# What Is the holehe No Password Recovery Flag? Understanding the `-NP` Option

> Learn how the holehe -NP no password recovery flag speeds up email enumeration by skipping password reset checks. Avoid unwanted emails and reduce scan time.

- Repository: [Palenath/holehe](https://github.com/megadose/holehe)
- Tags: deep-dive
- Published: 2026-09-09

---

**The `-NP` or `--no-password-recovery` flag tells holehe to skip all password-recovery endpoint checks during email enumeration, preventing unwanted password-reset emails while reducing scan time.**

Holehe is an open-source OSINT tool that queries hundreds of websites to determine if a target email address is registered on those platforms. By default, the tool probes "forgot password" endpoints to verify account existence, which can trigger notification emails to the target address. The holehe no password recovery flag exists to suppress these specific checks when operators want to avoid side effects or need faster results.

## How the holehe No Password Recovery Flag Works

The implementation spans the argument parsing logic and the core execution flow in the repository's main entry point.

### Command Line Definition

In [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py), the flag is registered with the argument parser at lines 90-92. The help text explicitly describes its purpose:

```text
-NP, --no-password-recovery   Do not try password recovery on the websites

```

This definition creates both the short form (`-NP`) and long form (`--no-password-recovery`) options accessible via the command line.

### Runtime Enforcement

Before any module executes a password-recovery request, the core logic inspects the flag value. In [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py) at line 58, the code checks:

```python
if args is not None and args.nopasswordrecovery == True:
    # skip password‑recovery logic

```

When this condition evaluates to true, holehe bypasses the password-recovery routine entirely. Individual site modules located in `holehe/modules/*` respect this flag, ensuring that no HTTP requests are sent to password-reset endpoints for any service in the target list.

## When to Use the `-NP` Flag

You should invoke the holehe no password recovery flag in the following scenarios:

- **Operational Security (OPSEC)** – Prevent the target email address from receiving "password reset requested" notifications that could alert the user to your investigation.
- **Speed Optimization** – Eliminate the latency associated with additional HTTP requests to recovery endpoints, significantly reducing total scan duration against large target lists.
- **Stealth Evasion** – Avoid triggering rate limits or anomaly detections specifically monitoring for abuse of password-recovery APIs.

## Usage Examples

Run holehe with default behavior (includes password-recovery checks):

```bash
holehe user@example.com

```

Execute a scan while suppressing all password-recovery attempts:

```bash
holehe -NP user@example.com

```

Alternatively, use the long-form option:

```bash
holehe --no-password-recovery user@example.com

```

In the second and third commands, holehe queries the same list of services but omits any requests to "forgot password" endpoints, returning results based solely on registration page analysis and other non-recovery indicators.

## Summary

- The `-NP` and `--no-password-recovery` flags are defined in [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py) (lines 90-92) as mutually exclusive options that set `args.nopasswordrecovery` to `True`.
- When enabled, the flag forces holehe to skip password-recovery logic checked at [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py) line 58, preventing modules from hitting reset endpoints.
- Default behavior (flag omitted) allows password-recovery checks, which verify account existence but may send notification emails to the target address.
- Using the flag improves scan speed and operational security at the potential cost of reduced accuracy for services where recovery endpoints are the only verification vector.

## Frequently Asked Questions

### What does the `-NP` flag do in holehe?

The `-NP` flag (short for `--no-password-recovery`) instructs holehe to skip all "forgot password" endpoint queries during its enumeration phase. According to the source code in [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py), this prevents the tool from sending requests that could trigger password-reset emails to the target address while still checking other registration indicators.

### Will using `--no-password-recovery` make holehe faster?

Yes. Password-recovery checks require additional HTTP requests to separate endpoints for each website in the target list. By setting `-NP`, you eliminate these round-trips, reducing total execution time, especially when scanning against the full module set included in `holehe/modules/`.

### Can website owners still detect the scan if I use `-NP`?

Yes. While the flag prevents password-recovery requests, holehe still performs other verification methods such as checking registration pages or API endpoints for account existence indicators. These remaining requests are logged by target servers and may still be detected through standard traffic analysis or rate-limiting mechanisms.

### Is the no password recovery flag enabled by default?

No. By default, `args.nopasswordrecovery` evaluates to `False`, meaning holehe attempts password-recovery checks unless you explicitly pass `-NP` or `--no-password-recovery` on the command line. This default is implemented in the argument parser definition found at lines 90-92 of [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py).