TTL
Time to Live
- Pronunciation
- tee-tee-EL
In short
TTL (time to live) is a limit on how long data stays valid: router hops left for an IP packet, or seconds a DNS or cached answer may be reused.
What is TTL (time to live)?
In an IP packet, the TTL field starts at a value such as 64 or 128 and every router that forwards the packet lowers it by one. When it reaches zero, the router drops the packet and usually sends back an ICMP "time exceeded" message. This stops packets from circling forever when routing goes wrong. IPv6 calls the same field the hop limit.
Traceroute is built on that behavior. It sends packets with a TTL of 1, then 2, then 3, and each router that drops one reveals itself with its time-exceeded reply, which maps the path to the destination hop by hop.
In DNS and caching, TTL means seconds. A DNS record with a TTL of 3600 can be cached by resolvers for an hour before they ask again, and caches such as Redis or a CDN use TTLs to decide when stored data expires. Short TTLs make changes appear quickly but cause more lookups; long TTLs reduce load but delay updates.
A common misconception is that the IP TTL measures time. It started as seconds in the original design, but in practice every router simply subtracts one, so today it counts hops. The DNS and cache meanings, on the other hand, really are durations.
Key takeaways
- TTL limits how long data stays valid before it is dropped or refreshed.
- In IP packets it counts router hops; each router subtracts one.
- IPv6 calls the field the hop limit; traceroute relies on it.
- In DNS and caches, TTL is a number of seconds.
- Short TTLs mean fast changes; long TTLs mean fewer lookups.
Example
# IP TTL: the reply's ttl shows how many hops remain
ping -c 1 example.com
# 64 bytes from 93.184.215.14: icmp_seq=1 ttl=56 time=12.3 ms
# DNS TTL: seconds the answer may be cached
dig example.com A +noall +answer
# example.com. 3600 IN A 93.184.215.14
# Cache TTL: Redis key that expires after 60 seconds
redis-cli SET session:42 "data" EX 60
redis-cli TTL session:42Readers ask
What is a good DNS TTL?
For records that rarely change, an hour to a day is common. Before a planned migration, lower it to a few minutes so the switch spreads quickly, then raise it again afterwards.
Why does ping show a TTL?
It is the TTL left in the reply packet when it arrived. Systems start with typical values such as 64 or 128, so the number hints at how many routers the reply crossed and sometimes at the sender's operating system.
What happens when a packet's TTL reaches zero?
The router discards it and normally returns an ICMP time-exceeded message to the sender, which is exactly what traceroute uses to discover each hop.
See also
- DNS RecordNetworking, p. 7A DNS record is an entry in a domain's DNS zone that maps a name to information, such as an IP address (A, AAAA), another name (CNAME) or mail servers (MX).
- TracerouteNetworking, p. 33Traceroute is a network diagnostic tool that lists every router a packet passes through on its way to a destination, along with the delay to reach each one.
- PingNetworking, p. 21Ping is a network utility that checks whether a host is reachable by sending it small ICMP echo requests and measuring how long each reply takes to return.
- CacheBackend & APIs, p. 8A cache is a fast, temporary storage layer that keeps copies of frequently used data so later requests can be served quickly without repeating slow work.
- RouterNetworking, p. 25A router is a networking device that forwards packets between different networks, choosing the next hop for each one based on its destination IP address.
- PacketNetworking, p. 20A packet is a small, formatted unit of data sent across a network, made of a header with addressing information and a payload that carries the actual data.
Spotted a mistake or something missing on this page?Suggest an edit