What Is the Default Concurrency for Email Scanning in user‑scanner?
The default concurrency for email scanning in user‑scanner is 25 simultaneous HTTP requests. This value is hard‑coded as a safety limit to prevent overwhelming target servers while maintaining efficient parallel execution.
The user‑scanner repository (kaifcodec/user‑scanner) provides a Python‑based reconnaissance tool for username and email enumeration. Understanding its default concurrency settings helps users tune performance without accidentally triggering rate limits or IP blocks.
Where the Default Is Defined
The primary definition resides in user_scanner/core/email_orchestrator.py:
# Concurrency control
MAX_CONCURRENT_REQUESTS = 25
This module exposes a set_concurrency() helper that updates this global limit at runtime.
MCP Handler Defaults
The MCP (JSON‑RPC) interface mirrors this default in user_scanner/mcp/handlers.py:
_DEFAULT_EMAIL_CONCURRENCY = 25
...
else:
set_user_concurrency(_DEFAULT_USER_CONCURRENCY)
set_email_concurrency(_DEFAULT_EMAIL_CONCURRENCY)
When the concurrency argument is omitted from MCP calls, the handler automatically restores 25 as the email scanning concurrency.
How to Run Scans with Default Concurrency
Programmatic Usage
from user_scanner.core.email_orchestrator import run_email_full_batch
from user_scanner.core.helpers import ScanConfig
config = ScanConfig() # uses default settings
results = run_email_full_batch("example@example.com", config)
Overriding the Default Programmatically
from user_scanner.core.email_orchestrator import set_concurrency, run_email_full_batch
from user_scanner.core.helpers import ScanConfig
set_concurrency(40) # raise limit to 40 concurrent requests
config = ScanConfig()
results = run_email_full_batch("example@example.com", config)
CLI Override
The --concurrency flag in user_scanner/__main__.py propagates your value to both orchestrators:
python -m user_scanner --email example@example.com --concurrency 40
Omitting --concurrency keeps the default of 25.
Design Rationale
The 25 default strikes a balance between speed and courtesy:
- Safety: Avoids aggressive polling that triggers WAF rules or temporary bans
- Throughput: Keeps CPU and network utilization high for typical broadband connections
- Consistency: Same default across CLI, programmatic API, and MCP interfaces
Power users on dedicated infrastructure or internal networks can safely increase this value using the methods above.
Key Source Files
| File | Role in Concurrency Control |
|---|---|
user_scanner/core/email_orchestrator.py |
Defines MAX_CONCURRENT_REQUESTS = 25 and set_concurrency() |
user_scanner/mcp/handlers.py |
Declares _DEFAULT_EMAIL_CONCURRENCY = 25 for JSON‑RPC fallback |
user_scanner/__main__.py |
Parses --concurrency CLI argument |
user_scanner/core/helpers.py |
Provides ScanConfig class used by orchestrators |
Summary
- Default concurrency: 25 simultaneous HTTP requests for email scanning
- Defined in:
user_scanner/core/email_orchestrator.pyasMAX_CONCURRENT_REQUESTS - Mirrored in:
user_scanner/mcp/handlers.pyas_DEFAULT_EMAIL_CONCURRENCY - Override methods:
set_concurrency()function,--concurrencyCLI flag, or explicit MCP argument
Frequently Asked Questions
Why is the default concurrency set to 25?
The 25 limit prevents accidental abuse of target services while still enabling parallel scanning. According to the user‑scanner source code, this value protects users from IP bans and rate‑limiting without sacrificing meaningful throughput on typical residential or cloud connections.
Can I increase concurrency beyond 25 for faster scans?
Yes. Call set_concurrency(n) before running run_email_full_batch(), or pass --concurrency n via the CLI. However, values above 50 may trigger defensive mechanisms on well‑protected endpoints.
Does the username scanner use the same default?
Yes. The codebase uses _DEFAULT_USER_CONCURRENCY (paired with _DEFAULT_EMAIL_CONCURRENCY in handlers.py), and the --concurrency flag applies to both orchestrators simultaneously.
Where can I verify the current concurrency setting at runtime?
Inspect user_scanner.core.email_orchestrator.MAX_CONCURRENT_REQUESTS directly, or check the logs emitted by run_email_full_batch() which include the active concurrency level in debug mode.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →