How to Disable Password Recovery Modules in Holehe Scans

Use the -NP or --no-password-recovery flag when running Holehe to skip all password-recovery verification modules and perform only standard email-existence checks.

Holehe, the open-source email OSINT tool developed by megadose/holehe, includes specialized modules that verify account existence through password-recovery endpoints for services like Adobe, Mail.ru, and Odnoklassniki. While these checks can validate account ownership, they may trigger security alerts or rate limits. You can selectively disable these specific modules without affecting standard registration checks using a dedicated command-line option.

Understanding the Password Recovery Flag

The Holehe command-line interface implements a boolean flag that controls whether password-recovery modules are included in the scan scope. According to the source code in holehe/core.py lines 90-92, the argument parser defines -NP/--no-password-recovery which sets args.nopasswordrecovery to True when present.

During module initialization, the get_functions() routine (lines 58-61 in holehe/core.py) inspects this flag. When nopasswordrecovery is enabled, the function automatically excludes the four modules that rely on password-reset verification flows: Adobe, Mail.ru, Odnoklassniki, and Samsung. This filtering occurs before any network requests are dispatched, ensuring these specific endpoints are never contacted.

Command-Line Usage Examples

Default Scan (Password Recovery Enabled)

By default, Holehe runs the full suite of modules including password-recovery checks:

holehe example@example.com

This command executes all applicable modules, including those that interact with password-reset APIs to confirm account ownership.

Disabling Password Recovery

To exclude password-recovery modules and limit the scan to standard registration-based existence checks, append the flag:

holehe -NP example@example.com

Or use the explicit long-form syntax:

holehe --no-password-recovery example@example.com

When either variant is supplied, Holehe skips the modules defined in holehe/modules/software/adobe.py, holehe/modules/mails/mail_ru.py, holehe/modules/social_media/odnoklassniki.py, and the Samsung module, significantly reducing the scan footprint and avoiding password-reset-specific rate limits.

Programmatic Usage

If integrating Holehe into automation pipelines or Python scripts, pass the flag via subprocess:

import subprocess

email = "target@example.com"
subprocess.run(["holehe", "-NP", email])

This approach preserves the filtering behavior while embedding the tool into larger workflows.

How the Filtering Works in Source Code

The exclusion logic resides in holehe/core.py within the module discovery phase. When get_functions() enumerates available check modules, it evaluates the nopasswordrecovery attribute from the parsed arguments (line 58):

  • If True: The function omits modules identified as password-recovery implementations, specifically filtering out adobe, mail_ru, odnoklassniki, and samsung from the execution list.
  • If False or undefined: All modules load normally, including those that query password-reset endpoints.

This implementation ensures that modules like sevencups.py (medical category) or other standard registration checks continue to run regardless of the flag's state, maintaining comprehensive OSINT coverage while allowing surgical removal of high-risk password-recovery probes.

Summary

  • Use -NP or --no-password-recovery to disable password-recovery modules in Holehe scans.
  • Four modules are excluded: Adobe, Mail.ru, Odnoklassniki, and Samsung when the flag is active.
  • Source implementation: The args.nopasswordrecovery boolean is checked in holehe/core.py (lines 58-61 and 90-92) to filter the module list before execution.
  • Standard checks remain unaffected: Email existence verification through registration pages continues normally for all other supported services.

Frequently Asked Questions

What is the short form of the disable flag?

The short form is -NP (capital N, capital P). The equivalent long form is --no-password-recovery. Both perform identical filtering of password-recovery modules as implemented in holehe/core.py.

Which specific modules are excluded when using -NP?

Holehe excludes four password-recovery specific modules: adobe (holehe/modules/software/adobe.py), mail_ru (holehe/modules/mails/mail_ru.py), odnoklassniki (holehe/modules/social_media/odnoklassniki.py), and samsung. These are the only modules that rely on password-reset endpoint verification rather than standard registration checks.

Does disabling password recovery affect email existence detection?

No. Disabling password recovery only removes the specific modules that interact with password-reset APIs. All standard modules that check email existence through registration forms, login pages, or API registrations continue to function normally, including modules for social media, programming platforms, and financial services.

Why would I want to disable password recovery checks?

Password-recovery endpoints often implement strict rate limiting, CAPTCHA challenges, or security monitoring that may flag automated queries. Disabling these checks reduces the likelihood of IP blocking or account restrictions while still allowing comprehensive email OSINT through less sensitive registration verification methods.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →