How to Filter Holehe Results to Show Only Websites Where an Email Exists

Use the --only-used flag when running Holehe to display only sites where the target email address is registered.

Holehe is an open-source OSINT tool that checks whether an email address exists on hundreds of online services. By default, it outputs results for every site it tests—including sites where the email isn't found, rate-limited responses, and errors. This guide explains how to use the built-in filtering option to see only the websites where an email exists, streamlining your reconnaissance workflow.

Understanding the --only-used Flag

The --only-used command-line argument modifies Holehe's output behavior at the source code level. In holehe/core.py, the argument parser defines this flag (lines 84–86), and the print_result function consumes it to control which entries get displayed (lines 122–135).

When enabled, the onlyused parameter passed to print_result causes the function to skip three branches:

  • "Not used" entries — sites where the email isn't registered
  • "Rate‑limited" entries — sites that blocked or throttled the check
  • "Error" entries — sites where the check failed

Only entries with exists=True in their result dictionary are printed.

Basic Command Syntax

Run Holehe with the --only-used flag following the target email:

holehe victim@example.com --only-used

Without the flag, Holehe produces verbose output showing every site's status. With the flag, the output collapses to confirmed hits:


# Full output (default)

holehe victim@example.com

# Filtered output (confirmed registrations only)

holehe victim@example.com --only-used

Example Output Comparison

Default output (truncated):


[*] victim@example.com
[+] instagram.com
[-] facebook.com
[-] netflix.com (Rate limit)
[+] github.com
[-] spotify.com (Error)
[+] twitter.com

With --only-used:


[*] victim@example.com
[+] instagram.com
[+] github.com
[+] twitter.com

Combining with CSV Export

For further analysis or reporting, pair --only-used with the --csv option. This generates a CSV file containing exclusively the confirmed registrations:

holehe victim@example.com --only-used --csv

The resulting CSV includes rows only for sites where the email was detected, eliminating manual filtering in spreadsheet software.

Where the Filtering Logic Lives

The --only-used implementation spans two critical sections in holehe/core.py according to the megadose/holehe source code:

Location Function Purpose
Lines 84–86 Argument parser Registers --only-used flag for CLI use
Lines 122–135 print_result() Applies the onlyused boolean to conditionally skip output branches

Each site check module in holehe/modules/ returns a standardized dictionary containing an exists key. The print_result function inspects this key when onlyused=True to determine whether to emit output.

Practical Use Cases

  • Focused reconnaissance — Skip noise and investigate only confirmed accounts
  • Large-scale scanning — Process thousands of emails without storage overhead from negative results
  • Automated pipelines — Pipe --only-used output directly into downstream tools without parsing intermediate formats

Summary

  • Holehe's --only-used flag filters output to confirmed email registrations only
  • The filtering occurs in holehe/core.py through the print_result function's conditional branches
  • Combine with --csv for clean, machine-readable export of positive findings
  • This option eliminates visual noise from rate limits, errors, and negative results

Frequently Asked Questions

What does Holehe check when I use --only-used?

Holehe still executes all site checks in holehe/modules/. The --only-used flag only affects output display—it doesn't skip the underlying HTTP requests. Every module runs, but only entries with exists=True reach your terminal.

Can I use --only-used with multiple email addresses?

Yes. Holehe accepts multiple emails as positional arguments, and --only-used applies to all results:

holehe email1@example.com email2@example.com --only-used

Does --only-used affect the JSON or CSV output format?

Yes. When combined with --csv, the CSV contains only confirmed registrations. When using --json, the flag similarly filters the returned array to objects where exists is True.

Why do I still see some errors with --only-used?

The --only-used filter strictly checks the exists field in result dictionaries. In rare cases where a module sets exists=True despite encountering an error (such as ambiguous responses), that entry may still appear. Review holehe/modules/ source if you suspect false positives.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →