HostChecker

Network diagnostics

Understanding Traceroute: How to Read Every Hop

Traceroute maps the path your traffic takes to a destination, one router at a time. Here's how it works and what the output is actually telling you.

Updated September 2026 · 5 min read

Traceroute output listing hop numbers and response times

When a connection is slow or a site won't load, ping tells you whether a host answers. It doesn't tell you where the delay is happening along the way. Traceroute does. It's a diagnostic tool built into every operating system that lists every router (or "hop") between your device and a destination, along with how long each one takes to respond.

Run a traceroute now Trace the path to any host directly from your browser.

How traceroute works

Traceroute relies on a field in every IP packet called TTL, or Time to Live. TTL isn't a timer; it's a hop counter. Traceroute sends a packet with TTL set to 1. The first router that receives it decrements the TTL to 0, discards the packet, and sends back an error message identifying itself. Traceroute then sends a packet with TTL set to 2, which survives the first router and gets dropped by the second one, and so on.

By increasing the TTL one hop at a time and recording who reports back at each step, traceroute reconstructs the full path to the destination, along with a round-trip time for each hop.

How to read the output

1 192.168.1.1 0.412 ms 0.398 ms 0.405 ms 2 10.20.0.1 4.112 ms 3.998 ms 4.201 ms 3 * * * 4 203.0.113.9 18.442 ms 18.201 ms 18.390 ms 5 198.51.100.5 (dst) 22.103 ms 21.998 ms 22.310 ms

Each line is one hop: the hop number, the router's hostname or IP, and three round-trip times from three separate probes. Three times per hop, rather than one, make it easier to spot a router that's consistently slow versus one that just had a single delayed packet.

A row of * * * means that hop didn't respond within the timeout window. That's common and usually harmless: many routers are deliberately configured not to answer traceroute probes, even though they pass the actual traffic through without issue. It only becomes a real signal if every hop past a certain point times out, including the final destination.

What common patterns mean

  • A sudden jump in latency at one hop, then it stays high: that hop, or the link right after it, is where the delay is introduced. Often a congested link or a router in a distant region.
  • Timeouts that start at some hop and continue to the end: could mean the destination is filtering ICMP, or a firewall along the path is dropping the probes. Check whether the destination itself is reachable another way (an HTTP request, for example) before assuming an outage.
  • A route through an unexpected country or network: not necessarily a problem. Internet routing follows business agreements between networks (BGP), not geographic shortest paths, so a "long way round" route is sometimes just how two networks peer with each other.

Limitations worth knowing

Traceroute has real limits. Some routers rate-limit or ignore the ICMP or UDP probes it depends on, which produces gaps that look worse than the actual path. Load-balanced routes can also send each of the three probes per hop over a slightly different physical path, so the three times at one hop aren't always measuring the exact same link. Treat a single traceroute as a snapshot, not a certainty, especially if you're deciding whether to escalate a network issue to an ISP or hosting provider.

The takeaway

Traceroute won't fix a slow connection, but it tells you where to look. Combined with ping, DNS lookup, and an HTTP status check, it turns "the site feels slow" into a specific hop or a specific layer of the stack you can point to. HostChecker runs all of these side by side, so a single result gives you the full picture instead of one number.

Trace the route yourself See every hop and response time for any host on HostChecker.