Modbus Frame Builder & CRC Checker

Build RTU and TCP requests, inspect the bytes field by field, and verify the CRC of a frame you paste.

Runs in your browser, sends no dataModbus RTU · TCP · CRC-16

Protocol

The address is the 0-based protocol address. Modicon numbers such as “40001” in documentation are 1-based: holding register 40001 = address 0. Enter the address in decimal or as hex with 0x.

Generated frame (hex)

    FieldBytesMeaning

    How is a Modbus frame built?

    The core of every Modbus message is the PDU, which does not depend on the transport: a function code and function-specific data. The envelope around it depends on the transport:

    • Modbus RTU — unit address + PDU + CRC-16. The CRC is calculated over all preceding bytes and appended low byte first.
    • Modbus TCP — an MBAP header (transaction ID, protocol ID = 0, length, unit ID) + PDU. There is no CRC; TCP provides the integrity.

    For the read functions (01–04) the data is the start address and the quantity (2 bytes each, big-endian). Write functions 05 and 06 carry an address and a value; 15 and 16 carry address, quantity, byte count and the values. The field table explains these bytes one by one.

    The tool only calculates the frame; it does not talk to a device. Before going live, verify the address map and the byte order in your device’s Modbus documentation.

    Frequently asked questions

    How is the Modbus RTU CRC calculated?

    CRC-16/MODBUS: initial value 0xFFFF, polynomial 0xA001 (reflected 0x8005). Each byte is XORed into the CRC, then shifted right eight times, XORing with the polynomial whenever the lowest bit is 1. The result is appended to the frame low byte first.

    What is the difference between function 03 and 04?

    03 reads holding registers (read/write) and 04 reads input registers (read-only). You need the one that matches the table where the data lives; the device documentation tells you.

    Why do I get an “illegal data address” exception?

    It is often a mix-up between 0-based and 1-based addresses: 40001 in the documentation is address 0 on the wire. The same exception appears when the quantity runs past the range the device supports.

    Related: Modbus · PLC · Modbus TCP and RTU Guide: Registers, Function Codes and Common Mistakes

    Want this running automatically in a real project?

    Let’s design an architecture with HighByte Intelligence Hub and GoodData so the data flows from machine to dashboard automatically.