Scanner traffic
You are probably here because Mycelia-Scanner showed up in your logs. This page explains what that traffic is, how to tell it apart from anyone else, and how to reach a person about a specific scan.
What this traffic is
It comes from Spectre, the external attack surface scanner operated by Mycelia Networks, a company based in Barcelona, Spain. A scan runs because a user of our platform asked for it, never on our own initiative and never at random.
What we are allowed to send depends on whether that user has proven control of the domain. Until they have, a scan stays at the level of observation any browser or mail server would make, listed under "What we check" below. Everything that reaches into your application requires proof of control first, and our detection probes require it without exception.
How to identify us
Every request we send to a domain under scan carries this User-Agent, with the identifier of that scan inside it:
Mycelia-Scanner/1.0 (+https://mycelia-networks.com/scanner; scan=<scan_id>)The scan identifier travels only to the domain being scanned and its subdomains. Requests we make to third parties while working on a scan, for example to certificate transparency logs, carry the same name without it:
Mycelia-Scanner/1.0 (+https://mycelia-networks.com/scanner)That identifier is what lets us answer a question about one specific scan, so it is worth keeping when you write to us. We also cap ourselves at 10 requests per second to a single domain by default, so our traffic should never look like a flood.
Our IP addresses
Today we egress through a shared pool belonging to our infrastructure provider. The address is not ours alone and it is not stable, which is why we do not publish ranges for allowlisting: a range we published would cover machines that are not ours, and allowlisting it would be worse for you than not having it.
We do record the egress address of every scan we run. If you see our traffic and want the address confirmed, write to security@mycelia-networks.com or to the contact in our security.txt with the scan identifier from the User-Agent, or the time and your domain if you no longer have it, and we will confirm the exact address that scan came from.
A dedicated European range is planned, and this page will say so when it is live.
What we check
Before the requester has proven control of the domain, a scan is limited to records and public sources: DNS, email authentication records, certificate transparency logs, reputation and threat databases. The only contact with the domain itself is a TLS handshake on port 443, one request for the standard MTA-STS policy file, and one request to the home page.
Once control of the domain is proven, a scan also looks at HTTP response headers, exposed ports and services, subdomains and dangling DNS records, and runs our detection probes against web endpoints. Those probes are limited to three families:
- Open redirect: a parameter that sends a visitor to a host we control.
- Reflected cross-site scripting: an inert marker that comes back unescaped.
- Parameter reflection: input that reaches the response unchanged.
Contracted active testing is a separate service and a separate decision. It is the only part of our platform that sends real payloads, it covers more families than the three above, and it runs only for a domain whose owner has proven control, activated it explicitly, and recorded their consent. If you have not signed for it, you will not see it.
What we never do
- We never authenticate. We do not log in, we do not use credentials we may have found, and we do not try to obtain any.
- We never brute force. No password guessing, no credential stuffing, no enumeration by exhaustion.
- We never exploit what we find. A probe stops at the evidence that a weakness exists. We do not go further, and we do not leave anything behind.
- We never extract data. We read what a response returns, and nothing else.
- We never run denial of service or load tests, deliberately or as a side effect of volume.
Asking us to stop
Write to security@mycelia-networks.com and we will stop scanning your domain. A scan identifier or a timestamp helps us find the scan, but it is not required: your domain is enough. We do not ask you to justify the request.
If you believe a scan reached a domain whose owner did not ask for it, say so in the same message and treat it as a report: we will trace the scan, tell you what we find, and act on it. The same mailbox handles vulnerability reports about our own platform, described on our security page.