# Detection Methods Used by Holehe Modules: A Complete Guide

> Discover the four detection methods Holehe modules use to check email associations with online services. Learn how register, login, password recovery, and other modules work.

- Repository: [Palenath/holehe](https://github.com/megadose/holehe)
- Tags: deep-dive
- Published: 2026-09-01

---

**Holehe uses four distinct detection methods across its modules—`register`, `login`, `password recovery`, and `other`—to determine whether an email address is associated with online services.**

Holehe is an open-source email enumeration tool written in Python, maintained by `megadose` on GitHub. Each module in the `holehe/modules/` directory implements a **detection method** that defines how the service validates email presence. Understanding these detection methods helps analysts interpret results and extend the tool with new modules.

## The Four Detection Methods in Holehe

Every Holehe module declares a `method` string variable that categorizes its approach. The core runner in [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py) executes all modules regardless of method type, using this value only for metadata in output formatting.

### Register Detection Method

The **`register`** method checks whether an email address can be used to create a new account. This typically involves sending a request to a registration validation endpoint that returns whether the address is already taken.

- **Mechanism**: Queries signup or email-validation APIs
- **Example modules**: `spotify`, `google`, `amazon`, `reddit`
- **Interpretation**: "Already registered" means the email exists on the platform

```python

# holehe/modules/music/spotify.py

method = "register"

```

According to the Holehe source code, this is the most common detection method. The `spotify` module sends a POST request to Spotify's account validation endpoint with [`spotify/__init__.py`](https://github.com/megadose/holehe/blob/main/spotify/__init__.py) containing the actual HTTP logic.

### Login Detection Method

The **`login`** method attempts a login-related request to determine if the service recognizes the email address. Unlike `register`, this may query login forms or authentication endpoints directly.

- **Mechanism**: Submits login-form data or queries authentication APIs
- **Example modules**: `anydo`, `flickr`, `hubspot`, `wordpress`, `yahoo`
- **Interpretation**: Email existence inferred from login-specific responses

In [`holehe/modules/mails/yahoo.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/mails/yahoo.py), the method is declared as:

```python
method = "login"

```

The Yahoo module queries Yahoo's authentication flow to check email validity, distinguishing between "account not found" and other error conditions.

### Password Recovery Detection Method

The **`password recovery`** method triggers a password reset flow to verify email association. This leverages the fact that password recovery systems typically confirm whether an email exists before sending reset instructions.

- **Mechanism**: Initiates forgot-password workflows
- **Example module**: `mail_ru`
- **Interpretation**: Direct confirmation via password-reset pipeline

The `mail_ru` module in [`holehe/modules/mails/mail_ru.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/mails/mail_ru.py) implements this approach:

```python
method = "password recovery"

```

This technique is particularly effective when registration endpoints are heavily protected or rate-limited, as password recovery flows often have different security constraints.

### Other Detection Method

The **`other`** category captures custom techniques that don't fit standard registration or login patterns. These modules employ service-specific tricks to enumerate emails.

- **Mechanism**: Service-specific API quirks, timing attacks, or unique validation flows
- **Example modules**: `protonmail`, `duolingo`
- **Interpretation**: Requires case-by-case understanding of the technique

In [`holehe/modules/mails/protonmail.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/mails/protonmail.py):

```python
method = "other"

```

The ProtonMail module uses ProtonMail's specific account lookup mechanisms that differ from conventional registration checks.

## How Detection Methods Flow Through Core

The [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py) file orchestrates execution without method-specific branching. Here's the operational flow:

1. **Module discovery**: Dynamically imports all Python files in `holehe/modules/`
2. **Method extraction**: Reads the `method` string as metadata
3. **Async execution**: Runs each module's main function with shared HTTP client
4. **Result tagging**: Attaches the `method` value to output for user context

```python

# Conceptual flow from holehe/core.py

async def execute_module(module, email, client):
    result = await module.run(email, client)
    result['method'] = module.method  # Preserves detection method type

    return result

```

This design means new detection strategies require no core changes—just set `method` appropriately in your module.

## Practical Usage and Output Interpretation

Running Holehe shows detection methods in contextual output:

```bash
$ holehe alice@example.com

```

Typical results display:

```

[+] spotify.com          # register → account exists (cannot register)

[-] amazon.com           # register → available for registration (not found)

[+] flickr.com           # login → address recognized

[+] mail.ru              # password recovery → address found

```

The `[+]` and `[-]` indicators show existence versus absence, while the comment reveals which detection method yielded the result.

### Inspecting Module Detection Methods Programmatically

```python
>>> from holehe.modules.music import spotify
>>> print(spotify.method)
'register'

>>> from holehe.modules.mails import protonmail
>>> print(protonmail.method)
'other'

```

## Key Source Files for Detection Methods

| File Path | Detection Method | Purpose |
|-----------|------------------|---------|
| [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py) | All (orchestration) | Imports modules and executes detection functions |
| [`holehe/modules/music/spotify.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/music/spotify.py) | `register` | Music streaming account validation |
| [`holehe/modules/mails/google.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/mails/google.py) | `register` | Complex multi-step Google account check |
| [`holehe/modules/mails/yahoo.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/mails/yahoo.py) | `login` | Yahoo authentication flow probe |
| [`holehe/modules/mails/mail_ru.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/mails/mail_ru.py) | `password recovery` | Mail.ru password reset enumeration |
| [`holehe/modules/mails/protonmail.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/mails/protonmail.py) | `other` | Privacy-focused email service check |

## Summary

- Holehe modules use **four detection methods**: `register`, `login`, `password recovery`, and `other`
- The **`method` string variable** in each module provides metadata only—core execution is method-agnostic
- **`register`** checks account existence via signup validation (most common)
- **`login`** queries authentication endpoints directly
- **`password recovery`** exploits password-reset flows
- **`other`** accommodates service-specific enumeration techniques
- All detection methods are implemented in `holehe/modules/` and executed by [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py)

## Frequently Asked Questions

### How do I add a new detection method to Holehe?

You don't need to modify core code. Create a module in `holehe/modules/` with a `method` variable set to any descriptive string. The [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py) runner will execute it automatically. Use existing method names (`register`, `login`, etc.) for consistency, or create new ones for novel techniques.

### Can the same service use multiple detection methods?

Yes, though typically one method per module. You could create multiple modules for the same service using different approaches—e.g., [`example_register.py`](https://github.com/megadose/holehe/blob/main/example_register.py) and [`example_recovery.py`](https://github.com/megadose/holehe/blob/main/example_recovery.py)—each with distinct `method` values targeting different endpoints.

### Why does Holehe categorize detection methods at all?

The `method` metadata helps analysts interpret results and assess confidence. A `password recovery` hit on `mail_ru` carries different implications than a `register` miss on `spotify`. It also enables filtering and reporting in downstream tools consuming Holehe JSON output.

### Which detection method is most reliable?

Reliability depends on the target service's API stability. `register` methods are most common and well-tested in Holehe. `password recovery` techniques often face stricter rate-limiting. The `other` category varies by implementation—review the specific module's code in `holehe/modules/` before relying on its output.