Terminus Expanse
CurriculumBlogPricingSign in
Back to dispatches
guidesnetworkingAug 8, 2026

How to actually read a traceroute output

Terminus Expanse

What traceroute is doing, in one sentence

Traceroute finds every router between you and a destination by sending packets that are deliberately designed to die one hop earlier each time, and reading the error message each router sends back when they do. That's the whole trick. It's not a special protocol the internet has for "show me the path" — it's a clever abuse of a feature that already exists for an entirely different reason.

The mechanism, without hand-waving

Every IP packet carries a field called TTL — time to live — which starts at some number (commonly 64) and gets decremented by exactly one at every router it passes through. When a router decrements a packet's TTL to zero, it doesn't forward the packet; it drops it and sends back an ICMP "Time Exceeded" message to whoever sent it, essentially saying "this packet expired here, on my watch."

Traceroute exploits this deliberately. It sends a packet toward the destination with TTL set to 1. The very first router along the path decrements it to zero, drops it, and sends back that Time Exceeded message — which reveals the first router's address. Traceroute then sends a second packet with TTL set to 2. It survives the first router, gets decremented to zero at the second router, and that router replies. Traceroute keeps incrementing the TTL by one and resending until a packet finally reaches the real destination, which responds with a normal reply instead of a Time Exceeded message — that's how traceroute knows to stop.

Every line of traceroute output is really "here's who replied when a packet died at exactly this many hops out," in the order those hops occur.

Reading a real line of output

A typical line looks like this:

``` 4 203.0.113.1 (203.0.113.1) 12.481 ms 11.892 ms 12.103 ms ```

The leading number is the hop count — how many routers away this one is. Then the address of the router that replied at that hop. Then three numbers in milliseconds, because traceroute sends three separate probe packets per hop by default, and each one might take a slightly different path or hit a slightly different amount of congestion, so you get three independent round-trip times rather than one. Three similar numbers close together is a normal, healthy hop. Three wildly different numbers is often a sign of a router under load or a link with real jitter.

What * * * actually means — and what it usually doesn't

This is the line that confuses people the most:

``` 7 * * * ```

Each asterisk means one probe packet got no reply within the timeout window. This does not necessarily mean that hop, or the path beyond it, is broken. Very often it means the router at that hop is configured — deliberately, as a security or load-management choice — to not send ICMP Time Exceeded replies at all, or to deprioritize them so far below actual traffic that they time out. The packets are usually still passing through that router just fine; it's simply choosing not to identify itself. If every hop after a * * * line still eventually reaches the destination and gets a normal reply, the path is working — that one router is just staying quiet. A real problem looks different: * * * on every hop from some point onward, all the way to the end, with no final reply at all.

Why the last real number matters more than any single hop

The single most useful thing to look at in a traceroute isn't any individual hop — it's where the latency jumps. If hop 6 shows 14ms and hop 7 suddenly shows 180ms, and every hop after that stays around 180ms too, you've found roughly where in the network the delay is being introduced, even if you don't control that router and can't fix it directly. This is genuinely useful information when you're trying to figure out whether a slow connection is your network, your ISP, or something much further away — and it's the reason network engineers reach for traceroute constantly instead of just pinging the final destination, which only tells you the total round trip with no visibility into where along the way the time actually went.

One caveat worth knowing before you trust a result too much

The path traceroute shows you is the path at the moment you ran it. The internet routes around failures and load constantly, so running traceroute again five minutes later to the same destination can legitimately show a different set of routers — that's not a bug in traceroute, it's the network doing exactly what it's supposed to do. Traceroute is a snapshot, not a guarantee, and that's worth remembering before treating any single run as the definitive answer to "what's between me and this server."

This post is about