The pointer target is the earlier QNAME, so the answer can reuse the name.

highlighted = computed this step

Pointer target is checked

The pointer offset 12 matches the QNAME offset 12.

12=1212=12
Pointer targets QNAMEThe answer NAME uses a two-byte compression pointer.Answer NAME pointer16 bits / 2 bytes0xc00cbyte 0byte 11100000000001100markeroffset12marker: 3

The target is the earlier name

At that offset, the bytes decode to the same requested name.

target labels=3\text{target labels}=3
Target name at offsetThe question name starts at byte offset twelve in the DNS message.QNAME at offset 12136 bits / 17 bytes0x03777777076578616d706c6503636f6d00byte 0byte 1byte 2byte 300000011011101110111011101110111byte 4byte 5byte 6byte 700000111011001010111100001100001byte 8byte 9byte 10byte 1101101101011100000110110001100101byte 12byte 13byte 14byte 1500000011011000110110111101101101byte 1600000000len-www3www0x777777len-example7(cont.)example0x6578616d706c65len-com3com0x636f6dterminator0x00Parsed name - 17 byte QNAME.comexamplewww

The answer does not copy the name

The answer NAME is only two bytes long here because it reuses the earlier QNAME.

answer name bytes=2\text{answer name bytes}=2
Pointer targets QNAMEThe answer NAME uses a two-byte compression pointer.Answer NAME pointer16 bits / 2 bytes0xc00cbyte 0byte 11100000000001100markeroffset12marker: 3

Summary

DNS compression saves space by pointing back to a name already in the message.

pointer bytes=2\text{pointer bytes}=2
Pointer targets QNAMEThe answer NAME uses a two-byte compression pointer.Answer NAME pointer16 bits / 2 bytes0xc00cbyte 0byte 11100000000001100markeroffset12marker: 3