URL Validation Regex
Regex for matching and validating HTTP/HTTPS URLs. Works in JavaScript, Python, and other languages.
https?:\/\/(www\.)?[-a-zA-Z0-9@:%._+~#=]{1,256}\.[a-zA-Z0-9()]{1,6}\b([-a-zA-Z0-9()@:%_+.~#?&/=]*)About this pattern
This regex matches HTTP and HTTPS URLs with an optional www prefix, a domain name, and optional path, query parameters, and fragment. It handles most real-world URLs including those with ports, paths, query strings, and hash fragments. Requiring the protocol avoids false positives from strings that merely contain a dot. Note that it is deliberately unanchored, which makes it suitable for finding URLs inside a larger body of text — for strict validation, where the whole string must be a URL and nothing else, wrap it in ^ and $, otherwise "see https://example.com now" passes as valid input.
Worked examples
Requiring the protocol is what stops ordinary sentences containing a dot from matching.
Matches
- https://example.com
- http://www.example.com/a/b?c=1#d
Does not match
- example.com
- ftp://example.com
FAQ
Does this match URLs without http/https?
No. Requiring the protocol avoids matching random strings like "example.com" in the middle of text. If you need to match bare domains, remove the "https?://" prefix from the pattern.
Can I use this to validate a URL input field?
Only after anchoring it. As written the pattern finds a URL anywhere in the input, so a string with surrounding text still matches. Add ^ at the start and $ at the end for validation. For anything beyond format checking, the URL constructor in JavaScript is more reliable than a regex.