Holehe Mails Category: Examples of Email Services Checked by the Open-Source OSINT Tool
Holehe's mails module includes dedicated checkers for Gmail, Yahoo, ProtonMail, Mail.ru, and La Poste, among others.
Holehe is an open-source OSINT (Open Source Intelligence) tool developed by megadose that verifies whether an email address is registered across hundreds of online services. The mails category specifically targets email providers, making it invaluable for investigators and security researchers who need to map digital footprints. This article examines the specific services covered in the mails module, how they work, and how to use them both from the command line and programmatically.
What Is the Holehe Mails Module?
The mails module consolidates all email-provider checks into a single Python package located at holehe/modules/mails/. Each service is implemented as an individual Python file containing a check function that probes the provider's registration or password-reset endpoints to determine account existence.
According to the holehe source code, the module follows a consistent pattern: every checker file exports an asynchronous check coroutine that accepts an email address and an HTTP client session, then returns a structured result indicating whether the account was found.
Email Services Checked in the Mails Category
Holehe currently includes dedicated checkers for these major email providers:
| Service | Module File | Description |
|---|---|---|
| Google (Gmail) | google.py |
Checks Gmail account existence via Google's authentication flows |
| Yahoo | yahoo.py |
Probes Yahoo Mail registration endpoints |
| ProtonMail | protonmail.py |
Verifies ProtonMail account status through their API |
| Mail.ru | mail_ru.py |
Tests Russian Mail.ru email services |
| La Poste | laposte.py |
Checks French postal service email (laposte.net) |
These files reside in holehe/modules/mails/ and are automatically discovered when the mails category is invoked.
How to Use Holehe Mails Category
Command-Line Usage
Run Holehe with the --mail flag to test an email address against all mail service modules:
holehe -u example@example.com --mail
Sample output:
[+] Google : account found
[+] Yahoo : no account
[+] ProtonMail : account found
[+] Mail.ru : no account
[+] La Poste : account found
Omit --mail to run the full suite of Holehe modules across all categories.
Programmatic Usage
Import individual mail modules to check specific providers from Python code:
from holehe.core import Holehe
from holehe.modules.mails import google, yahoo, protonmail
holehe = Holehe()
email = "example@example.com"
# Check Google
google_result = holehe.check_module(google, email)
print("Google:", google_result)
# Check Yahoo
yahoo_result = holehe.check_module(yahoo, email)
print("Yahoo:", yahoo_result)
# Check ProtonMail
protonmail_result = holehe.check_module(protonmail, email)
print("ProtonMail:", protonmail_result)
Each check_module call returns a dictionary with keys such as exists (boolean), rateLimit (boolean), and other provider-specific metadata.
Key Implementation Files in holehe/modules/mails/
Understanding the source structure helps when extending or debugging the mails category:
__init__.py— Package initializer that registers all mail modules for dynamic discoverygoogle.py— Implementscheck()for Gmail using Google's signup validation endpointsyahoo.py— Yahoo Mail checker that exploits registration form feedbackprotonmail.py— ProtonMail verifier using their public user existence APImail_ru.py— Mail.ru checker for the Russian email ecosystemlaposte.py— La Poste (laposte.net) checker for French government-affiliated email
Each module follows Holehe's standard interface: an async check(email, client, out) function that appends results to the out list parameter.
Adding New Mails Checkers
The modular architecture makes it straightforward to extend the mails category. To add a new provider:
- Create a new Python file in
holehe/modules/mails/ - Define an async
checkfunction with the standard signature - Implement HTTP requests to the target's registration or recovery endpoints
- Parse responses to determine account existence
- Append a result dictionary to the output list
New modules are automatically picked up by Holehe's module loader without requiring changes to core code.
Summary
- Holehe's mails category contains dedicated checkers for Gmail, Yahoo, ProtonMail, Mail.ru, and La Poste
- Each service is implemented as a standalone Python module in
holehe/modules/mails/ - The
check()function in each module handles provider-specific HTTP probing - Use
--mailfrom the command line or import modules directly for programmatic access - All mail checkers follow a consistent async interface for easy extension
Frequently Asked Questions
How does Holehe verify email accounts without passwords?
Holehe exploits public registration and password-reset endpoints that return different responses depending on whether an email is registered. For example, Google's signup flow reveals account existence through error messages, while ProtonMail exposes a public API endpoint for user lookup. These techniques avoid any authentication requirements.
Can I run Holehe mails checkers on multiple emails at once?
The command-line tool processes one email per invocation. For batch operations, use the programmatic API: create a script that iterates over your email list and calls holehe.check_module() for each target. Be mindful of rate limiting—aggressive scanning may trigger blocks from providers.
What information does Holehe return besides account existence?
Each mails module returns a structured result including: exists (boolean account status), rateLimit (whether the provider throttled the request), emailrecovery (partial recovery email if leaked), phoneNumber (partial phone if exposed), and others (provider-specific metadata). Not all fields populate for every service.
Is using Holehe on someone else's email address legal?
Holehe is a legitimate security research tool when used appropriately. Always ensure you have authorization before investigating third-party accounts, and comply with local laws regarding data privacy and computer access. The tool is designed for self-assessment, authorized penetration testing, and OSINT investigations with proper legal basis.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →