Network · Developer
IPv4 header checksum calculator.
Paste a 20 to 60 byte IPv4 header as hex, or fill in the fields. You get the word-by-word sum, the carry folding, the checksum, and whether the checksum already in the header is valid. Nothing is sent anywhere.
The rule: the checksum is the 16-bit one's complement of the one's complement sum of all 16-bit words in the header, with the checksum field taken as zero. A valid header, checksum included, sums to 0xFFFF.
Inputs
Result
Enter a header, then press Calculate.
How the IPv4 header checksum is computed
RFC 791 section 3.1 defines the header checksum as the 16-bit one's complement of the one's complement sum of all 16-bit words in the header, with the checksum field counted as zero. RFC 1071 describes how to compute it.
- Set the checksum field (bytes 10 and 11) to zero.
- Read the header as 16-bit big-endian words and add them as ordinary integers.
- Fold the carries: while the sum is above
0xFFFF, add the bits above the low 16 back onto the low 16 (end-around carry). - Invert all 16 bits. That value goes in the checksum field.
- To verify, sum the header including the checksum and fold. A valid header gives
0xFFFF(RFC 1071: all 1 bits, which is −0 in one's complement).
Worked example from RFC 1071 section 3
RFC 1071 sums the bytes 00 01 f2 03 f4 f5 f6 f7 as the words 0001 + f203 + f4f5 + f6f7 = 2ddf0. Folding the carry gives ddf2. RFC 1071 states the checksum is the one's complement of that sum, so inverting ddf2 gives 220d; this page computes that inversion, the RFC text does not print it. The example below is calculated live by the same code as the tool.
Sources: RFC 791, Internet Protocol (section 3.1) and RFC 1071, Computing the Internet Checksum.
Frequently asked questions
Why does the checksum change at every router?
RFC 791 notes that some header fields change, for example time to live, so the checksum is recomputed and verified wherever the header is processed.
Does the checksum cover the payload?
No. The IPv4 header checksum covers the header only (RFC 791). TCP and UDP have their own checksums over their data; this tool does not compute those.
What does a valid header sum to?
0xFFFF. RFC 1071 says that if summing the same octets including the checksum field gives all 1 bits, the check succeeds.
The header has options. Does that change anything?
Only the length: the checksum covers every 16-bit word of the header, options included, up to 60 bytes. Use the hex form and include the option bytes; the IHL field should equal the byte length divided by 4.
Checksum arithmetic only
This tool confirms the checksum arithmetic, not that a packet is genuine, was sent by anyone, or is otherwise well formed beyond the length and version checks shown. Everything runs in your browser and nothing you enter is transmitted or stored.