Home >Blog

How to Validate a URL with Regex: HTTP, HTTPS, Domains, and Query Strings

Published Updated

Short answer: use a whole-string pattern when you need a quick URL shape check, but use the native URL parser when your application must reliably separate protocol, hostname, port, path, query, and fragment. RegexToolBox can generate, test, and compare the pattern across several language examples; it cannot replace URL parsing, DNS checks, or an HTTP request.

What this URL regex validates

The practical pattern below accepts HTTP and HTTPS URLs with a DNS-style domain, an optional port, an optional path, an optional query string, and an optional fragment:

^https?:\\/\\/(?:[A-Za-z0-9](?:[A-Za-z0-9-]{0,61}[A-Za-z0-9])?\\.)+[A-Za-z]{2,}(?::\\d{1,5})?(?:\\/[^\\s?#]*)?(?:\\?[^\\s#]*)?(?:#[^\\s]*)?$

This is a practical web-form filter. It deliberately targets hostnames such as example.com and does not attempt to implement every URI rule, internationalized domain form, IPv6 literal, user-info credential, or local development hostname.

Break the pattern into URL parts

  • ^ and $ require the complete input to match, so a valid URL cannot be hidden inside extra text.
  • https? allows http or https.
  • \\/\\/ requires the authority separator after the scheme.
  • (?:...\\.)+[A-Za-z]{2,} requires one or more DNS labels and a two-character-or-longer alphabetic top-level label. Each label starts and ends with an alphanumeric character, while internal hyphens are allowed.
  • (?::\\d{1,5})? allows an optional numeric port such as :8080.
  • (?:\\/[^\\s?#]*)? allows a path and stops it from consuming the query or fragment markers.
  • (?:\\?[^\\s#]*)? allows a query string, including parameters separated by &.
  • (?:#[^\\s]*)? allows a fragment after the query or path.

HTTP and HTTPS only

If the input policy allows only secure URLs, change the scheme part to https:

^https:\\/\\/(?:[A-Za-z0-9](?:[A-Za-z0-9-]{0,61}[A-Za-z0-9])?\\.)+[A-Za-z]{2,}(?::\\d{1,5})?(?:\\/[^\\s?#]*)?(?:\\?[^\\s#]*)?(?:#[^\\s]*)?$

Keep the http alternative when a site accepts both schemes. A regex match says only that the text has the expected shape; it does not prove that the server supports the scheme or that a certificate is valid.

Domains, ports, paths, and query strings

Domain names

The domain branch rejects empty labels, leading or trailing hyphens, and a missing dot. It accepts subdomains such as docs.example.com. This policy excludes localhost, bare internal names, and IP addresses. Add separate alternatives if your product explicitly supports those inputs.

Ports

The optional port branch accepts one to five digits. It does not know whether a port is registered, reachable, or appropriate for HTTP. If you need the numeric range from 1 through 65535, parse the captured port and apply a numeric check in application code.

Paths

The path branch accepts ordinary URL characters until whitespace, ?, or #. It therefore handles values such as /products/regex-guide and encoded segments such as /search/%5Burl%5D without trying to decode them inside the regex.

Query parameters and fragments

The query branch accepts one or more non-space characters after ?, including multiple parameters such as ?q=regex&page=2. The fragment branch handles values after #. Regex does not verify that a parameter name is unique, that a value is URL-encoded, or that a server recognizes the parameter.

Regex or the native URL parser?

Use regex at the input boundary when you need a lightweight shape check, a search filter, or a quick test fixture. Use the native parser for routing, security decisions, canonicalization, redirects, allowlists, and any workflow that needs trustworthy components.

In JavaScript, new URL(value) parses an absolute URL and exposes protocol, hostname, port, pathname, search, and hash. The parser also normalizes some representations and throws for malformed input. In other languages, use the standard URL or URI parser available in that runtime. Treat parser success as syntax validation, then apply your own policy for allowed schemes, hosts, ports, and credentials.

Test the pattern in RegexToolBox

  1. Open the RegexToolBox regex tester.
  2. Paste the pattern into the Generated Regex field, or describe the requirement and choose Generate Regex with AI.
  3. Select JavaScript, PHP, Python, Java, or C# to see a language-specific code example.
  4. Put one URL per line in Test Content (one per line).
  5. Click Validate and review the per-line Validation Results.

Valid and invalid examples

InputExpectedReason
https://example.comValidHTTPS scheme and DNS-style domain
http://docs.example.com:8080/guideValidHTTP, subdomain, port, and path
https://example.com/search?q=regex&page=2#resultsValidQuery parameters and fragment
https://sub.example.co.uk/a%20bValidMulti-label domain and encoded path segment
ftp://example.com/fileInvalidScheme is outside the HTTP/HTTPS policy
https://localhost:3000InvalidLocal hostnames are excluded by this domain policy
https://-example.comInvalidDomain label starts with a hyphen
https://example.com/path with spacesInvalidWhitespace is not allowed
example.comInvalidScheme and authority separator are missing
https://192.0.2.10InvalidIPv4 literals are outside this hostname-only pattern

Language escaping examples

The regex engine receives the same logical pattern, but the host language may require an extra level of escaping. These snippets show the practical pattern in common forms.

JavaScript

const urlPattern = /^https?:\\/\\/(?:[A-Za-z0-9](?:[A-Za-z0-9-]{0,61}[A-Za-z0-9])?\\.)+[A-Za-z]{2,}(?::\\d{1,5})?(?:\\/[^\\s?#]*)?(?:\\?[^\\s#]*)?(?:#[^\\s]*)?$/;
const isValidShape = urlPattern.test(value);

PHP

$pattern = '~^https?://(?:[A-Za-z0-9](?:[A-Za-z0-9-]{0,61}[A-Za-z0-9])?\\.)+[A-Za-z]{2,}(?::\\d{1,5})?(?:/[^\\s?#]*)?(?:\\?[^\\s#]*)?(?:#[^\\s]*)?$~';
$isValidShape = preg_match($pattern, $value) === 1;

Python

import re

url_pattern = re.compile(r'^https?://(?:[A-Za-z0-9](?:[A-Za-z0-9-]{0,61}[A-Za-z0-9])?\\.)+[A-Za-z]{2,}(?::\\d{1,5})?(?:/[^\\s?#]*)?(?:\\?[^\\s#]*)?(?:#[^\\s]*)?$')
is_valid_shape = url_pattern.fullmatch(value) is not None

Java

String regex = "^https?://(?:[A-Za-z0-9](?:[A-Za-z0-9-]{0,61}[A-Za-z0-9])?\\\\.)+[A-Za-z]{2,}(?::\\\\d{1,5})?(?:/[^\\\\s?#]*)?(?:\\\\?[^\\\\s#]*)?(?:#[^\\\\s]*)?$";
boolean isValidShape = Pattern.compile(regex).matcher(value).matches();

C#

var pattern = @"^https?://(?:[A-Za-z0-9](?:[A-Za-z0-9-]{0,61}[A-Za-z0-9])?\\.)+[A-Za-z]{2,}(?::\\d{1,5})?(?:/[^\\s?#]*)?(?:\\?[^\\s#]*)?(?:#[^\\s]*)?$";
bool isValidShape = Regex.IsMatch(value, pattern);

When a language uses a normal quoted string, each regex backslash may need another backslash for the string literal. Raw strings, verbatim strings, regex literals, and delimiter choices can reduce that extra escaping. Always test the final runtime string, not only the source-code appearance.

Common questions

What is the best regex for URL validation?

There is no universal best pattern. Choose a policy for schemes, hostnames, ports, paths, queries, and fragments, then keep the expression as narrow as your input requires.

Can this regex validate every legal URL?

No. It is a hostname-focused HTTP/HTTPS filter. It excludes IPv4 and IPv6 literals, localhost, user-info credentials, internationalized domains, and less common URI schemes.

Does a match prove the URL works?

No. A match checks text shape only. It does not perform DNS resolution, certificate validation, connectivity checks, or an HTTP request.

When should I use new URL instead?

Use the native parser when you need reliable URL components, canonicalization, allowlist checks, redirects, or security-sensitive decisions. Apply your product policy after parsing.

How do I test language escaping?

Paste the logical pattern into RegexToolBox, choose the target language, copy the generated example, and run it against the same one-per-line test set. Confirm that the runtime receives the intended backslashes.

FAQ

What is the best regex for URL validation?
There is no universal best pattern. Choose a policy for schemes, hostnames, ports, paths, queries, and fragments, then keep the expression as narrow as your input requires.
Can this regex validate every legal URL?
No. It is a hostname-focused HTTP/HTTPS filter and excludes IP literals, localhost, user-info credentials, internationalized domains, and less common URI schemes.
Does a match prove the URL works?
No. A match checks text shape only; it does not perform DNS resolution, certificate validation, connectivity checks, or an HTTP request.
When should I use the native URL parser?
Use it for reliable URL components, canonicalization, allowlist checks, redirects, or security-sensitive decisions, then apply your product policy after parsing.
How do I test language escaping in RegexToolBox?
Paste the logical pattern into the tester, choose JavaScript, PHP, Python, Java, or C#, copy the generated example, and run it against the same one-per-line test set.

目录

信息

  • 点击248
  • 发布日期2026/09/03
0/500
友善分享您的看法。

更多帖子

探索本节更多文章
Regex for IP Addresses: Accurate IPv4 and IPv6 Validation Examples
Sep 09, 2026288视图

Regex for IP Addresses: Accurate IPv4 and IPv6 Validation Examples

Use regex to find possible IP addresses, then use the right validation rule for the job. This guide covers loo...

#regex for IP address#IP address regex#IPv4 regex#IPv6 regex
Password Validation Regex: Examples for Length, Numbers, Symbols, and Strong Passwords
Sep 07, 2026271视图

Password Validation Regex: Examples for Length, Numbers, Symbols, and Strong Passwords

Learn practical password validation regex patterns for length, digits, symbols, and mixed character classes. T...

#password validation regex#regex for password validation#strong password regex#regex lookahead
What Regex Should You Use for Phone Numbers? Patterns for US and International Formats
Aug 28, 2026256视图

What Regex Should You Use for Phone Numbers? Patterns for US and International Formats

Compare practical regex patterns for US formatted numbers, normalized local numbers, plus-prefixed internation...

#phone number regex#regex for phone number#US phone regex#international phone regex
How to Extract Email Addresses from Text with Regex in Python and JavaScript
Sep 15, 2026211视图

How to Extract Email Addresses from Text with Regex in Python and JavaScript

Extract email addresses from any text with regex in Python and JavaScript: the pattern explained piece by piec...

#regex extract email#email regex python#email regex javascript#extract emails from text
Regex for Numbers Only: Integers, Decimals, Negative Values, and Leading Zeros
Sep 12, 2026211视图

Regex for Numbers Only: Integers, Decimals, Negative Values, and Leading Zeros

Choose the right regex for numbers-only input. This guide covers ASCII digits, integers, decimals, negative va...

#regex for numbers only#numbers only regex#integer regex#decimal regex
What Is the Best Regex for Email Validation? Practical Patterns and Limitations
Aug 31, 2026208视图

What Is the Best Regex for Email Validation? Practical Patterns and Limitations

Choose a simple or practical email-validation regex based on your input policy, compare JavaScript and Python ...

#email validation regex#regex for email validation#email regex#JavaScript regex
反馈邮箱