# How to Disable Password Recovery Modules in Holehe: CLI and Programmatic Guide

> Learn how to disable password recovery modules in Holehe using the CLI or programmatically. Exclude specific modules with the no password recovery flag for enhanced security.

- Repository: [Palenath/holehe](https://github.com/megadose/holehe)
- Tags: how-to-guide
- Published: 2026-09-09

---

**Use the `-NP` or `--no-password-recovery` command-line flag to exclude Adobe, mail.ru, Odnoklassniki, and Samsung modules that trigger password recovery endpoints.**

Holehe is an open-source OSINT tool maintained by megadose that checks if an email address is registered across hundreds of websites. While the tool includes password recovery checks for several major platforms, you can disable password recovery modules in Holehe using a specific runtime argument that filters these checks at the module loading stage.

## Understanding Password Recovery Modules

By default, Holehe probes services using password recovery endpoints to verify email existence on specific high-value targets. The modules that implement this logic reside in distinct paths within the codebase:

- [`holehe/modules/software/adobe.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/software/adobe.py)
- [`holehe/modules/mails/mail_ru.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/mails/mail_ru.py)
- [`holehe/modules/social_media/odnoklassniki.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/social_media/odnoklassniki.py)
- [`holehe/modules/products/samsung.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/products/samsung.py)

These modules attempt to access password reset functionality rather than standard registration checks, which may trigger security notifications on the target accounts.

## Using the --no-password-recovery Flag

The simplest way to skip these specific checks is via the command line interface.

Run Holehe with the short flag:

```bash
holehe -NP user@example.com

```

Or use the long form for readability:

```bash
holehe --no-password-recovery user@example.com

```

When this flag is active, Holehe omits the four password recovery modules from the scan list while continuing to check all other supported platforms.

## Source Code Implementation in holehe/core.py

According to the megadose/holehe source code, the filtering logic is implemented in [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py). The CLI argument is defined at lines 90-92 using `argparse`:

```python
parser.add_argument("-NP","--no-password-recovery", default=False,
                    required=False,action="store_true",
                    dest="nopasswordrecovery",
                    help="Do not try password recovery on the websites")

```

The conditional filtering occurs within the `get_functions` logic (around lines 58-62), where the code checks the `nopasswordrecovery` attribute to exclude specific modules by name:

```python
if args is not None and args.nopasswordrecovery == True:
    if "adobe" not in str(modu.__dict__[site]) and
       "mail_ru" not in str(modu.__dict__[site]) and
       "odnoklassniki" not in str(modu.__dict__[site]) and
       "samsung" not in str(modu.__dict__[site]):
        websites.append(modu.__dict__[site])
else:
    websites.append(modu.__dict__[site])

```

This string-based validation inspects the module's dictionary representation to exclude the four specific services when the flag is enabled.

## Programmatic Usage in Python

If you are importing Holehe as a library rather than using the CLI, you can simulate the `-NP` flag by manipulating `sys.argv` before invoking `main()`:

```python
import sys
sys.argv = ["holehe", "-NP", "user@example.com"]
from holehe.core import main
main()

```

To inspect exactly which modules are loaded when the flag is active:

```python
from holehe.core import import_submodules, get_functions, ArgumentParser

parser = ArgumentParser()
parser.add_argument("-NP","--no-password-recovery", action="store_true")
args = parser.parse_args(["-NP"])

modules = import_submodules("holehe.modules")
sites = get_functions(modules, args)
print([s.__name__ for s in sites])  # Excludes adobe, mail_ru, odnoklassniki, samsung

```

## Summary

- **Disable password recovery modules** in Holehe using the `-NP` or `--no-password-recovery` flag.
- The flag specifically excludes **Adobe, mail.ru, Odnoklassniki, and Samsung** from the scan list.
- Filtering logic resides in [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py), where the `nopasswordrecovery` argument triggers string-based module exclusion in `get_functions`.
- You can use this feature both via command line and programmatically when importing `holehe.core`.

## Frequently Asked Questions

### Which specific sites are excluded when using the -NP flag?

The `-NP` flag excludes four specific modules: Adobe ([`holehe/modules/software/adobe.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/software/adobe.py)), mail.ru ([`holehe/modules/mails/mail_ru.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/mails/mail_ru.py)), Odnoklassniki ([`holehe/modules/social_media/odnoklassniki.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/social_media/odnoklassniki.py)), and Samsung ([`holehe/modules/products/samsung.py`](https://github.com/megadose/holehe/blob/main/holehe/modules/products/samsung.py)). These are hardcoded string matches in the filtering logic.

### Can I disable password recovery for only one specific site while keeping others?

No, the current implementation in [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py) uses a hardcoded exclusion list that filters all four password recovery modules simultaneously when `args.nopasswordrecovery` is True. You cannot selectively disable individual sites through the existing CLI interface without modifying the source code.

### Does skipping password recovery improve scan speed or reduce detection risk?

While the primary purpose is to avoid triggering password reset emails on target accounts, skipping these four modules does marginally reduce the total number of HTTP requests, slightly improving scan duration and reducing network noise during the reconnaissance phase.

### Is the --no-password-recovery flag available in all Holehe versions?

This feature requires a version of Holehe that includes the argument parser definition in [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py) at lines 90-92. If your installation lacks the `-NP` option, upgrade to the latest version from the megadose/holehe repository to access this functionality.