What Are the Four Detection Methods Used by Holehe Modules?

TLDR: Holehe assigns every OSINT module one of four detection methods—register, login, password recovery, or other—to determine the specific HTTP request strategy used to verify if an email address exists on a target service.

Holehe is an open-source email reconnaissance tool maintained by megadose that checks if an address is registered across hundreds of online platforms. Each service module in the repository sets a method variable that instructs the core engine which probing strategy to execute. According to the megadose/holehe source code, exactly four distinct detection methods exist across the entire codebase.

The Four Detection Methods Defined

Every module in holehe/modules/ declares its probing strategy by assigning a string to the method variable. These values tell holehe/core.py how to interpret the HTTP response when checking for account existence.

Register Method

The register method simulates a registration request to determine if an email address is already in use. This approach typically involves submitting the target email to a sign-up endpoint and parsing the response for "email already exists" errors.

In holehe/modules/programing/github.py, the module declares:

method = "register"

This instructs Holehe to treat the service as a registration-style check, where existing accounts return positive matches.

Login Method

The login method attempts a login-style request, often targeting password-recovery or sign-in endpoints that reveal account existence without attempting authentication. This differs from register by utilizing existing user flows rather than account creation paths.

The implementation in holehe/modules/social_media/snapchat.py sets:

method = "login"

This tells the core engine to expect login-form responses that indicate whether the email is tied to an active account.

Password Recovery Method

The password recovery method targets dedicated password-reset endpoints to confirm email presence. This strategy checks if the address can receive a reset token, providing a reliable indicator of account existence without triggering registration or login security mechanisms.

In holehe/modules/software/adobe.py, the module specifies:

method = "password recovery"

This detection type is distinct from the generic login method because it specifically abuses password-recovery workflows rather than authentication attempts.

Other Method

The other method serves as a fallback for services requiring custom logic that does not fit the standard three categories. Modules using this approach implement unique HTTP sequences or API calls to verify email presence.

The holehe/modules/software/office365.py module demonstrates this pattern:

method = "other"

This classification allows developers to handle edge cases while maintaining compatibility with the core engine's asynchronous execution framework.

How Detection Methods Work in the Core Engine

The holehe/core.py file contains the engine that loads all modules and executes them asynchronously. When processing results, the core references each module's method variable to categorize the type of probe performed, though the output formatting itself is handled separately.

Results are formatted by holehe.core.print_result, which prepends indicators to the console output:

$ holehe example@example.com
[+] github.com               # register method – email found

[-] snapchat.com             # login method – email not found

[+] adobe.com                # password recovery method – email found

[+] some-other-service.com   # other method – custom check

The bracketed symbols ([+], [-]) visualize the boolean results returned by each module's detection logic, while the underlying method value determines which probing strategy generated that result.

Summary

  • Holehe uses exactly four detection methods: register, login, password recovery, and other.
  • Each module sets a method variable (e.g., in github.py, snapchat.py, adobe.py, or office365.py) to declare its probing strategy.
  • The register method checks account creation endpoints, login uses authentication flows, password recovery targets reset mechanisms, and other handles custom implementations.
  • The core engine in holehe/core.py processes these methods asynchronously, with print_result formatting the output indicators.

Frequently Asked Questions

What is the difference between the register and login detection methods?

The register method probes account creation endpoints to see if an email is already taken, while the login method attempts to verify existence through authentication or password-recovery workflows. The distinction matters because registration checks often trigger different rate-limiting or security responses than login attempts.

How does Holehe handle services that don't fit standard detection patterns?

Services with unique verification requirements use the other detection method, as implemented in modules like office365.py. This classification allows module authors to write custom HTTP logic while maintaining compatibility with the core engine's asynchronous runner and result formatter.

Where is the detection method defined in a Holehe module?

Each module defines its detection strategy by setting the method variable at the module level, typically near the top of the file alongside metadata like the service name and description. For example, holehe/modules/programing/github.py contains method = "register" to declare its probing approach.

Can I add a new detection method to Holehe?

No, the codebase strictly enforces only the four existing methods—register, login, password recovery, and other. The core engine in holehe/core.py expects these specific string values, so custom modules must categorize their logic under the other method if they do not fit the standard three categories.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →