Application runtime

Java servlet container

Various, Jakarta EE standard · Application runtime. How DNSTrace.dev identifies it from public evidence.

Updated Sep 2026

What Java servlet container is

A JSESSIONID cookie is defined by the Java servlet specification, so its presence indicates the response came from a servlet container such as Tomcat, Jetty or WildFly. It names the standard rather than any particular server, framework or application.

How DNSTrace.dev detects it

Detection reads the final HTTPS response and the first bytes of its markup. One matching signal is reported as strong evidence; two or more independent signals are reported as confirmed.

  • JSESSIONID cookie — The session cookie name fixed by the servlet specification.

What a detection proves

The application runs on a Java servlet container.

What it does not prove

Which container, which framework, or which Java version. Spring, Struts and a plain servlet all produce the same cookie.

Common questions

Can the cookie name be changed?

Yes. Many deployments rename it, so absence is not evidence against Java.

Does this identify Tomcat?

No. The cookie is common to every servlet container.

Compare with

Server languagePHP

Open source, the PHP Group

Python application serverGunicorn

Open source

Application frameworkASP.NET

Microsoft Corporation

Elixir application frameworkPhoenix

Open source

Check a domain

Run a full lookup to see the delivery layer, the detected application stack, live TLS and the announcing network side by side.

Run a lookup →Application stack →Evidence model →