What Is the holehe No Password Recovery Flag? Understanding the `-NP` Option
The -NP or --no-password-recovery flag tells holehe to skip all password-recovery endpoint checks during email enumeration, preventing unwanted password-reset emails while reducing scan time.
Holehe is an open-source OSINT tool that queries hundreds of websites to determine if a target email address is registered on those platforms. By default, the tool probes "forgot password" endpoints to verify account existence, which can trigger notification emails to the target address. The holehe no password recovery flag exists to suppress these specific checks when operators want to avoid side effects or need faster results.
How the holehe No Password Recovery Flag Works
The implementation spans the argument parsing logic and the core execution flow in the repository's main entry point.
Command Line Definition
In holehe/core.py, the flag is registered with the argument parser at lines 90-92. The help text explicitly describes its purpose:
-NP, --no-password-recovery Do not try password recovery on the websites
This definition creates both the short form (-NP) and long form (--no-password-recovery) options accessible via the command line.
Runtime Enforcement
Before any module executes a password-recovery request, the core logic inspects the flag value. In holehe/core.py at line 58, the code checks:
if args is not None and args.nopasswordrecovery == True:
# skip password‑recovery logic
When this condition evaluates to true, holehe bypasses the password-recovery routine entirely. Individual site modules located in holehe/modules/* respect this flag, ensuring that no HTTP requests are sent to password-reset endpoints for any service in the target list.
When to Use the -NP Flag
You should invoke the holehe no password recovery flag in the following scenarios:
- Operational Security (OPSEC) – Prevent the target email address from receiving "password reset requested" notifications that could alert the user to your investigation.
- Speed Optimization – Eliminate the latency associated with additional HTTP requests to recovery endpoints, significantly reducing total scan duration against large target lists.
- Stealth Evasion – Avoid triggering rate limits or anomaly detections specifically monitoring for abuse of password-recovery APIs.
Usage Examples
Run holehe with default behavior (includes password-recovery checks):
holehe user@example.com
Execute a scan while suppressing all password-recovery attempts:
holehe -NP user@example.com
Alternatively, use the long-form option:
holehe --no-password-recovery user@example.com
In the second and third commands, holehe queries the same list of services but omits any requests to "forgot password" endpoints, returning results based solely on registration page analysis and other non-recovery indicators.
Summary
- The
-NPand--no-password-recoveryflags are defined inholehe/core.py(lines 90-92) as mutually exclusive options that setargs.nopasswordrecoverytoTrue. - When enabled, the flag forces holehe to skip password-recovery logic checked at
holehe/core.pyline 58, preventing modules from hitting reset endpoints. - Default behavior (flag omitted) allows password-recovery checks, which verify account existence but may send notification emails to the target address.
- Using the flag improves scan speed and operational security at the potential cost of reduced accuracy for services where recovery endpoints are the only verification vector.
Frequently Asked Questions
What does the -NP flag do in holehe?
The -NP flag (short for --no-password-recovery) instructs holehe to skip all "forgot password" endpoint queries during its enumeration phase. According to the source code in holehe/core.py, this prevents the tool from sending requests that could trigger password-reset emails to the target address while still checking other registration indicators.
Will using --no-password-recovery make holehe faster?
Yes. Password-recovery checks require additional HTTP requests to separate endpoints for each website in the target list. By setting -NP, you eliminate these round-trips, reducing total execution time, especially when scanning against the full module set included in holehe/modules/.
Can website owners still detect the scan if I use -NP?
Yes. While the flag prevents password-recovery requests, holehe still performs other verification methods such as checking registration pages or API endpoints for account existence indicators. These remaining requests are logged by target servers and may still be detected through standard traffic analysis or rate-limiting mechanisms.
Is the no password recovery flag enabled by default?
No. By default, args.nopasswordrecovery evaluates to False, meaning holehe attempts password-recovery checks unless you explicitly pass -NP or --no-password-recovery on the command line. This default is implemented in the argument parser definition found at lines 90-92 of holehe/core.py.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →