Validation
Match a URL
Flags: gi
Match http / https URLs including query strings and fragments.
Pattern
Regular expression
https?:\/\/[\w.-]+(?:\.[\w.-]+)+[\w\-._~:/?#\[\]@!$&'()*+,;=]*How it works
Matches URLs starting with `http://` or `https://`. Domain is at least one label plus a TLD, followed by the optional path/query/fragment characters allowed by RFC 3986.
Matches
- ▸https://example.com
- ▸http://api.example.com/v1/users?id=42
- ▸https://sub.example.co.uk/path#section
Non-matches
- ▸example.com (no protocol)
- ▸ftp://files.example.com
Common gotchas
This intentionally rejects protocol-less URLs (example.com) and non-http schemes. If you also need www.example.com without scheme, add an alternative branch. For strict RFC 3986 compliance, prefer a URL parser (URL constructor in JS, urllib in Python).
Language snippets
JavaScript
const re = /https?:\/\/[\w.-]+(?:\.[\w.-]+)+[\w\-._~:/?#\[\]@!$&'()*+,;=]*/gi;
text.match(re);Python
import re
re.findall(r"https?://[\w.-]+(?:\.[\w.-]+)+[\w\-._~:/?#\[\]@!$&'()*+,;=]*", text)Go
re := regexp.MustCompile(`https?://[\w.-]+(?:\.[\w.-]+)+[\w\-._~:/?#\[\]@!$&'()*+,;=]*`)
re.FindAllString(text, -1)Java
Pattern.compile("https?://[\\w.-]+(?:\\.[\\w.-]+)+[\\w\\-._~:/?#\\[\\]@!$&'()*+,;=]*").matcher(text)Related patterns
Match a domain name
(?:[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?\.)+[a-z]{2,63}
Match an email address
[\w.+-]+@[\w-]+\.[\w.-]+
Match an IPv4 address
(?:(?:25[0-5]|2[0-4]\d|1\d{2}|[1-9]?\d)\.){3}(?:25[0-5]|2[0-4]\d|1\d{2}|[1-9]?\d)
Match an IPv6 address
(?:[A-Fa-f0-9]{1,4}:){7}[A-Fa-f0-9]{1,4}|::1|::
Match a UUID (v4)
[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}
Match a US phone number
(?:\+?1[-. ]?)?\(?[2-9][0-9]{2}\)?[-. ]?[2-9][0-9]{2}[-. ]?[0-9]{4}