Detection Methods Used by Holehe Modules: A Complete Guide
Holehe uses four distinct detection methods across its modules—register, login, password recovery, and other—to determine whether an email address is associated with online services.
Holehe is an open-source email enumeration tool written in Python, maintained by megadose on GitHub. Each module in the holehe/modules/ directory implements a detection method that defines how the service validates email presence. Understanding these detection methods helps analysts interpret results and extend the tool with new modules.
The Four Detection Methods in Holehe
Every Holehe module declares a method string variable that categorizes its approach. The core runner in holehe/core.py executes all modules regardless of method type, using this value only for metadata in output formatting.
Register Detection Method
The register method checks whether an email address can be used to create a new account. This typically involves sending a request to a registration validation endpoint that returns whether the address is already taken.
- Mechanism: Queries signup or email-validation APIs
- Example modules:
spotify,google,amazon,reddit - Interpretation: "Already registered" means the email exists on the platform
# holehe/modules/music/spotify.py
method = "register"
According to the Holehe source code, this is the most common detection method. The spotify module sends a POST request to Spotify's account validation endpoint with spotify/__init__.py containing the actual HTTP logic.
Login Detection Method
The login method attempts a login-related request to determine if the service recognizes the email address. Unlike register, this may query login forms or authentication endpoints directly.
- Mechanism: Submits login-form data or queries authentication APIs
- Example modules:
anydo,flickr,hubspot,wordpress,yahoo - Interpretation: Email existence inferred from login-specific responses
In holehe/modules/mails/yahoo.py, the method is declared as:
method = "login"
The Yahoo module queries Yahoo's authentication flow to check email validity, distinguishing between "account not found" and other error conditions.
Password Recovery Detection Method
The password recovery method triggers a password reset flow to verify email association. This leverages the fact that password recovery systems typically confirm whether an email exists before sending reset instructions.
- Mechanism: Initiates forgot-password workflows
- Example module:
mail_ru - Interpretation: Direct confirmation via password-reset pipeline
The mail_ru module in holehe/modules/mails/mail_ru.py implements this approach:
method = "password recovery"
This technique is particularly effective when registration endpoints are heavily protected or rate-limited, as password recovery flows often have different security constraints.
Other Detection Method
The other category captures custom techniques that don't fit standard registration or login patterns. These modules employ service-specific tricks to enumerate emails.
- Mechanism: Service-specific API quirks, timing attacks, or unique validation flows
- Example modules:
protonmail,duolingo - Interpretation: Requires case-by-case understanding of the technique
In holehe/modules/mails/protonmail.py:
method = "other"
The ProtonMail module uses ProtonMail's specific account lookup mechanisms that differ from conventional registration checks.
How Detection Methods Flow Through Core
The holehe/core.py file orchestrates execution without method-specific branching. Here's the operational flow:
- Module discovery: Dynamically imports all Python files in
holehe/modules/ - Method extraction: Reads the
methodstring as metadata - Async execution: Runs each module's main function with shared HTTP client
- Result tagging: Attaches the
methodvalue to output for user context
# Conceptual flow from holehe/core.py
async def execute_module(module, email, client):
result = await module.run(email, client)
result['method'] = module.method # Preserves detection method type
return result
This design means new detection strategies require no core changes—just set method appropriately in your module.
Practical Usage and Output Interpretation
Running Holehe shows detection methods in contextual output:
$ holehe alice@example.com
Typical results display:
[+] spotify.com # register → account exists (cannot register)
[-] amazon.com # register → available for registration (not found)
[+] flickr.com # login → address recognized
[+] mail.ru # password recovery → address found
The [+] and [-] indicators show existence versus absence, while the comment reveals which detection method yielded the result.
Inspecting Module Detection Methods Programmatically
>>> from holehe.modules.music import spotify
>>> print(spotify.method)
'register'
>>> from holehe.modules.mails import protonmail
>>> print(protonmail.method)
'other'
Key Source Files for Detection Methods
| File Path | Detection Method | Purpose |
|---|---|---|
holehe/core.py |
All (orchestration) | Imports modules and executes detection functions |
holehe/modules/music/spotify.py |
register |
Music streaming account validation |
holehe/modules/mails/google.py |
register |
Complex multi-step Google account check |
holehe/modules/mails/yahoo.py |
login |
Yahoo authentication flow probe |
holehe/modules/mails/mail_ru.py |
password recovery |
Mail.ru password reset enumeration |
holehe/modules/mails/protonmail.py |
other |
Privacy-focused email service check |
Summary
- Holehe modules use four detection methods:
register,login,password recovery, andother - The
methodstring variable in each module provides metadata only—core execution is method-agnostic registerchecks account existence via signup validation (most common)loginqueries authentication endpoints directlypassword recoveryexploits password-reset flowsotheraccommodates service-specific enumeration techniques- All detection methods are implemented in
holehe/modules/and executed byholehe/core.py
Frequently Asked Questions
How do I add a new detection method to Holehe?
You don't need to modify core code. Create a module in holehe/modules/ with a method variable set to any descriptive string. The holehe/core.py runner will execute it automatically. Use existing method names (register, login, etc.) for consistency, or create new ones for novel techniques.
Can the same service use multiple detection methods?
Yes, though typically one method per module. You could create multiple modules for the same service using different approaches—e.g., example_register.py and example_recovery.py—each with distinct method values targeting different endpoints.
Why does Holehe categorize detection methods at all?
The method metadata helps analysts interpret results and assess confidence. A password recovery hit on mail_ru carries different implications than a register miss on spotify. It also enables filtering and reporting in downstream tools consuming Holehe JSON output.
Which detection method is most reliable?
Reliability depends on the target service's API stability. register methods are most common and well-tested in Holehe. password recovery techniques often face stricter rate-limiting. The other category varies by implementation—review the specific module's code in holehe/modules/ before relying on its output.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →