How to Filter Holehe Results to Show Only Websites Where an Email Exists
Use the --only-used flag when running Holehe to display only sites where the target email address is registered.
Holehe is an open-source OSINT tool that checks whether an email address exists on hundreds of online services. By default, it outputs results for every site it tests—including sites where the email isn't found, rate-limited responses, and errors. This guide explains how to use the built-in filtering option to see only the websites where an email exists, streamlining your reconnaissance workflow.
Understanding the --only-used Flag
The --only-used command-line argument modifies Holehe's output behavior at the source code level. In holehe/core.py, the argument parser defines this flag (lines 84–86), and the print_result function consumes it to control which entries get displayed (lines 122–135).
When enabled, the onlyused parameter passed to print_result causes the function to skip three branches:
- "Not used" entries — sites where the email isn't registered
- "Rate‑limited" entries — sites that blocked or throttled the check
- "Error" entries — sites where the check failed
Only entries with exists=True in their result dictionary are printed.
Basic Command Syntax
Run Holehe with the --only-used flag following the target email:
holehe victim@example.com --only-used
Without the flag, Holehe produces verbose output showing every site's status. With the flag, the output collapses to confirmed hits:
# Full output (default)
holehe victim@example.com
# Filtered output (confirmed registrations only)
holehe victim@example.com --only-used
Example Output Comparison
Default output (truncated):
[*] victim@example.com
[+] instagram.com
[-] facebook.com
[-] netflix.com (Rate limit)
[+] github.com
[-] spotify.com (Error)
[+] twitter.com
With --only-used:
[*] victim@example.com
[+] instagram.com
[+] github.com
[+] twitter.com
Combining with CSV Export
For further analysis or reporting, pair --only-used with the --csv option. This generates a CSV file containing exclusively the confirmed registrations:
holehe victim@example.com --only-used --csv
The resulting CSV includes rows only for sites where the email was detected, eliminating manual filtering in spreadsheet software.
Where the Filtering Logic Lives
The --only-used implementation spans two critical sections in holehe/core.py according to the megadose/holehe source code:
| Location | Function | Purpose |
|---|---|---|
| Lines 84–86 | Argument parser | Registers --only-used flag for CLI use |
| Lines 122–135 | print_result() |
Applies the onlyused boolean to conditionally skip output branches |
Each site check module in holehe/modules/ returns a standardized dictionary containing an exists key. The print_result function inspects this key when onlyused=True to determine whether to emit output.
Practical Use Cases
- Focused reconnaissance — Skip noise and investigate only confirmed accounts
- Large-scale scanning — Process thousands of emails without storage overhead from negative results
- Automated pipelines — Pipe
--only-usedoutput directly into downstream tools without parsing intermediate formats
Summary
- Holehe's
--only-usedflag filters output to confirmed email registrations only - The filtering occurs in
holehe/core.pythrough theprint_resultfunction's conditional branches - Combine with
--csvfor clean, machine-readable export of positive findings - This option eliminates visual noise from rate limits, errors, and negative results
Frequently Asked Questions
What does Holehe check when I use --only-used?
Holehe still executes all site checks in holehe/modules/. The --only-used flag only affects output display—it doesn't skip the underlying HTTP requests. Every module runs, but only entries with exists=True reach your terminal.
Can I use --only-used with multiple email addresses?
Yes. Holehe accepts multiple emails as positional arguments, and --only-used applies to all results:
holehe email1@example.com email2@example.com --only-used
Does --only-used affect the JSON or CSV output format?
Yes. When combined with --csv, the CSV contains only confirmed registrations. When using --json, the flag similarly filters the returned array to objects where exists is True.
Why do I still see some errors with --only-used?
The --only-used filter strictly checks the exists field in result dictionaries. In rare cases where a module sets exists=True despite encountering an error (such as ambiguous responses), that entry may still appear. Review holehe/modules/ source if you suspect false positives.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →