Holehe OSINT Review: The Open-Source Email Account Checker

Holehe OSINT is a free, open-source Python tool that checks whether an email address is registered on more than 120 websites, from Twitter and Instagram to smaller services. This review covers how it works, what a hit does and does not prove, how current the code is, and the terms and privacy questions it raises.

  • Free, GPL-3.0 license
  • Python command line and library
  • 120+ site modules
  • Last PyPI release July 2022

Based on the GitHub repository and PyPI release history, checked 10 October 2026. OSINT-S has no affiliation with the project.

Short answer

Holehe is a free GPL-3.0 Python tool that tests an email address against more than 120 sites, mostly through their sign-up, login or password-recovery responses, and reports where an account seems to exist. It suits technical investigators and security teams who can run code. There is no paid plan; the cost is your time, your IP reputation and the work of verifying results.

What Holehe OSINT Does

Holehe answers one question per site: does an account registered with this email appear to exist here? It does not log in or read account content.

The repository describes Holehe as a tool that "checks if an email is attached to an account on sites like twitter, instagram, imgur and more than 120 others" and that "retrieves information using the forgotten password function" (Holehe on GitHub). The project is maintained under the megadose account, released under GPL-3.0, written in Python and published on PyPI.

For an investigator, the output is a list of services where the address is in use. That is useful for building a picture of someone's online footprint, for spotting a burner address with no history, or for checking which services a leaked staff address is tied to. Holehe sits alongside username tools such as Sherlock and Maigret in our OSINT tools catalog.

How Holehe Checks Email Registrations

Each module sends the address to a site's registration, login or password-recovery flow and reads whether the site treats it as known.

The README's module table marks, for every site, which method is used: registration, login or password recovery. Many services answer differently for an email they know, for example by saying the address is already taken. Holehe reads that difference. Some password-recovery responses also reveal a partly masked recovery email or phone number.

Results come back in a small set of fields documented in the README:

FieldMeaning
existsWhether an account appears to exist for the email on that site
rateLimitWhether the site rate-limited the request, so the answer is unknown
emailrecoveryA partially obfuscated recovery email, when the site returns one
phoneNumberA partially obfuscated recovery phone number, when returned
othersAny extra information the site exposed

The README states in bold that Holehe "does not alert the target email", linking to a discussion in the issue tracker. That is the maintainers' claim about how the modules were written. Sites change their flows, and a module that once stopped short of sending a reset message could behave differently after a site update.

Holehe Key Features

Broad site coverage, a simple yes-or-no output, and the option to embed it in Python code or Maltego.

Coverage

120+ site modules

Social networks, forums, shopping and productivity services, each handled by its own module.

Integration

CLI and Python library

Runs from the command line or inside your own Python application, according to the README.

Maltego

Transform project

A separate Holehe Maltego repository wraps it as a Maltego transform.

Hosted

Online version link

The README links an online version hosted by OSINT Industries, a commercial platform with its own pricing.

Holehe Pricing, License and Maintenance

Holehe is free under GPL-3.0. The most recent PyPI release, 1.61, was published on 21 July 2022, so some modules may no longer match the sites they test.

ItemStatus (checked 10 October 2026)
PriceFree; no paid tier from the project
LicenseGPL-3.0
LanguagePython 3
Latest PyPI release1.61, 21 July 2022 (PyPI)
RepositoryPublic, not archived, about 14,600 stars and 71 open issues
Stated purpose"Built for educational purposes only" (README)

A four-year gap since the last packaged release matters for a tool that depends on how 120 websites behave. Sites redesign sign-up pages, add bot protection or change wording, and each change can turn a module silent or wrong. Before relying on any result, check the module against an account you control and read open issues for that site.

Free also has hidden costs. Holehe sends many requests from your own network, so sites may rate-limit or block your IP address, and the activity is attributable to you. Running it from a corporate network without approval can trigger your own security team's alerts.

Who Holehe OSINT Suits and Who It Does Not

It suits analysts comfortable with Python who need a quick footprint of an address. It does not suit anyone who needs a supported product, evidence-grade output or a non-technical interface.

Good fit: security teams mapping where corporate addresses are registered after a breach, threat researchers profiling a phishing operator's sign-up address, and investigators who want a free first pass before paid tools.

Poor fit: teams that need a vendor, a service level or an audit trail. There is no support contract, no result logging beyond what you build, and no guarantee that a module still works. Non-technical users are better served by a web tool such as Epieos.

Holehe Limitations, Terms and Legal Risks

A hit shows registration, not ownership; automated requests may breach the tested sites' terms; and the person behind the address has data protection rights.

  • Registration is not ownership. Many sites never confirm the email used at sign-up, so someone else may have registered it. A hit is a lead.
  • False negatives are common. A rate-limited or broken module looks like "no account". Absence of a hit proves little.
  • Platform terms. Holehe automates requests to sites that did not agree to it. Many platforms restrict automated access in their terms, and repeated probing can get your IP or accounts blocked. Read the terms of the services that matter to your case.
  • Masked recovery data is personal data. Partial phone numbers and emails returned by recovery flows relate to an identifiable person. Twelve data protection authorities stated in 2023 that publicly accessible personal information is still subject to data protection and privacy laws in most jurisdictions (joint statement on data scraping).
  • Lawful purpose. Under the GDPR you need a lawful basis, usually legitimate interest with a documented balancing test (EDPB guidance). Never use the tool to locate or monitor a private person for personal reasons.

Holehe Alternatives for Email OSINT

Epieos offers a hosted interface, GHunt goes deep on Google accounts, OSINT Industries is a paid platform, and Have I Been Pwned covers breach exposure.

Web tool

Epieos

Browser-based email and phone lookup with a free tier and a paid plan in euros. No code to maintain.

Epieos review →
Open source

GHunt

Focuses on Google accounts behind an email. Needs a logged-in Google session.

GHunt review →
Commercial

OSINT Industries

Paid lookup platform for email, phone and username searches, linked from the Holehe README as its online version.

OSINT Industries review →
Breach data

Have I Been Pwned

Shows which known breaches an address appeared in, with paid API tiers for domain monitoring.

Need the Answer, Not the Tool?

When a decision depends on who uses an email address, an investigation verifies each lead instead of handing you a list of sites.

Holehe tells you that an address is in use somewhere. Our email address investigations work out whether those accounts belong to the same person, grade each link by confidence and capture evidence you can show a lawyer or a bank. If your concern is staff addresses circulating after a breach, leaked credential monitoring tracks them over time without anyone testing passwords. Focused cases start from 10 business days with a fixed quote after scoping. You can also browse all OSINT services for security and legal teams.

Want an Email Address Explained, Not Just Listed?

Send the address and the decision that depends on it. We confirm a lawful purpose and reply with a fixed quote and a delivery date.

Holehe OSINT FAQ

I found Holehe on GitHub while looking for email OSINT tools — what does Holehe OSINT actually tell me about an address, and is it still maintained in 2026?

Holehe OSINT tells you on which of more than 120 sites an email address appears to be registered, and sometimes shows a masked recovery email or phone number. The repository is public and not archived, but the latest PyPI release, 1.61, dates from 21 July 2022. Expect some modules to be out of date, and verify any important result manually.

If I run Holehe on a suspicious supplier's email address, will the supplier receive password reset emails or any warning that I checked them?

The README states that Holehe does not alert the target email. That reflects how the modules were designed, but websites change their recovery flows, and an old module could behave differently today. If discretion matters, limit checks to what you need, confirm a module's behavior against an address you control first, and take advice before probing a counterparty in a legal dispute.

Holehe says an email we're investigating has accounts on Instagram and a dating site — can we put that in a report as proof that this person uses those platforms?

Not as proof. Holehe shows that the address is registered, and many sites never verify sign-up emails, so someone else could have used it. Report it as a lead, then corroborate with independent evidence such as a matching username, profile photo or activity. Grade the finding by confidence and note when and how the check was run.

Our security team wants to run Holehe across all staff email addresses after a breach — is that allowed under GDPR and the websites' terms of service?

It can be justified, but it needs care. Document a legitimate-interest balancing test, tell staff in your privacy notice, and keep results to what supports the security purpose. Separately, Holehe sends automated requests to third-party sites whose terms may restrict that, and bulk runs from your network can get your IP blocked. A breach-exposure service is often the cleaner option.

I don't write code and just want to check one email address — is there an easier way than installing Holehe and running Python on my laptop?

Yes. Web tools such as Epieos run similar checks in a browser, and the Holehe README itself links to an online version hosted by OSINT Industries, a paid platform. If the result feeds a decision about money, employment or legal action, an analyst-led investigation adds the verification and evidence capture that a raw tool output lacks.

We're a law firm and need to know who is behind an email address used in a dispute — should we buy a tool like Holehe or hire an OSINT provider?

Hire a provider when the answer must stand up to scrutiny. Holehe gives a list of sites, which is a starting point. A provider verifies which accounts belong to one person, captures evidence with dates and sources, explains confidence levels and keeps the work within data protection rules. Focused cases start from 10 business days with a fixed quote after scoping.