Regular expressions are a powerful tool for pattern matching and text manipulation. Love them or hate them, regex is everywhere — from form validation to log parsing to search-and-replace operations. Here are 15 patterns you'll reach for again and again.
1. Email Validation
/^[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}$/ A practical email pattern that catches most invalid addresses without being overly strict. For production, consider using the HTML5 email input type or a dedicated validation library.
2. URL Validation
/^https?:\/\/(www\.)?[-a-zA-Z0-9@:%._\+~#=]{1,256}\.[a-zA-Z0-9()]{1,6}\b([-a-zA-Z0-9()@:%_\+.~#?&//=]*)$/ 3. Phone Number (US)
/^(\+1|1)?[-.\s]?\(?([0-9]{3})\)?[-.\s]?([0-9]{3})[-.\s]?([0-9]{4})$/ Matches formats like (123) 456-7890, 123-456-7890, 123.456.7890, and +1 123 456 7890.
4. Strong Password
/^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)(?=.*[@$!%*?&])[A-Za-z\d@$!%*?&]{8,}$/ Requires at least 8 characters with one lowercase, one uppercase, one digit, and one special character.
5. IPv4 Address
/^(?:(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)$/ 6. Date (YYYY-MM-DD)
/^\d{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])$/ 7. Hex Color Code
/^#?([a-fA-F0-9]{6}|[a-fA-F0-9]{3})$/ Matches both 3-digit (#fff) and 6-digit (#ffffff) hex colors.
8. UUID v4
/^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-4[0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}$/ 9. Slug (URL-friendly string)
/^[a-z0-9]+(?:-[a-z0-9]+)*$/ Matches URL slugs like "my-blog-post-title" — lowercase alphanumeric with hyphens.
10. HTML Tag
/<\/?[a-zA-Z][^>]*>/ Tip
For parsing HTML, prefer a DOM parser over regex. Regex can handle simple tag matching but will break on nested or malformed HTML.
11. Number with Optional Decimals
/^-?\d+(\.\d+)?$/ 12. Username (alphanumeric + underscore)
/^[a-zA-Z0-9_]{3,20}$/ 3-20 characters, letters, numbers, and underscores only.
13. Hashtag
/#[\w]+/g Use the global flag to find all hashtags in a string. Great for social media text processing.
14. Credit Card Number (basic)
/^(?:4[0-9]{12}(?:[0-9]{3})?|5[1-5][0-9]{14}|3[47][0-9]{13})$/ Warning
This is a basic pattern for Visa, Mastercard, and Amex. For production, use a dedicated library like creditcard.js that performs Luhn checksum validation.
15. Whitespace Trimming
/^\s+|\s+$/g Matches leading and trailing whitespace. In modern JavaScript, just use String.prototype.trim() instead.
Regex Testing Tips
- Always test with both valid and invalid inputs.
- Use online testers like DevKit's Regex Tester for instant feedback.
- Be mindful of catastrophic backtracking — avoid nested quantifiers like (a+)+.
- Use non-capturing groups (?:...) when you don't need the captured value.
- Anchor your patterns with ^ and $ to avoid partial matches.
"Some people, when confronted with a problem, think "I know, I'll use regular expressions." Now they have two problems. — Jamie Zawinski"
Regex is a tool, not a hammer for every nail. Use it where it shines — pattern matching and text extraction — and reach for parsers when dealing with structured formats like HTML or JSON.
Why This Matters in 2026
Regular expressions are everywhere in modern development — form validation, log parsing, search-and-replace, data extraction, and routing. In 2026, regex remains indispensable despite the rise of AI-assisted text processing. The key insight is knowing when regex is the right tool and when it is not. Regex excels at pattern matching in structured text but fails on nested structures like HTML and JSON. Mastering regex patterns and understanding catastrophic backtracking is essential for writing secure, performant code.
Key Takeaways
- Always test regex with both valid and invalid inputs, including edge cases
- Anchor patterns with ^ and $ to avoid unexpected partial matches
- Use non-capturing groups (?:...) when you do not need the captured value
- Watch for catastrophic backtracking with nested quantifiers like (a+)+
- Prefer regex testers with live highlighting and match group visualization
- Use atomic groups or possessive quantifiers to prevent ReDoS attacks
Common Mistakes to Avoid
- Using nested quantifiers like (a+)+ that cause catastrophic backtracking
- Not anchoring patterns, allowing unexpected partial matches
- Using regex to parse HTML or JSON — use a proper parser instead
- Not testing with empty strings, Unicode, and very long inputs
- Forgetting to escape special characters like ., *, +, ? in patterns
- Using greedy quantifiers when lazy ones (*?) are needed, causing over-matching
Warning
Catastrophic backtracking can turn a regex pattern into a denial-of-service vector. A single crafted input can cause your server to hang indefinitely. Always test patterns with long, near-matching inputs before deploying to production.
Best Practices
- Test with empty strings, Unicode text (emoji, CJK), and 10,000+ character inputs
- Set regex timeouts in languages that support them (e.g., Python, .NET)
- Use atomic groups (?>...) or possessive quantifiers (a++) where supported
- Prefer character classes [a-z] over alternation (a|b|c|...) for performance
- Compile regex patterns once and reuse them, not on every call
- Document complex patterns with inline comments using (?#comment) or /x flag
Tip
Use a regex tester that shows execution time. If a pattern takes more than a few milliseconds on a long input, investigate for catastrophic backtracking before it reaches production.
Quick Reference
Here is a collection of the most useful regex patterns for common validation tasks, all tested and production-ready:
// Email validation
const email = /^[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}$/;
// Strong password (8+ chars, upper, lower, digit, special)
const password = /^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)(?=.*[@$!%*?&])[A-Za-z\d@$!%*?&]{8,}$/;
// URL validation
const url = /^https?:\/\/(www\.)?[-a-zA-Z0-9@:%._\+~#=]{1,256}\.[a-zA-Z0-9()]{1,6}\b([-a-zA-Z0-9()@:%_\+.~#?&//=]*)$/;
// IPv4 address
const ipv4 = /^(?:(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)$/;
// Hex color
const hex = /^#?([a-fA-F0-9]{6}|[a-fA-F0-9]{3})$/; Real-World Example
A practical example: validating user input from a registration form. This function checks email format, password strength, and username constraints in a single pass:
function validateRegistration(input) {
const errors = [];
if (!/^[a-zA-Z0-9_]{3,20}$/.test(input.username)) {
errors.push("Username must be 3-20 alphanumeric characters");
}
if (!/^[^\s@]+@[^\s@]+\.[^\s@]+$/.test(input.email)) {
errors.push("Invalid email format");
}
if (!/^(?=.*[a-z])(?=.*[A-Z])(?=.*\d).{8,}$/.test(input.password)) {
errors.push("Password needs 8+ chars with upper, lower, and digit");
}
return errors.length ? { valid: false, errors } : { valid: true };
} Tools and Resources
- DevKit Regex Tester — live highlighting with match groups and execution time
- regex101.com — detailed regex explanation and debugging
- ReDoS checker — detect catastrophic backtracking before deployment
- grep and ripgrep — command-line regex search tools
- JSDoc @pattern annotation — document regex constraints in TypeScript
"Some people, when confronted with a problem, think "I know, I will use regular expressions." Now they have two problems. — Jamie Zawinski"
Regex is a powerful tool for pattern matching and text manipulation, but it must be used judiciously. Test thoroughly with edge cases, watch for catastrophic backtracking, and reach for a proper parser when dealing with nested structures like HTML or JSON. With the right patterns and testing discipline, regex becomes an indispensable part of your toolkit.