What Is Holehe?

Holehe is an open-source email OSINT tool that takes a single email address and tells you which of 200+ online services it is registered on. It is one of the most cited utilities in the OSINT community for mapping the digital footprint behind an email.

The short definition

Holehe is an email-registration checker. Given an address such as [email protected], it queries the public sign-up and password-recovery endpoints of more than 200 sites, social networks, developer platforms, e-commerce stores, gaming services, music apps and more, and reports, for each one, whether an account exists for that email.

The tool was originally released as an open source Python command-line utility. This site is the browser-based version: same coverage, no install, runs from any device.

How Holehe works under the hood

Holehe never logs in, never guesses passwords and never scrapes private content. For each supported site, it uses the site's own publicly exposed signal, typically the response returned by the sign-up form or the "forgot my password" flow, to deduce whether an account is registered.

  • Sends a single, low-noise request per site
  • Reads the response to classify the address as Found, Not Found or Rate-limited
  • Aggregates everything into one consolidated report
  • Tags each hit by category: social, dev, shopping, gaming, music…

What you can learn from a Holehe report

A Holehe scan turns a bare email address into an account footprint. You discover, in under a minute:

  • Which platforms the person actively uses (LinkedIn, Twitter, Spotify, Steam…)
  • Whether the address is tied to developer ecosystems (GitHub, GitLab, npm)
  • Hints about purchasing behaviour through e-commerce registrations
  • Pivots toward further OSINT: usernames, avatars and profile URLs to follow up on

Who uses Holehe?

Holehe is built for authorized OSINT work. The typical users are:

  • Pentesters and red-teamers scoping a target's external attack surface
  • Threat-intelligence analysts profiling compromised mailboxes
  • Journalists and fact-checkers verifying the existence of a source or subject
  • Fraud and trust-and-safety teams triaging suspicious sign-ups
  • Academic researchers studying online identity

Holehe vs other email OSINT tools

Holehe focuses on one question, "is this email registered here?", and answers it across 200+ sites. It is complementary to:

  • HaveIBeenPwned, tells you if the address appeared in a data breach
  • EmailRep / Hunter, score and corporate context
  • Sherlock / Maigret, same idea, but pivoting on usernames
  • GHunt, deep dive on a single Google account

Holehe is usually the first step: it tells you where to look next.

Try Holehe in your browser

You don't need Python, pip or a terminal. Paste an email into the console on the home page and the report is generated in seconds.

Run a Holehe scan now →

Frequently asked questions about Holehe

Is Holehe safe to use?
Yes. Holehe only reads public sign-up and password-recovery responses from each site. It never logs in, never guesses passwords, never scrapes private content, and never notifies the email owner. Use it on addresses you are authorised to investigate.
How do I install Holehe?
You do not need to install anything to use Holehe online, open holehe-osint.com in any browser and paste an email. To install the original Python CLI, run "pip install holehe" inside a virtualenv on Python 3.10 or 3.11.
How do I use Holehe?
On holehe-osint.com, paste an email into the console on the home page and click Search. Results stream in as each of the 200+ modules reports whether the address is registered on that site.
How do I run Holehe from the command line?
After "pip install holehe", run "holehe [email protected]" in your terminal. Holehe will scan all supported sites and print a Found / Not Found verdict for each.
How do I download Holehe?
The browser version requires no download, just open holehe-osint.com. The Python CLI is on PyPI ("pip install holehe") and the source code is open source on GitHub.
Is Holehe legal?
Holehe only reads public sign-up signals, which is generally lawful. Lawfulness depends on your jurisdiction and the purpose of the investigation. Use it for authorised pentesting, threat intelligence, journalism, fraud triage, or your own accounts.