What it actually does
Holehe is an OSINT (Open Source Intelligence) tool that takes an email address and checks if it is attached to an account on over 120 different websites (like Twitter, Instagram, Imgur, Github, etc.). It does this cleanly using the sites' 'forgot password' or account recovery mechanisms, meaning it does not alert the target that their email is being checked. When connected to an AI agent, it gives the agent instant visibility into the digital footprint of an email address.
Who it's for
- 01
Security teams verifying the digital footprint of their own employees for potential phishing risks
- 02
Sales teams trying to verify if an inbound lead's email is a real, active account
- 03
Fraud prevention analysts checking if a newly registered user has a legitimate online presence
Where it earns its keep
- Running a script to check if your company's corporate emails have been used to sign up for unauthorized shadow-IT services
- Validating the authenticity of an anonymous whistleblower's email address
- Enriching inbound sales leads by verifying they use professional platforms like GitHub or LinkedIn
Use it, or skip it
Reach for it when
- You are doing authorized OSINT research or fraud prevention
- You need to quickly validate if an email is a burner address or a real person
Skip it when
- You are trying to dox people or violate privacy policies—use only on authorized targets
- You need 100% guarantee; some sites frequently change their recovery endpoints, breaking the checks
10 automations
Ideas, not tutorials. Each one is work a team does by hand today.
- 01Sales
Inbound Lead Scorer
When a lead fills out a form, an agent runs Holehe to verify the email exists on legitimate platforms, prioritizing the lead if it's a real person.
- 02Operations
Shadow IT Detector
Nightly script checks employee corporate emails against unauthorized SaaS platforms and alerts IT if accounts are found.
- 03Finance
Fraudulent Account Blocker
During sign-up, an agent checks the user's email. If it's not registered on any other internet site, it flags the account for manual review.
- 04Finance
Automated KYC Enrichment
Agent enriches KYC (Know Your Customer) profiles by summarizing the user's digital footprint across social platforms.
- 05Engineering
Phishing Target Analyzer
Agent analyzes which company emails have the largest public footprint to identify high-risk phishing targets.
- 06Sales
Burner Email Rejector
Agent automatically rejects free trial signups from emails that have zero footprint on major websites.
- 07Founders
Recruitment Profile Builder
Given an email, the agent finds the candidate's GitHub and StackOverflow profiles to summarize their coding history.
- 08Founders
Security Incident Context
When an unknown email emails the CEO, the agent instantly runs OSINT and replies in Slack with a risk assessment.
- 09Operations
Data Breach Correlator
Agent cross-references employee emails with known breach sites to enforce mandatory password resets.
- 10Marketing
Customer Persona Extractor
Agent determines if a B2B user is highly active on developer sites vs social media to route them to the right sales funnel.
Want one of these running by Friday?
LimeDock builds these as real workflows inside your stack — deployed to your cloud, wired into your Slack and CRM, with the code in your repo. You pay a build fee and your own API keys, nothing else.
Source
Repository stats were read from the GitHub API and reflect the last time we refreshed this entry. The editorial breakdown above is LimeDock’s own analysis — we are not affiliated with megadose.
https://github.com/megadose/holehe