# How to Filter Holehe Results to Show Only Websites Where an Email Exists

> Learn how to filter Holehe results to show only websites where an email exists. Use the --only-used flag to streamline your checks and get precise information.

- Repository: [Palenath/holehe](https://github.com/megadose/holehe)
- Tags: how-to-guide
- Published: 2026-09-01

---

**Use the `--only-used` flag when running Holehe to display only sites where the target email address is registered.**

Holehe is an open-source OSINT tool that checks whether an email address exists on hundreds of online services. By default, it outputs results for every site it tests—including sites where the email isn't found, rate-limited responses, and errors. This guide explains how to use the built-in filtering option to see only the websites where an email exists, streamlining your reconnaissance workflow.

## Understanding the --only-used Flag

The `--only-used` command-line argument modifies Holehe's output behavior at the source code level. In [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py), the argument parser defines this flag (lines 84–86), and the `print_result` function consumes it to control which entries get displayed (lines 122–135).

When enabled, the `onlyused` parameter passed to `print_result` causes the function to skip three branches:

- **"Not used" entries** — sites where the email isn't registered
- **"Rate‑limited" entries** — sites that blocked or throttled the check
- **"Error" entries** — sites where the check failed

Only entries with `exists=True` in their result dictionary are printed.

## Basic Command Syntax

Run Holehe with the `--only-used` flag following the target email:

```bash
holehe victim@example.com --only-used

```

Without the flag, Holehe produces verbose output showing every site's status. With the flag, the output collapses to confirmed hits:

```bash

# Full output (default)

holehe victim@example.com

# Filtered output (confirmed registrations only)

holehe victim@example.com --only-used

```

### Example Output Comparison

**Default output (truncated):**

```

[*] victim@example.com
[+] instagram.com
[-] facebook.com
[-] netflix.com (Rate limit)
[+] github.com
[-] spotify.com (Error)
[+] twitter.com

```

**With `--only-used`:**

```

[*] victim@example.com
[+] instagram.com
[+] github.com
[+] twitter.com

```

## Combining with CSV Export

For further analysis or reporting, pair `--only-used` with the `--csv` option. This generates a CSV file containing exclusively the confirmed registrations:

```bash
holehe victim@example.com --only-used --csv

```

The resulting CSV includes rows only for sites where the email was detected, eliminating manual filtering in spreadsheet software.

## Where the Filtering Logic Lives

The `--only-used` implementation spans two critical sections in [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py) according to the megadose/holehe source code:

| Location | Function | Purpose |
|----------|----------|---------|
| Lines 84–86 | Argument parser | Registers `--only-used` flag for CLI use |
| Lines 122–135 | `print_result()` | Applies the `onlyused` boolean to conditionally skip output branches |

Each site check module in `holehe/modules/` returns a standardized dictionary containing an `exists` key. The `print_result` function inspects this key when `onlyused=True` to determine whether to emit output.

## Practical Use Cases

- **Focused reconnaissance** — Skip noise and investigate only confirmed accounts
- **Large-scale scanning** — Process thousands of emails without storage overhead from negative results
- **Automated pipelines** — Pipe `--only-used` output directly into downstream tools without parsing intermediate formats

## Summary

- Holehe's `--only-used` flag filters output to confirmed email registrations only
- The filtering occurs in [`holehe/core.py`](https://github.com/megadose/holehe/blob/main/holehe/core.py) through the `print_result` function's conditional branches
- Combine with `--csv` for clean, machine-readable export of positive findings
- This option eliminates visual noise from rate limits, errors, and negative results

## Frequently Asked Questions

### What does Holehe check when I use --only-used?

Holehe still executes all site checks in `holehe/modules/`. The `--only-used` flag only affects **output display**—it doesn't skip the underlying HTTP requests. Every module runs, but only entries with `exists=True` reach your terminal.

### Can I use --only-used with multiple email addresses?

Yes. Holehe accepts multiple emails as positional arguments, and `--only-used` applies to all results:

```bash
holehe email1@example.com email2@example.com --only-used

```

### Does --only-used affect the JSON or CSV output format?

Yes. When combined with `--csv`, the CSV contains only confirmed registrations. When using `--json`, the flag similarly filters the returned array to objects where `exists` is `True`.

### Why do I still see some errors with --only-used?

The `--only-used` filter strictly checks the `exists` field in result dictionaries. In rare cases where a module sets `exists=True` despite encountering an error (such as ambiguous responses), that entry may still appear. Review `holehe/modules/` source if you suspect false positives.