
0:00
Whole frame
Eight bytes of header: two ports, a length and a checksum. No connection, no sequence numbers, no retransmission. D4 31 00 35 00 25 2C 9C
| Field | Offset | Example value | Meaning |
|---|---|---|---|
| Source port | Byte 0–1 | 0xD431 = 54321 | The sender's port, so the reply knows where to go. The OS picks a random 'ephemeral' port (49152–65535 by convention). |
| Destination port | Byte 2–3 | 0x0035 = 53 (DNS) | Which service on the destination host should receive this: 53 is DNS. The IP address picks the machine, the port picks the program. |
| Length | Byte 4–5 | 37 | Header plus data in bytes: 8 + 29 = 37. |
| Checksum | Byte 6–7 | 0x2C9C (✓) | A 16-bit checksum over a pseudo-header (source IP, destination IP, protocol 17, length), the UDP header and the data. Computed for real here. In IPv4 it is optional (0 = none); in IPv6 it is mandatory. |
| Data (a DNS query) | Byte 8–36 | DNS query | UDP does not care what is inside. Here it is a 29-byte DNS question about example.com (see the DNS page). Whatever the application hands over is sent as one datagram. |
Overview
UDP (User Datagram Protocol) adds just two things to IP: port numbers, so many programs can share one machine, and a checksum. It is connectionless: each datagram stands alone, may arrive out of order, twice, or not at all, and the sender never finds out.
That minimalism is the feature: no handshake means no setup delay, and applications that tolerate loss (voice, games, DNS) or implement their own recovery (QUIC) choose it.
Key facts
- Header
- 8 bytes
- Ports
- 16 bits (0 – 65535)
- IP protocol number
- 17
- Delivery
- Unreliable, unordered
- Max datagram
- 65,507 bytes (IPv4)
- Standard
- RFC 768
Where you meet it
- DNS queries, DHCP, NTP
- Voice and video calls (RTP), online games
- QUIC and HTTP/3 run on top of UDP
Watch out for
- A datagram bigger than the path MTU (about 1472 bytes of data) gets fragmented by IP; lose one fragment and the whole datagram is lost.
- No congestion control: a UDP sender can flood a network. Protocols built on UDP must add their own limits.
- UDP amplification attacks abuse small spoofed queries that trigger large replies (DNS, NTP, memcached).
Standards
- RFC 768: User Datagram Protocol