Traceroute Interpreter
Paste traceroute or MTR output to see where latency is actually introduced, which hops are misleading, and why asterisks and a latency spike in the middle usually mean nothing.
Last reviewed by the Radiatus Cloud team
Need this monitored 24/7?
Radiatus delivers managed cloud & network operations.
A slow hop in the middle is almost always nothing
Traceroute works by sending packets with increasing time to live values and reading the ICMP time exceeded messages that come back. Generating those messages is a low priority task handled by the router's control plane, not its forwarding hardware, so a busy core router will deprioritise them and report a high round trip time while forwarding actual traffic at line rate. A hop showing 200 milliseconds followed by hops showing 30 is not a problem at that hop; it is a router that answered slowly.
Latency only matters if it persists
The number at each hop is the round trip time to that hop, not the time between hops. Latency that rises at one hop and stays high for every hop afterwards indicates a genuine increase on that segment. Latency that rises and then falls again tells you only that one router was slow to reply. This distinction is the single most useful thing to know when reading a trace, and it is the opposite of what the output visually suggests.
The reverse path is invisible
Every measurement in a trace is a round trip, and the return path may be entirely different from the outbound one. A trace showing a problem at hop nine may be reporting congestion on the return journey from that router, which traverses networks the trace never displays. Asymmetric routing is the norm on the internet rather than the exception, which is why a trace in both directions is worth far more than a trace in one.
Related tools
- Port Scanner — Check which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
- DNS Misconfiguration — Analyze DNS records (TXT, SPF) for security gaps.
- TLS Compat Tester — Check client-server compatibility for TLS versions.
- Firewall Rule Risk — Evaluate firewall rules for over-permissive exposure.
Frequently Asked Questions
Why does one hop show high latency and the next show low?
Because the router at that hop deprioritised generating the ICMP reply. Time exceeded messages are handled by the control plane rather than the forwarding hardware, so a busy router answers slowly while forwarding traffic normally. Only latency that persists to the end matters.
What do the asterisks mean?
No reply was received. Usually the router is configured not to send ICMP time exceeded messages, or a firewall filtered them. If later hops still respond, traffic is passing through fine and the silence is a configuration choice rather than a fault.
Does the last hop matter more?
Yes. The round trip time to the final destination is the only figure that reflects what an application experiences. Everything before it is diagnostic context for where an increase was introduced.
Why does the trace stop before the destination?
Commonly a firewall dropping the probes, which are UDP on Unix traceroute and ICMP echo on Windows tracert. Trying the other protocol, or TCP traceroute to the actual service port, frequently completes when the default does not.
Should I use traceroute or MTR?
MTR, where available. It runs continuously and reports loss and latency statistics per hop over many probes, which distinguishes a persistent problem from a single slow reply. A single traceroute is one sample and one sample is rarely enough to conclude anything.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Paste the output of traceroute, tracert or MTR to have it interpreted hop by hop.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Port Scanner
NetworkCheck which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
DNS Misconfiguration
NetworkAnalyze DNS records (TXT, SPF) for security gaps.
TLS Compat Tester
NetworkCheck client-server compatibility for TLS versions.