Regex for Beginners: 10 Patterns You'll Use
October 6, 2026
1 readsRegular expressions have a reputation: powerful, cryptic, and easy to get wrong. A string like ^\d{4}-\d{2}-\d{2}$ looks like a cat walked across the keyboard. But it's really a short sentence in a tiny language, and you only need a handful of words from it to be useful. Here are the building blocks, followed by ten patterns you can paste into real work today.
The five building blocks
Almost every pattern is made from these:
- Literal characters match themselves.
catmatches "cat". - Character classes match one character from a set.
[abc]matches a, b or c.[0-9]matches any digit.\dis a shortcut for a digit,\wfor a letter, digit or underscore, and\sfor whitespace. - Quantifiers say how many.
+means one or more,*zero or more,?optional, and{3}exactly three, or{2,5}between two and five. - Anchors pin a match to a position.
^is the start of the text and$is the end.\bis a word boundary. - Groups use parentheses to treat several characters as one unit, and
|means "or".
That's most of the language. Everything below is these pieces put together.
10 patterns worth keeping
1. Digits only
^\d+$
The whole text must be one or more digits. The anchors are what make it "only".
2. A simple date (2026-10-05)
^\d{4}-\d{2}-\d{2}$
Four digits, a dash, two digits, a dash, two digits. It checks the shape, not whether the date is real, so "2026-99-99" would match.
3. A hex color
^#([0-9a-fA-F]{3}|[0-9a-fA-F]{6})$
A hash followed by either three or six hex digits. Our HEX to RGB tool does the conversion once you've validated it.
4. A US-style ZIP code
^\d{5}(-\d{4})?$
Five digits, with an optional dash and four more.
5. A username (3 to 16 characters)
^[a-zA-Z0-9_]{3,16}$
Letters, digits and underscores only, within a length range.
6. Leading and trailing whitespace
^\s+|\s+$
Find the spaces at either end of a line so you can trim them. For general cleanup, see Remove Extra Spaces.
7. A repeated word
\b(\w+)\s+\1\b
Catches the classic typo "the the". The \1 refers back to whatever the group matched earlier, which is called a backreference.
8. A basic web address
https?://[^\s]+
"http" followed by an optional "s", then "://", then any non-space characters. The ? makes the "s" optional.
9. An email-shaped string
^[^\s@]+@[^\s@]+\.[^\s@]+$
Some characters, an "@", some characters, a dot, some characters. Treat this as a first filter. Truly valid email addresses are more complicated than any short pattern, so the only reliable check is sending a confirmation message.
10. Everything inside quotes
"([^"]*)"
A quote, any characters that aren't a quote, then a closing quote. The parentheses capture the text between them.
Flags change how a pattern behaves
Flags sit after the pattern and adjust the matching:
- g (global) finds every match, not just the first
- i ignores upper and lower case
- m makes
^and$match at each line, not just the whole text
If a pattern matches only once when you expected many, you probably need g. If it misses "Cat" but finds "cat", add i.
The mistakes everyone makes
Forgetting to escape special characters. A dot means "any character", so 3.14 also matches "3x14". To match an actual dot, write \.. The same goes for +, *, ?, (, ), [, { and $ when you mean the character itself.
Greedy matching. By default, quantifiers grab as much as they can. Run <.+> against <b>bold</b> and it matches the whole string, not just <b>. Adding a ? makes it lazy: <.+?> stops at the first closing bracket.
Skipping anchors. Without ^ and $, a validation pattern matches anywhere in the text. \d+ happily "validates" "abc123xyz". If you mean "the entire value", anchor it.
Writing one huge pattern. If a pattern takes you ten minutes to read, split the job into two or three simple steps in your code.
Patterns that can run away. Nested repeats such as (a+)+ can take a very long time on certain inputs, a problem known as catastrophic backtracking. Keep nested quantifiers rare and test with unusually long strings.
How to build one without going mad
- Write down, in plain words, exactly what should match and what shouldn't.
- Start with the simplest version and test it on a few examples.
- Add one piece at a time, retesting after each.
- Test the edge cases: empty text, very long text, and near-misses that should fail.
A live tester makes this loop fast, because you see the matches highlighted as you type. Try it in the Regex Tester. If you're cleaning up data instead, Remove Duplicate Lines and Case Converter handle common jobs without any pattern at all. And when your regex is part of validating structured data, a formatter like JSON Formatter shows you quickly what you're actually matching against; see also JSON formatter vs. validator.
The short version
Learn five building blocks (literals, classes, quantifiers, anchors, groups), keep the ten patterns above handy, escape your special characters, anchor your validations, and test as you build. Regex stops looking like noise once you can read it a piece at a time.