# How to Disable Password Recovery Modules in Holehe Scans

> Learn how to disable password recovery modules in Holehe scans using the -NP flag. Perform only email existence checks for enhanced security and control over your scans.

- Repository: [Palenath/holehe](https://github.com/megadose/holehe)
- Tags: how-to-guide
- Published: 2026-09-10

---

**Use the `-NP` or `--no-password-recovery` flag when running Holehe to skip all password-recovery verification modules and perform only standard email-existence checks.**

Holehe, the open-source email OSINT tool developed by megadose/holehe, includes specialized modules that verify account existence through password-recovery endpoints for services like Adobe, Mail.ru, and Odnoklassniki. While these checks can validate account ownership, they may trigger security alerts or rate limits. You can selectively disable these specific modules without affecting standard registration checks using a dedicated command-line option.

## Understanding the Password Recovery Flag

The Holehe command-line interface implements a boolean flag that controls whether password-recovery modules are included in the scan scope. According to the source code in [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py) lines 90-92, the argument parser defines `-NP/--no-password-recovery` which sets `args.nopasswordrecovery` to **True** when present.

During module initialization, the `get_functions()` routine (lines 58-61 in [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py)) inspects this flag. When `nopasswordrecovery` is enabled, the function automatically excludes the four modules that rely on password-reset verification flows: **Adobe**, **Mail.ru**, **Odnoklassniki**, and **Samsung**. This filtering occurs before any network requests are dispatched, ensuring these specific endpoints are never contacted.

## Command-Line Usage Examples

### Default Scan (Password Recovery Enabled)

By default, Holehe runs the full suite of modules including password-recovery checks:

```bash
holehe example@example.com

```

This command executes all applicable modules, including those that interact with password-reset APIs to confirm account ownership.

### Disabling Password Recovery

To exclude password-recovery modules and limit the scan to standard registration-based existence checks, append the flag:

```bash
holehe -NP example@example.com

```

Or use the explicit long-form syntax:

```bash
holehe --no-password-recovery example@example.com

```

When either variant is supplied, Holehe skips the modules defined in [`holehe/modules/software/adobe.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/software/adobe.py), [`holehe/modules/mails/mail_ru.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/mails/mail_ru.py), [`holehe/modules/social_media/odnoklassniki.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/social_media/odnoklassniki.py), and the Samsung module, significantly reducing the scan footprint and avoiding password-reset-specific rate limits.

### Programmatic Usage

If integrating Holehe into automation pipelines or Python scripts, pass the flag via subprocess:

```python
import subprocess

email = "target@example.com"
subprocess.run(["holehe", "-NP", email])

```

This approach preserves the filtering behavior while embedding the tool into larger workflows.

## How the Filtering Works in Source Code

The exclusion logic resides in [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py) within the module discovery phase. When `get_functions()` enumerates available check modules, it evaluates the `nopasswordrecovery` attribute from the parsed arguments (line 58):

- **If `True`**: The function omits modules identified as password-recovery implementations, specifically filtering out `adobe`, `mail_ru`, `odnoklassniki`, and `samsung` from the execution list.
- **If `False` or undefined**: All modules load normally, including those that query password-reset endpoints.

This implementation ensures that modules like [`sevencups.py`](https://github.com/megadose/holehe/blob/main/sevencups.py) (medical category) or other standard registration checks continue to run regardless of the flag's state, maintaining comprehensive OSINT coverage while allowing surgical removal of high-risk password-recovery probes.

## Summary

- **Use `-NP` or `--no-password-recovery`** to disable password-recovery modules in Holehe scans.
- **Four modules are excluded**: Adobe, Mail.ru, Odnoklassniki, and Samsung when the flag is active.
- **Source implementation**: The `args.nopasswordrecovery` boolean is checked in [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py) (lines 58-61 and 90-92) to filter the module list before execution.
- **Standard checks remain unaffected**: Email existence verification through registration pages continues normally for all other supported services.

## Frequently Asked Questions

### What is the short form of the disable flag?

The short form is `-NP` (capital N, capital P). The equivalent long form is `--no-password-recovery`. Both perform identical filtering of password-recovery modules as implemented in [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py).

### Which specific modules are excluded when using -NP?

Holehe excludes four password-recovery specific modules: `adobe` ([`holehe/modules/software/adobe.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/software/adobe.py)), `mail_ru` ([`holehe/modules/mails/mail_ru.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/mails/mail_ru.py)), `odnoklassniki` ([`holehe/modules/social_media/odnoklassniki.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/social_media/odnoklassniki.py)), and `samsung`. These are the only modules that rely on password-reset endpoint verification rather than standard registration checks.

### Does disabling password recovery affect email existence detection?

No. Disabling password recovery only removes the specific modules that interact with password-reset APIs. All standard modules that check email existence through registration forms, login pages, or API registrations continue to function normally, including modules for social media, programming platforms, and financial services.

### Why would I want to disable password recovery checks?

Password-recovery endpoints often implement strict rate limiting, CAPTCHA challenges, or security monitoring that may flag automated queries. Disabling these checks reduces the likelihood of IP blocking or account restrictions while still allowing comprehensive email OSINT through less sensitive registration verification methods.