holehe (email → services)

holehe <email>

Checks if an email is registered in online services with holehe, mapping the accounts associated with the address.

Run it in the OSINT phase when you have a target email and want to know which services it's registered on: holehe queries the services (the platforms, the sites) with the address and reports existing accounts (and those that return different errors). It's the reference email OSINT tool (from Megadose): the email's registration in services. In reconnaissance, holehe gives the map of the email's accounts — the surface for phishing (the platform where the user is registered), password reset (the account vector), and correlation with breaches.

Don't use it as verification: results depend on each service's selectors (some return ambiguous responses) — findings are verified (rate limit, login page). The sweep generates traffic to services (and some block your IP): space it out and use it carefully. And note: the tool queries services unauthenticated — services with protection (captcha, rate limit) fail; review the list of supported services. For email in breaches, use breach search tools; holehe is for current registration.