Holehe
OSINT tool that checks which sites have an email registered via password-reset flows.
Technical Architecture & Overview
Holehe tests an email address against more than 120 websites using the password reset function: a reset response that confirms registration reveals account existence without login attempts or notifications to the target. Output lists registered and unregistered sites, and the technique avoids the lockouts that failed logins cause. It is a standard email pivot in investigator toolkits.
Targeted Technical Use Cases
Mapping account footprint for an email address during authorized investigations.
Evaluation & Trade-offs
Core Strengths
- +Quiet by design; no failed-login noise.
- +Covers major platforms including social and commerce sites.
- +Simple CLI with JSON output.
Trade-Offs & Limitations
- -Depends on each site’s reset flow, which changes over time.
- -Speed is bounded by per-site request handling.
Defensive Security Application
Fraud and account takeover investigations that need to map a compromised email’s reach.
Frequently Asked Questions
What is Holehe?→
Holehe tests an email address against more than 120 websites using the password reset function: a reset response that confirms registration reveals account existence without login attempts or notifications to the target. Output lists registered and unregistered sites, and the technique avoids the lockouts that failed logins cause. It is a standard email pivot in investigator toolkits.
What is Holehe used for?→
Mapping account footprint for an email address during authorized investigations.
What are the strengths of Holehe?→
- +Quiet by design; no failed-login noise.
- +Covers major platforms including social and commerce sites.
- +Simple CLI with JSON output.
What are the limitations of Holehe?→
- +Depends on each site’s reset flow, which changes over time.
- +Speed is bounded by per-site request handling.
How is Holehe used defensively?→
Fraud and account takeover investigations that need to map a compromised email’s reach.