HOLEHE
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Email OSINT tool that checks if an email address is registered on 120+ websites using password reset and login flows.
INSTALLATION#
pip install holehe # From source git clone https://github.com/megadose/holehe cd holehe pip install .
BASIC USAGE#
# Check single email holehe user@example.com # Check with rate limiting (recommended) holehe user@example.com --timeout 10 # Only show registered accounts holehe user@example.com --only-used # CSV output holehe user@example.com --csv output.csv # No color holehe user@example.com --no-color
PYTHON API#
import trio
from holehe.core import holehe
async def main():
email = "user@example.com"
results = await holehe(email)
for result in results:
if result['exists']:
print(f"[+] {result['name']}: Registered")
trio.run(main)
# With custom modules
from holehe.modules.social_media import instagram, twitter
OUTPUT FORMAT#
# Each result contains: # [+] Site: email is registered # [-] Site: email is not registered # [x] Site: rate limited or error # Fields in CSV/JSON output: name # Website name domain # Website URL exists # True/False emailrecovery # Email shown in recovery (if partial) phoneNumber # Phone shown in recovery (if partial) others # Additional info
SUPPORTED SITES (CATEGORIES)#
# Social Media Instagram, Twitter/X, Facebook, Pinterest, Snapchat, TikTok, Tumblr, Reddit # Professional LinkedIn, Freelancer, Fiverr, Upwork # Email/Communication Google (Gmail), Microsoft (Outlook/Hotmail), Yahoo, ProtonMail, Mail.ru, Zoho # Shopping Amazon, eBay, AliExpress, Etsy, Nike, Adidas, H&M # Streaming/Entertainment Spotify, Netflix, Disney+, Deezer, SoundCloud, Twitch, Vimeo # Development GitHub, GitLab, Bitbucket, Docker Hub, Npmjs, PyPI # Gaming Steam, Epic Games, EA (Origin), Ubisoft, Blizzard # Finance PayPal, Stripe, Coinbase, Binance # Cloud/Productivity Dropbox, Evernote, Notion, Trello, Atlassian, Adobe # Dating Tinder, Bumble, OKCupid, Badoo # Other Gravatar, WordPress, Imgur, Archive.org, Duolingo, Strava
HOW IT WORKS#
# Holehe uses legitimate website features:
1. Password reset forms (most common)
- Submit email to "forgot password"
- Check if site says "email sent" vs "account not found"
2. Registration forms
- Try to register with the email
- Check if site says "email already in use"
3. Login forms
- Some sites reveal email existence on login attempt
# Important: this is NOT brute forcing passwords
# It only checks if the email is registered
PARTIAL DATA RECOVERY#
# Some sites reveal partial information during password reset: # Email recovery hints "We sent a code to j***@g***.com" # Partial email "We sent a code to +1***567" # Partial phone # Holehe captures these hints when available # Useful for discovering: - Alternative email addresses - Phone number patterns - Recovery email providers
RATE LIMITING & OPSEC#
# Best practices to avoid blocks: - Use --timeout 10 or higher between requests - Use a VPN or proxy to rotate IPs - Don't scan the same email repeatedly - Space out scans of emails from the same org # Some sites will: - Block your IP after too many requests - Send notification to the account owner - Log the lookup attempt - Rate limit (shown as [x] in output) # For stealth: - Run behind Tor or VPN - Use residential proxies - Limit to specific sites with --module
WORKFLOW EXAMPLES#
# 1. Email → Account Discovery
holehe target@company.com --only-used --csv results.csv
# 2. Combine with Sherlock
# Email prefix as username
sherlock targetuser
holehe targetuser@gmail.com
holehe targetuser@outlook.com
# 3. From breach data
# Found email in breach → check what sites they use
holehe breached_user@email.com --only-used
# 4. Batch processing
#!/bin/bash
while IFS= read -r email; do
echo "=== $email ==="
holehe "$email" --only-used --timeout 10
sleep 5
done < emails.txt
# 5. Social engineering prep
# Know which services a target uses
# Craft targeted phishing lures matching their accounts
COMPARISON WITH SIMILAR TOOLS#
Tool Method Scope Notes ---- ------ ----- ----- Holehe Email lookup 120+ sites Password reset probes Sherlock Username 400+ sites Profile page checks GHunt Google account Google Deep Google OSINT Maigret Username 3000+ sites Sherlock fork Epieos Email/phone Many Web-based, limited free
TIPS#
- --only-used flag reduces noise significantly - Partial recovery info (phone/email) is valuable intelligence - Cross-reference results with Sherlock using email prefix - Personal emails (Gmail, Outlook) yield more results than work emails - Some sites notify users of password reset attempts (OPSEC risk) - Rate limiting is aggressive on some sites; be patient - Combine with HIBP to check breach exposure for found accounts - Old/inactive accounts may still show as registered - Results change over time as users create/delete accounts - Use Python API for integration into OSINT pipelines