How Holehe Formats Terminal Output: Color-Coded Status and Metadata Display
Holehe formats terminal results through the print_result function in holehe/core.py, applying color-coded prefixes like [+], [-], [x], and [!] to indicate account status, rate limits, and errors while optionally appending recovery metadata for found accounts.
Holehe is an open-source email OSINT (Open Source Intelligence) tool maintained by megadose that checks if an email address is registered across hundreds of websites. Understanding how Holehe formats terminal output helps security researchers parse results efficiently and integrate the tool into automated reporting pipelines. The formatting logic lives in the print_result function within holehe/core.py, which processes asynchronous module results into a human-readable, color-coded table.
The Core Formatting Pipeline in holehe/core.py
The print_result function (starting at line 106 in holehe/core.py) executes a deterministic six-step pipeline to transform raw module data into structured terminal output.
ANSI Color Management with print_color
Before printing any text, Holehe determines whether to apply ANSI color codes through the print_color helper (lines 107-111). This function checks the --no-color command-line flag; if disabled, it wraps strings with colored ANSI codes, otherwise returns raw text for piping into other tools or logging to files.
Status Legend Construction
At line 113, Holehe constructs a concise legend explaining the four mutually exclusive status prefixes:
[+](Green): Email is registered on the site[-](Magenta): Email is not registered[x](Yellow): Rate limit encountered[!](Red): Error during checking
Terminal Screen Handling
If the user omits the --no-clear flag, the terminal screen is cleared (lines 114-118) to provide a clean canvas for results. The target email address is then framed with asterisk banners (lines 118-120) for immediate visual identification, creating a header like:
***************************
example@mail.com
***************************
Processing Asynchronous Module Results
The function iterates over the data list containing dictionaries from async modules (lines 122-147), evaluating four distinct states in order of priority to determine the final output line.
Rate Limit Detection
When results["rateLimit"] evaluates to true, Holehe prints "[x] <domain>" in yellow, indicating the site temporarily blocked the query and the result is inconclusive.
Error State Reporting
If results["error"] is true, the output shows "[!] <domain> <error-message>" in red, extracting the specific failure description from results["others"]["errorMessage"]. This captures exceptions like Cloudflare challenges or connection timeouts.
Account Existence Validation
For successful responses without errors or rate limits, Holehe checks the boolean results["exists"]:
- False: Prints
"[-] <domain>"in magenta, indicating the email is available or unregistered - True: Prints
"[+] <domain>"in green and proceeds to append metadata
Metadata Enrichment for Found Accounts
When an account exists (lines 136-144), Holehe appends additional intelligence to the green [+] line, joined by " / " separators:
- Recovery email: Extracted from
results["emailrecovery"] - Phone number: Extracted from
results["phoneNumber"] - Full name: Extracted from
results["others"]["FullName"] - Creation date: Extracted from
results["others"]["Date, time of the creation"]
Each line is passed through print_color before final output.
Terminal Output Example
Running Holehe against an email address produces output following this exact structure:
# Simplified illustration of the formatting logic
def format_result(results, args):
if results["rateLimit"]:
return f"[x] {results['domain']}"
if results.get("error"):
msg = results["others"].get("errorMessage", "")
return f"[!] {results['domain']} {msg}"
if not results["exists"]:
return f"[-] {results['domain']}"
# Account found
extra = []
if results["emailrecovery"]:
extra.append(results["emailrecovery"])
if results["phoneNumber"]:
extra.append(results["phoneNumber"])
if results["others"] and "FullName" in results["others"]:
extra.append(f"FullName {results['others']['FullName']}")
if results["others"] and "Date, time of the creation" in results["others"]:
extra.append(f"Date, time of the creation {results['others']['Date, time of the creation']}")
return f"[+] {results['domain']} {' / '.join(extra)}"
A typical execution yields:
***************************
example@mail.com
***************************
[+] github.com / FullName John Doe / Date, time of the creation 2020-01-01
[-] twitter.com
[x] instagram.com
[!] reddit.com Error message: Cloudflare challenge failed
...
[+] Email used, [-] Email not used, [x] Rate limit, [!] Error
30 websites checked in 12.34 seconds
Summary
- The
print_resultfunction inholehe/core.py(line 106) serves as the central formatter for all terminal output in Holehe - Output uses four color-coded prefixes:
[+]green for found accounts,[-]magenta for unused emails,[x]yellow for rate limits, and[!]red for errors - The
--no-colorflag disables ANSI codes via theprint_colorhelper, while--no-clearprevents screen clearing - Found accounts display enriched metadata including recovery emails, phone numbers, full names, and creation dates when available
- Each result line is constructed by evaluating
rateLimit,error, andexistskeys in module result dictionaries
Frequently Asked Questions
How do I disable colors in Holehe terminal output?
Pass the --no-color flag when running Holehe. This instructs the print_color function (lines 107-111 in holehe/core.py) to return raw strings without ANSI escape codes, producing plain text suitable for logging or piping to other tools.
What does the [x] prefix mean in Holehe results?
The [x] prefix indicates a rate limit has been hit on the target website. Displayed in yellow, this status means the site temporarily blocked the query (likely due to too many requests), and the result for that domain is inconclusive rather than a confirmed negative.
Where is the terminal formatting logic located in the Holehe repository?
All terminal formatting logic resides in holehe/core.py, specifically within the print_result function starting at line 106. This includes the color helper print_color, legend construction, screen clearing logic, and the result iteration pipeline that processes data from the async modules in holehe/modules/.
Can I parse Holehe output programmatically?
Yes, by using the --no-color flag to strip ANSI codes and splitting lines on the status prefixes ([+], [-], [x], [!]). However, for robust automation, you should modify the print_result function to output JSON or consume the data list directly before it reaches the formatting stage, as the current text output is optimized for human readability rather than machine parsing.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →