Practical Modbus Guide

Modbus register addressing: why 40001 often means address 0

Modbus protocol messages carry a zero-based address, while many device manuals use human-readable references such as 40001. If a manual lists holding register 40001, software may require you to enter address 0; 40002 may be address 1.

Quick answer: Modbus frames carry a zero-based address, while many manuals use 1-based references such as 40001. The leading 4 means holding register (FC 03); the remaining digits minus one give the protocol address. So 40001 is address 0, 40010 is address 9, and 30001 is input-register address 0. Always confirm the manual’s addressing note.

What do 00001, 10001, 30001 and 40001 mean?

Most confusion comes from mixing three different ways of naming the same point:

Manual notationRegister typeProtocol address
00001Coil0
10001Discrete input0
30001Input register0
40001Holding register0

The leading digit is a documentation convention, not a value transmitted in the Modbus frame. The function code identifies the data area; the request contains the actual starting address.

How do you convert 40001 to a Modbus address?

If the device manual uses the classic 4xxxx holding-register notation, subtract the base reference to get the protocol address. For example, 40001 → 0, 40010 → 9 and 40101 → 100. For 3xxxx input registers the same idea applies: 30001 → 0.

Important: not every manufacturer follows the same notation. Some manuals already show protocol offsets directly, and some start their displayed registers at 1 without the 3xxxx/4xxxx prefix. Always check the manual's addressing note.
ModbusBB can show addresses as 0-based, 1-based or Modicon (4xxxx) numbers.

How do you fix an off-by-one register error?

  1. Confirm whether you are reading holding registers (FC 03) or input registers (FC 04).
  2. Find one register with a value you can independently verify, such as frequency, voltage or status.
  3. Try the documented address using the software's expected convention.
  4. If the result is an exception or an obviously wrong adjacent value, test one address lower or higher.
  5. Once confirmed, apply the same convention consistently to the whole map.

An Illegal Data Address (exception 02) often points to the wrong offset or to a request that extends beyond the valid register range.

Do not confuse address with quantity

A Modbus read request contains both a starting address and a quantity. A device may allow address 0 but reject a request for 125 registers if the implemented range is smaller. When troubleshooting, start with a quantity of 1 or 2 and expand only after the address is confirmed.

Why is the value right but the magnitude wrong?

Correct addressing only tells you which raw number was returned. Many devices store engineering values as scaled integers—for example, a raw value of 2301 with a scale factor of 0.1 means 230.1 V. Others use IEEE-754 Float32 across two registers. Check the manual for data type, scale factor and units before judging whether a returned value is correct.

ModbusBB register maps can store aliases, formats, scaling and units so the interpretation stays attached to the address instead of being re-entered every session.

In ModbusBB 2.0 the start address you type (and the CLI --address option) is always the 0-based protocol address that goes on the wire, in decimal or 0x hex. View > Address Notation changes how the Address column of the grid is displayed: 0-based (protocol/PDU), 1-based (register number) or Modicon (0xxxx coils, 1xxxx discrete inputs, 3xxxx input registers, 4xxxx holding registers). Reading address 0 with FC 03 and switching to Modicon shows it as 40001, so you can compare the grid directly with a manual that uses 4xxxx references. The built-in device library uses 0-based wire addresses too. See address notation.

Modbus Organization reference

For protocol-level definitions, use the official MODBUS Application Protocol Specification V1.1b3.

Frequently asked questions

Is Modbus register 40001 address 0 or 1?

In the classic 4xxxx notation, 40001 is the first holding register, which is protocol address 0. Software that expects protocol addresses (including the ModbusBB address field and CLI) needs 0; software that accepts 4xxxx references needs 40001. ModbusBB can display the result as 40001 with View > Address Notation > Modicon. If a read returns an adjacent value, check whether the manual already lists zero-based offsets.

Why do I get Illegal Data Address (exception 02)?

The starting address, or the address plus quantity, falls outside what the device implements. The usual causes are an off-by-one offset from 40001-style notation, the wrong register area (FC 03 vs FC 04) or reading too many registers at once. Start with a quantity of 1 at a known address.

What is the difference between 30001 and 40001?

30001 refers to the first input register (read-only, FC 04) and 40001 to the first holding register (read/write, FC 03, 06 and 16). Both map to protocol address 0 inside their own data area; the function code, not the address, selects the area.

Try it on a real device

Use ModbusBB while you troubleshoot

Connect, scan, read/write, inspect raw TX/RX traffic, trend data or simulate a device from the same Windows application.