Regex for US Social Security Number
SSN with known-invalid ranges excluded.
The US Social Security Number regex is ^(?!000|666|9\d{2})\d{3}-(?!00)\d{2}-(?!0000)\d{4}$ — copy it below, or open it in the explainer for a token-by-token breakdown.
The pattern
^(?!000|666|9\d{2})\d{3}-(?!00)\d{2}-(?!0000)\d{4}$
What it matches
123-45-6789012-34-5678555-12-3456
What it doesn't match
000-12-3456666-12-3456900-12-3456123-00-6789123-45-0000
Notes & gotchas
Excludes invalid SSNs: area numbers 000, 666, and 900-999; group 00; serial 0000. Per SSA rules. For unformatted SSNs (no dashes), use \d{9}.
Code in your language
Use the explainer's Code tab to generate ready-to-paste snippets in JavaScript, Python, Java, .NET, Go, Ruby, and PHP for this pattern.
Open in explainer →Token-by-token breakdown
Every part of the pattern, left to right:
| Token | Meaning |
|---|---|
^ | start of string (or line in multiline mode) |
(?! | start of a negative lookahead — NOT followed by |
000 | literal text “000” |
| | OR — try the alternative |
666 | literal text “666” |
| | OR — try the alternative |
9 | literal text “9” |
\d{2} | exactly 2 times: digit (0–9) |
) | end of group |
\d{3} | exactly 3 times: digit (0–9) |
- | literal text “-” |
(?! | start of a negative lookahead — NOT followed by |
00 | literal text “00” |
) | end of group |
\d{2} | exactly 2 times: digit (0–9) |
- | literal text “-” |
(?! | start of a negative lookahead — NOT followed by |
0000 | literal text “0000” |
) | end of group |
\d{4} | exactly 4 times: digit (0–9) |
$ | end of string (or line in multiline mode) |
About this pattern
US-specific identifiers follow patterns set by federal and state authorities (SSA, IRS, USPS, state DMVs). Regex catches malformed values; final validation usually requires an authoritative lookup.
Quick usage in different languages
This exact pattern — with the correct escaping and idioms for each language:
- JavaScript:
/^(?!000|666|9\d{2})\d{3}-(?!00)\d{2}-(?!0000)\d{4}$/.test(value) - Python:
re.match(r"^(?!000|666|9\d{2})\d{3}-(?!00)\d{2}-(?!0000)\d{4}$", value) - Java:
Pattern.compile("^(?!000|666|9\\d{2})\\d{3}-(?!00)\\d{2}-(?!0000)\\d{4}$").matcher(value).matches() - C# / .NET:
Regex.IsMatch(value, @"^(?!000|666|9\d{2})\d{3}-(?!00)\d{2}-(?!0000)\d{4}$") - Go:
regexp.MustCompile(`^(?!000|666|9\d{2})\d{3}-(?!00)\d{2}-(?!0000)\d{4}$`).MatchString(value) - Ruby:
/^(?!000|666|9\d{2})\d{3}-(?!00)\d{2}-(?!0000)\d{4}$/.match?(value) - PHP:
preg_match('~^(?!000|666|9\d{2})\d{3}-(?!00)\d{2}-(?!0000)\d{4}$~', $value)
The explainer’s Code tab regenerates these for any pattern you paste, and the downloadable cheat sheet bundles the breakdown, all seven snippets, and the pitfalls below onto one printable page.
Common pitfalls
- Anchored to the whole string. This pattern uses ^ and $, so it requires the entire input to match. To find it inside a longer text, drop the anchors and use the global (g) flag.
- Escape it correctly per language. In Java and JavaScript strings each backslash must be doubled (\\d); in Python, Go, and C# use raw/verbatim strings so the backslashes survive.
- Validate beyond format. Matching the format doesn't guarantee the value is real. Confirm the us social security number against a source of truth (database, API, or checksum) where it matters.
Standards & sources
This pattern is based on the following authoritative specification(s) and issuing authorities. Formats can change — always confirm against the primary source.
Related patterns
More patterns in the United States 🇺🇸 category:
See also
Browse all 300 patterns in the library, or open this regex in the interactive explainer for a token-by-token breakdown, live testing, and code in seven languages.
Want more patterns? Browse the full library →