← All cheat sheets

HOLEHE

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Email OSINT tool that checks if an email address is registered
on 120+ websites using password reset and login flows.

INSTALLATION#

pip install holehe

# From source
git clone https://github.com/megadose/holehe
cd holehe
pip install .

BASIC USAGE#

# Check single email
holehe user@example.com

# Check with rate limiting (recommended)
holehe user@example.com --timeout 10

# Only show registered accounts
holehe user@example.com --only-used

# CSV output
holehe user@example.com --csv output.csv

# No color
holehe user@example.com --no-color

PYTHON API#

import trio
from holehe.core import holehe

async def main():
    email = "user@example.com"
    results = await holehe(email)
    for result in results:
        if result['exists']:
            print(f"[+] {result['name']}: Registered")

trio.run(main)

# With custom modules
from holehe.modules.social_media import instagram, twitter

OUTPUT FORMAT#

# Each result contains:
# [+] Site: email is registered
# [-] Site: email is not registered
# [x] Site: rate limited or error

# Fields in CSV/JSON output:
  name         # Website name
  domain       # Website URL
  exists       # True/False
  emailrecovery # Email shown in recovery (if partial)
  phoneNumber  # Phone shown in recovery (if partial)
  others       # Additional info

SUPPORTED SITES (CATEGORIES)#

# Social Media
  Instagram, Twitter/X, Facebook, Pinterest,
  Snapchat, TikTok, Tumblr, Reddit

# Professional
  LinkedIn, Freelancer, Fiverr, Upwork

# Email/Communication
  Google (Gmail), Microsoft (Outlook/Hotmail),
  Yahoo, ProtonMail, Mail.ru, Zoho

# Shopping
  Amazon, eBay, AliExpress, Etsy,
  Nike, Adidas, H&M

# Streaming/Entertainment
  Spotify, Netflix, Disney+, Deezer,
  SoundCloud, Twitch, Vimeo

# Development
  GitHub, GitLab, Bitbucket, Docker Hub,
  Npmjs, PyPI

# Gaming
  Steam, Epic Games, EA (Origin),
  Ubisoft, Blizzard

# Finance
  PayPal, Stripe, Coinbase, Binance

# Cloud/Productivity
  Dropbox, Evernote, Notion, Trello,
  Atlassian, Adobe

# Dating
  Tinder, Bumble, OKCupid, Badoo

# Other
  Gravatar, WordPress, Imgur, Archive.org,
  Duolingo, Strava

HOW IT WORKS#

# Holehe uses legitimate website features:
  1. Password reset forms (most common)
     - Submit email to "forgot password"
     - Check if site says "email sent" vs "account not found"

  2. Registration forms
     - Try to register with the email
     - Check if site says "email already in use"

  3. Login forms
     - Some sites reveal email existence on login attempt

# Important: this is NOT brute forcing passwords
# It only checks if the email is registered

PARTIAL DATA RECOVERY#

# Some sites reveal partial information during password reset:

# Email recovery hints
  "We sent a code to j***@g***.com"      # Partial email
  "We sent a code to +1***567"            # Partial phone

# Holehe captures these hints when available
# Useful for discovering:
  - Alternative email addresses
  - Phone number patterns
  - Recovery email providers

RATE LIMITING & OPSEC#

# Best practices to avoid blocks:
  - Use --timeout 10 or higher between requests
  - Use a VPN or proxy to rotate IPs
  - Don't scan the same email repeatedly
  - Space out scans of emails from the same org

# Some sites will:
  - Block your IP after too many requests
  - Send notification to the account owner
  - Log the lookup attempt
  - Rate limit (shown as [x] in output)

# For stealth:
  - Run behind Tor or VPN
  - Use residential proxies
  - Limit to specific sites with --module

WORKFLOW EXAMPLES#

# 1. Email → Account Discovery
holehe target@company.com --only-used --csv results.csv

# 2. Combine with Sherlock
#    Email prefix as username
sherlock targetuser
holehe targetuser@gmail.com
holehe targetuser@outlook.com

# 3. From breach data
#    Found email in breach → check what sites they use
holehe breached_user@email.com --only-used

# 4. Batch processing
#!/bin/bash
while IFS= read -r email; do
    echo "=== $email ==="
    holehe "$email" --only-used --timeout 10
    sleep 5
done < emails.txt

# 5. Social engineering prep
#    Know which services a target uses
#    Craft targeted phishing lures matching their accounts

COMPARISON WITH SIMILAR TOOLS#

Tool         Method          Scope        Notes
----         ------          -----        -----
Holehe       Email lookup    120+ sites   Password reset probes
Sherlock     Username        400+ sites   Profile page checks
GHunt        Google account  Google       Deep Google OSINT
Maigret      Username        3000+ sites  Sherlock fork
Epieos       Email/phone     Many         Web-based, limited free

TIPS#

  - --only-used flag reduces noise significantly
  - Partial recovery info (phone/email) is valuable intelligence
  - Cross-reference results with Sherlock using email prefix
  - Personal emails (Gmail, Outlook) yield more results than work emails
  - Some sites notify users of password reset attempts (OPSEC risk)
  - Rate limiting is aggressive on some sites; be patient
  - Combine with HIBP to check breach exposure for found accounts
  - Old/inactive accounts may still show as registered
  - Results change over time as users create/delete accounts
  - Use Python API for integration into OSINT pipelines