How to Change Your IP Address When Holehe Detects Rate Limiting

You can bypass Holehe rate limiting by routing traffic through a different IP address using VPNs, Tor SOCKS5 proxies, rotating proxy services, or manual network changes, since Holehe respects standard HTTP_PROXY/HTTPS_PROXY environment variables through its requests-based HTTP stack.

Holehe is an open-source OSINT tool that checks email address usage across hundreds of online services. When services detect too many requests from a single IP, they return rate-limit responses that Holehe flags and stops processing for that service. Understanding how to rotate your IP address allows you to continue reconnaissance without interruption. This guide explains the rate-limit detection mechanism in Holehe and provides actionable methods to change your IP when needed.

How Holehe Detects Rate Limiting

Holehe determines rate limiting through a standardized response dictionary that every service module returns. Each module (such as holehe/modules/social_media/twitter.py or holehe/modules/social_media/instagram.py) defines flags including frequent_rate_limit and rateLimit to indicate when a remote service has blocked an IP.

The rateLimit boolean specifically signals that the last HTTP call was rejected due to IP-based throttling. When rateLimit is True, Holehe ceases further requests to that service and reports the limitation to the user. To resume scanning, you must present a fresh IP address that the remote service has not flagged.

Method 1: Use a VPN (Simplest Approach)

A VPN routes all outbound traffic through a remote server, masking your original IP with the VPN endpoint's address. This requires no code modifications to Holehe.


# Connect to your VPN provider

openvpn --config your-vpn-config.ovpn

# Verify IP change

curl https://ipinfo.io

# Run Holehe with new IP

holehe -l target@example.com

Method 2: Route Through Tor (SOCKS5 Proxy)

Tor provides automatic IP rotation through its exit nodes. Configure Holehe to use Tor's SOCKS5 proxy at 127.0.0.1:9050.

First, ensure Tor is running:

tor &

Then export proxy environment variables before invoking Holehe:

export HTTP_PROXY="socks5://127.0.0.1:9050"
export HTTPS_PROXY="socks5://127.0.0.1:9050"

holehe -l target@example.com

Holehe's requests dependency automatically reads these variables and routes all HTTP calls through the Tor network.

Method 3: Rotating Proxy Services

Commercial proxy services provide fresh IP addresses per request or on demand. Examples include Bright Data, ScraperAPI, Oxylabs, and Smartproxy.

export HTTP_PROXY="http://username:password@proxy-provider.com:8080"
export HTTPS_PROXY="http://username:password@proxy-provider.com:8080"

holehe -l target@example.com

For session-based rotation, configure your provider's endpoint to maintain sticky sessions, then request a new IP through their API when rate limited.

Method 4: Patch holehe/localuseragent.py for Persistent Proxy Support

For a more integrated solution, modify holehe/localuseragent.py to create a requests.Session with built-in proxy configuration. This file is where Holehe centralizes HTTP session creation and user-agent management.

Add the following at the top of holehe/localuseragent.py:

import os
import requests

# Read proxy from environment variable

PROXY = os.getenv("HOLEHE_PROXY")

# Create session with proxy if configured

SESSION = requests.Session()
if PROXY:
    SESSION.proxies.update({
        "http": PROXY,
        "https": PROXY
    })

Then run Holehe with your proxy:

export HOLEHE_PROXY="http://proxy.example.com:8080"
holehe -l target@example.com

This approach ensures all module calls inherit the same proxied session without requiring repeated environment variable exports.

Method 5: Manual IP Change (Network Switching)

Restart your router to obtain a new dynamic IP from your ISP, or switch to an alternative network such as a mobile hotspot:


# Switch to mobile hotspot, then verify

curl https://ipinfo.io

# Run Holehe

holehe -l target@example.com

This method requires no software configuration but lacks the automation and reliability of VPN or proxy solutions.

Key Source Files in Holehe

Understanding these files helps you customize proxy behavior and trace rate-limit handling:

Verification Steps

Always confirm your IP has actually changed before resuming Holehe operations:


# Check current public IP

curl https://ipinfo.io/ip

# Run a single test to verify no rate limit

holehe -l test@example.com --only twitter

Summary

  • Holehe detects rate limiting through the rateLimit boolean returned by each service module
  • Environment variables work immediately: HTTP_PROXY and HTTPS_PROXY are respected by Holehe's requests dependency
  • VPNs require no code changes — connect and run
  • Tor provides free IP rotation via SOCKS5 proxy at 127.0.0.1:9050
  • Rotating proxies offer commercial reliability with per-request or sticky-session IP assignment
  • holehe/localuseragent.py is the optimal injection point for persistent session-level proxy configuration

Frequently Asked Questions

Does Holehe have built-in proxy rotation?

No. Holehe relies on the standard requests library, which reads HTTP_PROXY/HTTPS_PROXY environment variables. For automatic rotation, you must configure these variables externally or patch holehe/localuseragent.py with custom session logic.

Why does Holehe stop after detecting rate limiting instead of retrying?

Holehe's design prioritizes responsible OSINT practices. When rateLimit: True is returned, the tool stops further requests to prevent service abuse and potential IP blacklisting. You must manually change your IP and restart the scan.

Can I use a proxy with authentication in Holehe?

Yes. Include credentials directly in the proxy URL: http://username:password@proxy.host:port. Ensure special characters in passwords are URL-encoded. Both environment variables and direct SESSION.proxies configuration in localuseragent.py support authenticated proxies.

Will changing my IP guarantee access to rate-limited services?

Not always. Some services employ additional detection methods including browser fingerprinting, CAPTCHA challenges, or account-based tracking. IP rotation addresses IP-based rate limiting but may not overcome these secondary protections.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →