Skip to main content
network

Traceroute

Traceroute helps you trace network path to a destination, for routing analysis, ownership checks, and faster network troubleshooting.

Enter a domain name or IP address

TracerouteAnimated network path tracing illustrationPCR1R2R3Hop 1Hop 2Hop 35ms12ms8ms15ms

Advertisement · Anuncio

Advertisement · Anuncio

Technical Analysis & Guide

What It Does

Traceroute maps the network path packets take from your location to a destination, showing each router (hop) along the way and measuring latency at each point.

Illustration of network concept

Why It Matters

  • →Path Visibility: See exactly how data travels to reach a destination
  • →Bottleneck Identification: Find where delays or failures occur
  • →ISP Routing: Understand your ISP's network paths and peering
  • →Geolocation: Track physical path through different regions

How to Read Results

  • Hop Number: Position in the route (1 is your router, 15-20 typical)
  • IP Address: Router at each hop (with hostname if available)
  • Response Time: Latency to that hop (sudden increases show bottlenecks)
  • * * * : Timeout - router not responding to probes (often normal)

Technical Background

Traceroute (tracert on Windows) works by sending packets with incrementally increasing TTL (Time to Live) values, exploiting the ICMP Time Exceeded message mechanism. Packet 1 has TTL=1 — the first router decrements it to 0, sends ICMP Time Exceeded back. Packet 2 has TTL=2 — passes the first router, stopped at the second. This continues until the destination is reached. On Unix/macOS, traceroute uses UDP probes by default (ports 33434+); on Windows, tracert uses ICMP Echo. TCP traceroute (traceroute -T) uses TCP SYN packets on a specified port, useful for tracing through firewalls that block ICMP/UDP.

Each hop shows 3 probe round-trip times in milliseconds. Asterisks (* * *) appear when a router silently drops probes — common for routers configured with ICMP rate-limiting or ACLs. Asymmetric routing (different forward/return paths) can make interpretation complex: the latency shown at each hop reflects the RETURN path from that router to your machine, not just that segment's latency. High latency at a single intermediate hop but normal latency at subsequent hops is typically an ICMP rate-limiting artifact at that router, not an actual bottleneck.

Traceroute is invaluable for network diagnostics: identifying where packet loss occurs, detecting BGP routing changes, discovering CDN and ISP topology, measuring latency per network segment, and debugging asymmetric routing. Tools like mtr (My TraceRoute) combine ping and traceroute in a continuous real-time display, making it easier to identify intermittent packet loss. Modern enterprise networks use MPLS (Multi-Protocol Label Switching) which can cause traceroute to show only edge routers, hiding internal MPLS hops. Paris-traceroute and Dublin-traceroute use flow-aware probing to produce consistent results in load-balanced networks.

Network engineers use traceroute output to calculate per-segment latency by subtracting the previous hop RTT from the current hop RTT. This reveals latency-heavy segments in the path. Multiple traceroutes from different geographic vantage points help identify whether routing issues are localized or widespread. Services like Thousand Eyes, Catchpoint, and the Looking Glass networks operated by major ISPs provide multi-point traceroute capabilities. When comparing routes, note that internet routing is asymmetric by design — the path taken for outbound packets and the path taken by return packets may traverse completely different networks, which complicates latency attribution.

Common Errors and How to Fix Them

ProblemA middle hop shows 40 percent loss or a timeout, and the ISP is blamed even though the final destination answers fine.
FixRouters answer probes from their control plane and rate-limit or deprioritize those replies. Loss that does not continue to later hops is cosmetic; only loss that persists all the way to the destination indicates a real problem.
ProblemThe last several hops show only asterisks and the destination is assumed to be down.
FixThe destination or its firewall is probably dropping the UDP or ICMP probes. Retry with a TCP traceroute to an open port, for example 'sudo traceroute -T -p 443 host' on Linux, and confirm reachability with a port check.
ProblemLatency jumps from 15 ms to 120 ms at one hop and that router is reported as faulty.
FixLook at where the hop is: a jump at the point where the path crosses an ocean or a continent is distance, not a fault. A problem router shows increased latency that persists on every subsequent hop and grows over time.
ProblemThe traceroute looks clean, but users on the other side still see packet loss.
FixInternet routing is often asymmetric, and traceroute only shows the forward path. Ask the remote side for a traceroute back to you, or run one from a host in their network, to see the return path.
ProblemSeveral consecutive hops report identical latency or private addresses such as 10.x or 100.64.x, and the path is assumed to be misconfigured.
FixMPLS tunnels inside carrier networks often hide or compress hops, and private or CGNAT addresses on internal links are normal. Focus on where the latency changes and where the path leaves one network for another.
ProblemA hop shows a single asterisk and is treated as packet loss.
FixThis tool sends one probe per hop with a short wait, so a single unanswered probe is expected on routers that rate-limit. Run the trace again or use mtr locally for per-hop statistics over many probes.

Frequently Asked Questions

Why do some hops show asterisks instead of an address?

An asterisk means no reply arrived for that probe within the wait time. Many routers are configured not to send ICMP Time Exceeded messages, or to send them only at a limited rate, and some firewalls drop them. If later hops and the destination respond, the silent hop is simply private about its existence and the path is working.

Why is a middle hop slower than the final destination?

Routers forward transit traffic in hardware but generate ICMP replies in a slower control-plane CPU, often at low priority. The response time of a single hop can therefore look worse than the destination's. Only latency that rises and stays higher for all subsequent hops reflects the actual forwarding path.

What is the difference between traceroute, tracert and mtr?

Unix traceroute sends UDP probes to high ports by default and can use ICMP or TCP with flags. Windows tracert uses ICMP echo requests. mtr combines traceroute and ping, sending probes continuously and showing loss and latency statistics per hop, which makes it the better tool for intermittent problems.

How many hops is normal?

Most destinations are reached within 8 to 20 hops. Content behind large CDNs is often fewer because the edge is close to your network. This tool stops at 30 hops; reaching that limit without arriving usually means the destination does not answer probes or there is a routing loop, visible as the same addresses repeating.

Can I tell which cities or networks the path crosses?

Often, yes. Router hostnames from reverse DNS frequently embed airport or city codes, such as 'ae-1.r20.mia01' for Miami, and the network owner's name. Combine this with an IP lookup of each hop to see where traffic leaves your provider and enters a transit or peering network. Codes are conventions, not guarantees.

Academic Documentation

Protocol context and primary references

REST API Documentation

v1.0
GET /api/tools/traceroute
					curl -X POST https://epcybertools.com/api/tools/traceroute \
  -H "Content-Type: application/json" \
  -d '{"host":"google.com"}'
				
					{
  "success": true,
  "results": [
    { "test": "Sample Check", "status": "pass", "message": "All clear" }
  ]
}
				
Rate Limit: 100 requests / 15 minutes

Usage Examples

			# Basic traceroute

traceroute example.com

# TCP traceroute on port 443

sudo traceroute -T -p 443 example.com

# IPv6 traceroute

traceroute6 example.com
		
100-Day Max Lifespan
155d 5h 19m 57s
PQC Migration Target
1178d 5h 19m 57s