Detection Methods Used by Holehe Modules: A Complete Guide

Holehe uses four distinct detection methods across its modules—register, login, password recovery, and other—to determine whether an email address is associated with online services.

Holehe is an open-source email enumeration tool written in Python, maintained by megadose on GitHub. Each module in the holehe/modules/ directory implements a detection method that defines how the service validates email presence. Understanding these detection methods helps analysts interpret results and extend the tool with new modules.

The Four Detection Methods in Holehe

Every Holehe module declares a method string variable that categorizes its approach. The core runner in holehe/core.py executes all modules regardless of method type, using this value only for metadata in output formatting.

Register Detection Method

The register method checks whether an email address can be used to create a new account. This typically involves sending a request to a registration validation endpoint that returns whether the address is already taken.

  • Mechanism: Queries signup or email-validation APIs
  • Example modules: spotify, google, amazon, reddit
  • Interpretation: "Already registered" means the email exists on the platform

# holehe/modules/music/spotify.py

method = "register"

According to the Holehe source code, this is the most common detection method. The spotify module sends a POST request to Spotify's account validation endpoint with spotify/__init__.py containing the actual HTTP logic.

Login Detection Method

The login method attempts a login-related request to determine if the service recognizes the email address. Unlike register, this may query login forms or authentication endpoints directly.

  • Mechanism: Submits login-form data or queries authentication APIs
  • Example modules: anydo, flickr, hubspot, wordpress, yahoo
  • Interpretation: Email existence inferred from login-specific responses

In holehe/modules/mails/yahoo.py, the method is declared as:

method = "login"

The Yahoo module queries Yahoo's authentication flow to check email validity, distinguishing between "account not found" and other error conditions.

Password Recovery Detection Method

The password recovery method triggers a password reset flow to verify email association. This leverages the fact that password recovery systems typically confirm whether an email exists before sending reset instructions.

  • Mechanism: Initiates forgot-password workflows
  • Example module: mail_ru
  • Interpretation: Direct confirmation via password-reset pipeline

The mail_ru module in holehe/modules/mails/mail_ru.py implements this approach:

method = "password recovery"

This technique is particularly effective when registration endpoints are heavily protected or rate-limited, as password recovery flows often have different security constraints.

Other Detection Method

The other category captures custom techniques that don't fit standard registration or login patterns. These modules employ service-specific tricks to enumerate emails.

  • Mechanism: Service-specific API quirks, timing attacks, or unique validation flows
  • Example modules: protonmail, duolingo
  • Interpretation: Requires case-by-case understanding of the technique

In holehe/modules/mails/protonmail.py:

method = "other"

The ProtonMail module uses ProtonMail's specific account lookup mechanisms that differ from conventional registration checks.

How Detection Methods Flow Through Core

The holehe/core.py file orchestrates execution without method-specific branching. Here's the operational flow:

  1. Module discovery: Dynamically imports all Python files in holehe/modules/
  2. Method extraction: Reads the method string as metadata
  3. Async execution: Runs each module's main function with shared HTTP client
  4. Result tagging: Attaches the method value to output for user context

# Conceptual flow from holehe/core.py

async def execute_module(module, email, client):
    result = await module.run(email, client)
    result['method'] = module.method  # Preserves detection method type

    return result

This design means new detection strategies require no core changes—just set method appropriately in your module.

Practical Usage and Output Interpretation

Running Holehe shows detection methods in contextual output:

$ holehe alice@example.com

Typical results display:


[+] spotify.com          # register → account exists (cannot register)

[-] amazon.com           # register → available for registration (not found)

[+] flickr.com           # login → address recognized

[+] mail.ru              # password recovery → address found

The [+] and [-] indicators show existence versus absence, while the comment reveals which detection method yielded the result.

Inspecting Module Detection Methods Programmatically

>>> from holehe.modules.music import spotify
>>> print(spotify.method)
'register'

>>> from holehe.modules.mails import protonmail
>>> print(protonmail.method)
'other'

Key Source Files for Detection Methods

File Path Detection Method Purpose
holehe/core.py All (orchestration) Imports modules and executes detection functions
holehe/modules/music/spotify.py register Music streaming account validation
holehe/modules/mails/google.py register Complex multi-step Google account check
holehe/modules/mails/yahoo.py login Yahoo authentication flow probe
holehe/modules/mails/mail_ru.py password recovery Mail.ru password reset enumeration
holehe/modules/mails/protonmail.py other Privacy-focused email service check

Summary

  • Holehe modules use four detection methods: register, login, password recovery, and other
  • The method string variable in each module provides metadata only—core execution is method-agnostic
  • register checks account existence via signup validation (most common)
  • login queries authentication endpoints directly
  • password recovery exploits password-reset flows
  • other accommodates service-specific enumeration techniques
  • All detection methods are implemented in holehe/modules/ and executed by holehe/core.py

Frequently Asked Questions

How do I add a new detection method to Holehe?

You don't need to modify core code. Create a module in holehe/modules/ with a method variable set to any descriptive string. The holehe/core.py runner will execute it automatically. Use existing method names (register, login, etc.) for consistency, or create new ones for novel techniques.

Can the same service use multiple detection methods?

Yes, though typically one method per module. You could create multiple modules for the same service using different approaches—e.g., example_register.py and example_recovery.py—each with distinct method values targeting different endpoints.

Why does Holehe categorize detection methods at all?

The method metadata helps analysts interpret results and assess confidence. A password recovery hit on mail_ru carries different implications than a register miss on spotify. It also enables filtering and reporting in downstream tools consuming Holehe JSON output.

Which detection method is most reliable?

Reliability depends on the target service's API stability. register methods are most common and well-tested in Holehe. password recovery techniques often face stricter rate-limiting. The other category varies by implementation—review the specific module's code in holehe/modules/ before relying on its output.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →