Holehe Command-Line Arguments: Complete CLI Reference for Email OSINT Scanning

Holehe supports 6 command-line arguments including one required positional argument (email) and 5 optional flags that control output formatting, runtime behavior, and result export options.

Holehe is an open-source email reconnaissance tool developed by megadose that checks email addresses against 120+ websites to identify where they're registered. Understanding its command-line interface is essential for effective OSINT investigations and automation workflows. This guide explains every argument available in holehe/core.py with practical usage examples.


Required Positional Argument: email

The only mandatory input is the target email address you want to scan.

Argument Format Description Source
email Positional One or more email addresses to investigate. Per the implementation in holehe/core.py lines 181-184, only the first email is processed—additional addresses are silently ignored. core.py#L181

# Basic usage: scan a single email

holehe target@example.com

# Multiple addresses provided (only first is used)

holehe target@example.com another@example.com

Output Control Flags

--only-used

Filters results to show only sites where the email is actually registered. By default, Holehe displays all checked services regardless of outcome. This flag reduces noise in large-scale investigations.

Source Implementation
core.py#L184-L186 Boolean flag passed to result formatter
holehe target@example.com --only-used

--no-color

Disables ANSI color codes in terminal output. Essential for environments without color support, log file redirection, or when piping output to other tools.

Source Implementation
core.py#L186-L188 Overrides default colorama styling
holehe target@example.com --no-color > results.txt

--no-clear

Prevents the terminal from being cleared before displaying results. Preserves prior command history and output—useful for iterative investigations or debugging.

Source Implementation
core.py#L188-L190 Skips os.system('clear') call
holehe target@example.com --no-clear

Runtime Behavior Flags

-NP / --no-password-recovery

Skips password-recovery attempt modules on services supporting this method (e.g., Adobe, Mail.ru). Reduces:

  • Network requests and scan duration
  • Risk of rate-limiting
  • Account lockout triggers on target services
Source Implementation
core.py#L190-L192 Boolean flag filtering module selection
holehe target@example.com --no-password-recovery

Data Export and Performance

-C / --csv

Exports the complete result set to a timestamped CSV file. Filename format: holehe_{email}_{timestamp}.csv. Captures all metadata including rate-limited services and errors.

Source Implementation
core.py#L192-L194 Triggers pandas.DataFrame.to_csv() export
holehe target@example.com --csv

-T / --timeout

Sets the HTTP request timeout in seconds for each module. Default: 10 seconds. Increase for slow connections or decrease for faster failure on unresponsive services.

Source Implementation
core.py#L194-L196 Passed to aiohttp.ClientTimeout

# Aggressive timing for fast networks

holehe target@example.com --timeout 5

# Lenient timing for Tor/proxied connections

holehe target@example.com --timeout 30

Complete Argument Parsing Flow

All arguments are processed through Python's argparse library at runtime. The parser initialization and parse_args() call occur at holehe/core.py line 198, feeding directly into the asynchronous execution engine.


# Simplified structure from holehe/core.py

parser = argparse.ArgumentParser()
parser.add_argument("email", nargs="+", help="Target email address")
parser.add_argument("--only-used", action="store_true", ...)
parser.add_argument("--no-color", action="store_true", ...)
parser.add_argument("--no-clear", action="store_true", ...)
parser.add_argument("-NP", "--no-password-recovery", action="store_true", ...)
parser.add_argument("-C", "--csv", action="store_true", ...)
parser.add_argument("-T", "--timeout", type=int, default=10, ...)
args = parser.parse_args()  # Line 198

Practical Usage Patterns

Silent Logging-Compatible Scan

holehe target@example.com --no-color --no-clear --only-used --csv

Fast, Non-Intrusive Reconnaissance

holehe target@example.com --no-password-recovery --timeout 5

Full Documentation Export

holehe target@example.com --csv --timeout 20

Summary

  • One required argument: email (positional, accepts multiple but uses only first)
  • Five optional flags: --only-used, --no-color, --no-clear, --no-password-recovery (-NP), --csv (-C), --timeout (-T)
  • All arguments defined in holehe/core.py lines 181-198 using Python's argparse
  • Default timeout: 10 seconds; adjustable per network conditions
  • CSV export: Generates timestamped files for forensic documentation

Frequently Asked Questions

How do I scan multiple emails with Holehe?

Holehe's CLI accepts multiple email addresses but only processes the first one per the nargs="+" implementation in holehe/core.py lines 181-184. For batch processing, use shell loops:

for email in $(cat emails.txt); do holehe "$email" --csv; done

Can I disable all visual formatting for automated scripts?

Yes. Combine --no-color (removes ANSI codes) and --no-clear (preserves terminal history). For fully machine-readable output, add --csv to generate structured files instead of parsing terminal text.

What happens if I set timeout too low?

Modules hitting the timeout will return rate-limited or failed status rather than completed checks. The default 10 seconds balances thoroughness and speed; reduce only on reliable, fast connections.

Does --only-used affect CSV export?

No. --only-used filters terminal display only. The --csv flag always exports all results including negative findings and errors, providing complete forensic records regardless of display filters.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →