Using regex safely: a 60-second primer
A regular expression is a pattern that describes a set of strings. They are perfect for format checks (does this look like an email?) and extraction (find every URL in this text). They are not proof of validity: an email-shaped string can still bounce, so the real email check is sending a confirmation message.
- Anchor when validating, do not anchor when searching. Use
^...$ for "is this whole string an email", and the bare pattern with a global flag to find matches inside longer text.
- Keep patterns simple. Nested quantifiers like
(a+)+ can hang your program on crafted input (a ReDoS attack). The patterns on this page avoid that trap.
- Limit input length before running a regex against untrusted text, and prefer a timeout where your language supports one.
- Test both sides. Always test with strings that should match and strings that should not. The live tester above does exactly that.
Frequently asked questions
Can a regex fully validate an email address?
No. The official email standard (RFC 5322) allows exotic formats that no practical pattern covers, and a pattern cannot tell you whether an inbox exists. A regex is the right tool for a format hint: catch typos like missing @ signs instantly, then confirm ownership by sending a verification email or link.
What is the difference between ^...$ and a bare pattern?
The anchors ^ and $ tie the pattern to the start and end of the string, so it only matches when the entire string fits. That is what you want for validating a form field. Without anchors, the same pattern will find matches inside longer text, which is what you want for extracting emails or URLs from a document.
Do these patterns work in both JavaScript and Python?
Yes. Every pattern on this page uses syntax shared by JavaScript and Python regular expressions. The main differences to watch for elsewhere are flags (JavaScript /i versus Python re.IGNORECASE) and the fact that Python raw strings (r"...") make backslashes easier to read. The code snippets above handle both for you.
Why does my password regex not match accented characters?
Character classes like [a-z] cover only unaccented Latin letters. If your users type names or passwords with accents, use the Unicode-aware equivalents your language provides (for example \p{L} with the u flag in JavaScript, or the regex module in Python), or normalize the input first.
Is my test input sent to a server?
No. This entire page is one static file. The generator, the live tester, and the code snippets all run locally in your browser with JavaScript. Nothing you type or paste ever leaves your device.
Pro features coming soon
A saved pattern library is on the way: store your customized patterns, organize them into collections, and share them with your team. The free generator above stays free.