ScreenshotNeo

BlogGuides

Traceroute Test: Analyze the Network Path to Any Host

Run traceroute on Windows or Linux, read every hop, understand asterisks and latency, and troubleshoot slow or unreachable destinations.

By the ScreenshotNeo team1 October 20267 min read

Traceroute shows the hop-by-hop path from your computer to a destination and the round-trip time (RTT) reported by each responding hop. It works by sending probes with increasing IP time-to-live (TTL) values. Each router that decrements a probe’s TTL to zero may return an ICMP Time Exceeded message, allowing the tool to identify that hop.

A trace is an observation from one source network at one moment. It is not a complete record of every packet’s route, and asterisks do not automatically mean the route is broken.

Run a traceroute test

Windows

tracert example.com

Microsoft documents a default maximum of 30 hops. Change it with /h:

tracert /h  horizonte.example.com

Use an IP address when DNS names make the output difficult to interpret:

tracert 203.0.113.10

Windows TRACERT sends ICMP Echo probes with increasing TTL values. See Microsoft’s TRACERT documentation for the documented behavior and limits.

Linux

traceroute example.com

The Linux utility commonly uses UDP probes and sends three probes per TTL by default. Disable reverse DNS lookups for faster, easier-to-parse output:

traceroute -n example.com

Useful options vary by installed version. Check the local manual before copying a production command:

man traceroute
traceroute --help

The Linux traceroute manual documents probe methods, probe count, timeout, and hop-limit options.

Choose a probe method deliberately

Implementations differ. Linux can use UDP, ICMP, or TCP methods depending on the version and permissions; Windows TRACERT uses ICMP Echo. If a firewall treats one method differently, repeat the test with another supported method and record which command you used.

Read each line of the output

A typical row contains:

Field Meaning
Hop number The TTL value used for that row.
Router name or address The device that returned a diagnostic response, if it revealed an identity.
Several times RTT for each probe sent at that hop.

For example, Linux may print three measurements for one hop because it sends three probes. Compare repeated rows and the destination response rather than treating one number as a permanent property of a router.

What an asterisk means

An asterisk means that a probe did not receive a response within the utility’s timeout. A router may forward traffic normally while suppressing or rate-limiting TTL-expired replies. Microsoft notes that routers that do not return these messages are invisible to TRACERT.

Interpret asterisks using later rows:

  • Asterisks at one intermediate hop, followed by normal later hops: usually response filtering or rate limiting at that hop.
  • Asterisks from one hop through the destination: possible filtering, a routing problem, or an unreachable destination; verify with an application-level test.
  • The destination responds but an intermediate hop does not: the missing response alone is not evidence of packet loss.

Find where a connection slows down

  1. Run the trace several times and save the complete output.
  2. Record the source network, destination, time, probe method, timeout, probe count, and maximum hop count.
  3. Compare end-to-end RTT and reachability with the intermediate rows.
  4. Look for a pattern that begins at one point and continues through every later responding hop.
  5. Run an application test to confirm that the symptom affects the service you care about.

A high RTT at one hop is not proof that the router is introducing that delay. The reported time includes the return trip of the diagnostic response, and routers may prioritize forwarding over answering traceroute probes. If later hops return to their previous latency, the high value is often only a response-path artifact.

Equal-cost multipath routing can make successive probes follow different paths. RFC 7276 explains that traceroute finds a path while traffic can be forwarded across multiple equal-cost paths. Treat changing hop identities as evidence of multipath behavior, not automatically as instability.

Traceroute versus ping

Tool Answers Does not answer
Ping Whether the destination responds to the selected echo protocol and the approximate RTT and loss for those probes. Which routers are between you and the destination.
Traceroute Which intermediate hops respond and the RTT reported for each responding hop. A guaranteed route for all application packets or one-way delay.

Use both when diagnosing a service: ping supplies a simple end-to-end signal, while traceroute supplies path clues.

Use pathping when loss is the question

On Windows, pathping combines route discovery with longer measurements of latency and packet loss for routers and links:

pathping example.com

Microsoft identifies pathping as the adjacent tool when you need loss reporting along the path. Allow it time to collect its measurements before interpreting the final table.

Automate traceroute safely

Python

This script runs the platform utility, captures both output streams, and returns a nonzero exit code if the command fails:

import platform
import shutil
import subprocess
import sys

host = sys.argv[1] if len(sys.argv) > 1 else "example.com"
command = "tracert" if platform.system() == "Windows" else "traceroute"
if shutil.which(command) is None:
    raise SystemExit(f"{command} is not installed or is not on PATH")

result = subprocess.run(
    [command, host],
    text=True,
    capture_output=True,
    timeout=180,
)
print(result.stdout, end="")
if result.stderr:
    print(result.stderr, file=sys.stderr, end="")
raise SystemExit(result.returncode)

Run it with python trace.py example.com. Store the command, timestamp, and source network with the captured output so later comparisons are meaningful.

Node.js

import { execFile } from "node:child_process";
import process from "node:process";

const host = process.argv[2] ?? "example.com";
const command = process.platform === "win32" ? "tracert" : "traceroute";

execFile(command, [host], { timeout: 180000, maxBuffer: 1024 * 1024 }, (error, stdout, stderr) => {
  if (stdout) process.stdout.write(stdout);
  if (stderr) process.stderr.write(stderr);
  if (error) process.exitCode = error.code === null ? 1 : 1;
});

cURL for the application check

cURL does not perform a hop-by-hop traceroute. Use it to check whether the destination’s HTTP service responds after you inspect the route:

curl -I --max-time 20 https://example.com/

Compare the HTTP result with traceroute. A working HTTP response alongside missing intermediate hops is consistent with routers filtering diagnostic replies.

Common errors and fixes

Symptom Likely cause Fix
command not found: traceroute The utility is not installed or is outside PATH. Install the package provided by your operating system, then verify with traceroute --help.
Only asterisks appear ICMP/UDP filtering, a blocked destination, or a method mismatch. Try the documented alternate probe method, test the hostname with ping or cURL, and check local and destination firewalls.
Names are slow or inconsistent Reverse DNS lookups are timing out or changing. Use Linux -n or trace an IP address, then resolve names separately if needed.
Trace stops at the same hop every time A filtering boundary or a genuine reachability issue. Check whether later application traffic works; repeat from another network before assigning blame to that hop.
Permission or raw-socket error The selected method requires privileges. Use a supported unprivileged method or follow your operating system’s permission guidance; avoid granting broad privileges to ad hoc scripts.
Different runs show different routers Load balancing or changing routing. Collect multiple traces and record timestamps. ECMP can produce more than one observed path.
High value at one hop, normal values afterward The router may deprioritize diagnostic replies. Do not infer congestion from that row alone; inspect the destination and later hops.

Performance, reliability, and cost

  • Performance: Reverse DNS can add most of the waiting time. Numeric output is faster and easier to parse. Increase the timeout only when the path is known to be slow.
  • Reliability: A trace measures one vantage point, protocol, and moment. Repeat at different times and, when possible, from another network or monitoring location.
  • Safety: Traceroute sends diagnostic probes to the destination and intermediate networks. Use reasonable probe counts and intervals in operational environments.
  • Cost: The local utilities are software tools and do not require a special router, cable, or paid physical product. Remote monitoring services may charge separately; this research does not establish a specific service or price.

Or skip the browser setup

Traceroute diagnoses network paths. If your next task is collecting a visual of a web page, ScreenshotNeo provides a single HTTP request instead of maintaining browser automation:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo API documentation for request options. The same call in Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

And Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo removes cookie banners, newsletter popups, and chat widgets before capture. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP server lets AI agents call take_screenshot, get_page_info, and capture_pdf. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 screenshots.

Create a free ScreenshotNeo account.

FAQ

Does traceroute show the exact route of every request?

No. It shows the path taken by its probes from one source at one time. Multipath routing and protocol differences can produce another path for application traffic.

Should I report an ISP because one hop has a high RTT?

Only after the high latency persists through later hops and matches an end-to-end symptom. A router can delay or deprioritize diagnostic replies while forwarding traffic normally.

Why does Windows use a different command from Linux?

TRACERT and traceroute use different implementations and default probe methods. Always include the operating system and options with a trace you share.

What should I collect for support?

Save several complete traces, the destination, timestamps, source network, command line, probe method, and an application-level result such as ping or cURL.

Primary references