Holehe Mails Category: Examples of Email Services Checked by the Open-Source OSINT Tool

Holehe's mails module includes dedicated checkers for Gmail, Yahoo, ProtonMail, Mail.ru, and La Poste, among others.

Holehe is an open-source OSINT (Open Source Intelligence) tool developed by megadose that verifies whether an email address is registered across hundreds of online services. The mails category specifically targets email providers, making it invaluable for investigators and security researchers who need to map digital footprints. This article examines the specific services covered in the mails module, how they work, and how to use them both from the command line and programmatically.

What Is the Holehe Mails Module?

The mails module consolidates all email-provider checks into a single Python package located at holehe/modules/mails/. Each service is implemented as an individual Python file containing a check function that probes the provider's registration or password-reset endpoints to determine account existence.

According to the holehe source code, the module follows a consistent pattern: every checker file exports an asynchronous check coroutine that accepts an email address and an HTTP client session, then returns a structured result indicating whether the account was found.

Email Services Checked in the Mails Category

Holehe currently includes dedicated checkers for these major email providers:

Service Module File Description
Google (Gmail) google.py Checks Gmail account existence via Google's authentication flows
Yahoo yahoo.py Probes Yahoo Mail registration endpoints
ProtonMail protonmail.py Verifies ProtonMail account status through their API
Mail.ru mail_ru.py Tests Russian Mail.ru email services
La Poste laposte.py Checks French postal service email (laposte.net)

These files reside in holehe/modules/mails/ and are automatically discovered when the mails category is invoked.

How to Use Holehe Mails Category

Command-Line Usage

Run Holehe with the --mail flag to test an email address against all mail service modules:

holehe -u example@example.com --mail

Sample output:


[+] Google        : account found
[+] Yahoo         : no account
[+] ProtonMail    : account found
[+] Mail.ru       : no account
[+] La Poste      : account found

Omit --mail to run the full suite of Holehe modules across all categories.

Programmatic Usage

Import individual mail modules to check specific providers from Python code:

from holehe.core import Holehe
from holehe.modules.mails import google, yahoo, protonmail

holehe = Holehe()
email = "example@example.com"

# Check Google

google_result = holehe.check_module(google, email)
print("Google:", google_result)

# Check Yahoo

yahoo_result = holehe.check_module(yahoo, email)
print("Yahoo:", yahoo_result)

# Check ProtonMail

protonmail_result = holehe.check_module(protonmail, email)
print("ProtonMail:", protonmail_result)

Each check_module call returns a dictionary with keys such as exists (boolean), rateLimit (boolean), and other provider-specific metadata.

Key Implementation Files in holehe/modules/mails/

Understanding the source structure helps when extending or debugging the mails category:

  • __init__.py — Package initializer that registers all mail modules for dynamic discovery
  • google.py — Implements check() for Gmail using Google's signup validation endpoints
  • yahoo.py — Yahoo Mail checker that exploits registration form feedback
  • protonmail.py — ProtonMail verifier using their public user existence API
  • mail_ru.py — Mail.ru checker for the Russian email ecosystem
  • laposte.py — La Poste (laposte.net) checker for French government-affiliated email

Each module follows Holehe's standard interface: an async check(email, client, out) function that appends results to the out list parameter.

Adding New Mails Checkers

The modular architecture makes it straightforward to extend the mails category. To add a new provider:

  1. Create a new Python file in holehe/modules/mails/
  2. Define an async check function with the standard signature
  3. Implement HTTP requests to the target's registration or recovery endpoints
  4. Parse responses to determine account existence
  5. Append a result dictionary to the output list

New modules are automatically picked up by Holehe's module loader without requiring changes to core code.

Summary

  • Holehe's mails category contains dedicated checkers for Gmail, Yahoo, ProtonMail, Mail.ru, and La Poste
  • Each service is implemented as a standalone Python module in holehe/modules/mails/
  • The check() function in each module handles provider-specific HTTP probing
  • Use --mail from the command line or import modules directly for programmatic access
  • All mail checkers follow a consistent async interface for easy extension

Frequently Asked Questions

How does Holehe verify email accounts without passwords?

Holehe exploits public registration and password-reset endpoints that return different responses depending on whether an email is registered. For example, Google's signup flow reveals account existence through error messages, while ProtonMail exposes a public API endpoint for user lookup. These techniques avoid any authentication requirements.

Can I run Holehe mails checkers on multiple emails at once?

The command-line tool processes one email per invocation. For batch operations, use the programmatic API: create a script that iterates over your email list and calls holehe.check_module() for each target. Be mindful of rate limiting—aggressive scanning may trigger blocks from providers.

What information does Holehe return besides account existence?

Each mails module returns a structured result including: exists (boolean account status), rateLimit (whether the provider throttled the request), emailrecovery (partial recovery email if leaked), phoneNumber (partial phone if exposed), and others (provider-specific metadata). Not all fields populate for every service.

Holehe is a legitimate security research tool when used appropriately. Always ensure you have authorization before investigating third-party accounts, and comply with local laws regarding data privacy and computer access. The tool is designed for self-assessment, authorized penetration testing, and OSINT investigations with proper legal basis.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →