Ctrl + K
Regex20 min read

Regex Quantifiers Explained

A practical guide to regex quantifiers covering *, +, ?, exact and ranged repetitions, greedy and lazy matching, common patterns, and performance considerations.

Published: 2026-10-05

Regex quantifiers control how many times a character, character class, group, or other regex expression can occur. They are among the most important parts of regular expressions because they turn a pattern that matches one item into a pattern that can match a sequence of items.

The most common quantifiers are *, +, ?, {n}, {n,}, and {n,m}. Once these are combined with character classes, groups, and anchors, you can describe patterns such as one or more digits, an optional protocol, a username with a length limit, or a sequence containing between two and five characters.

This guide explains what each quantifier means, how greedy and lazy variants work, how quantifiers interact with groups and alternation, and how to avoid common mistakes and performance problems.

Regex Quantifiers Quick Reference

QuantifierMeaningExample
*Zero or morea*
+One or morea+
?Zero or onea?
{n}Exactly na{3}
{n,}At least na{3,}
{n,m}Between n and ma{3,5}
*?Zero or more, lazya*?
+?One or more, lazya+?
??Zero or one, lazya??
{n,m}?Between n and m, lazya{3,5}?
💡 A useful way to remember quantifiers is: * means optional repetition, + means required repetition, ? means optional once, and {n,m} gives you an explicit numeric range.

What Is a Regex Quantifier?

A quantifier normally applies to the regex token immediately before it. That token might be a literal character, a character class, a group, or another supported expression.

a+

Here, a is the token and + is the quantifier. The expression means that one or more a characters must occur.

a
aa
aaa
aaaa

Quantifiers can also apply to character classes.

\d+

This means one or more digit characters. A quantifier can also apply to a group.

(ab)+

In this case, the entire group ab must repeat one or more times. It can match ab, abab, ababab, and so on.

The * Quantifier: Zero or More

The asterisk * means zero or more occurrences of the preceding expression. Because zero occurrences are allowed, the quantified expression is optional.

ab*

The pattern begins with a and then allows zero or more b characters.

a
a b
abb
abbb
abbbb

Without spaces, the matching strings include a, ab, abb, and abbb. The important point is that b is not required.

Common Uses of *

The * quantifier is useful when a section of a pattern may be absent but can also occur repeatedly.

https?://

Here the ? applies to s, not *. The example is useful for illustrating optional syntax: it matches both http:// and https://. For zero-or-more repetition, a simple example is:

\d*

This can match an empty string as well as a sequence of digits. That property is sometimes exactly what you want, but it can also cause unexpected matches when a pattern is supposed to require at least one character.

⚠️ If the input must contain at least one occurrence, do not use *. Use + instead. The difference between zero and one minimum occurrence is important in validation patterns.

The + Quantifier: One or More

The plus sign + means one or more occurrences of the preceding expression. Unlike *, it requires at least one match.

ab+

This matches ab, abb, abbb, and other strings containing a followed by at least one b. It does not match a by itself.

Common Uses of +

The + quantifier is extremely common when processing input that requires at least one character.

\d+

This matches one or more digits.

\s+

This matches one or more whitespace characters.

[A-Za-z]+

This matches one or more ASCII letters.

💡 When you are writing a validation pattern, ask whether an element is allowed to be absent. If it must appear at least once, + is usually more appropriate than *.

The ? Quantifier: Zero or One

The question mark ? means zero or one occurrence of the preceding expression. It is commonly used to make a character, group, or other expression optional.

colou?r

This pattern matches both color and colour because the u is allowed to occur zero or one time.

Optional Groups

The ? quantifier becomes particularly useful when applied to a group.

https?

The s is optional, so the expression can match http or https.

(https?|ftp)://

Here the group chooses between http, https, or ftp before the literal :// sequence.

Exact Repetition with {n}

Curly braces let you specify an exact number of repetitions. The form {n} means exactly n occurrences.

\d{4}

This matches exactly four digits.

[A-Z]{3}

This matches exactly three uppercase ASCII letters.

Exact repetition is useful when the format has a known fixed width, such as a four-digit year or a fixed-length identifier.

At Least n with {n,}

The form {n,} means at least n occurrences. There is no upper limit specified by the quantifier.

\d{6,}

This matches six or more digits.

a{3,}

This matches aaa, aaaa, aaaaa, and any longer sequence of a characters.

⚠️ Do not confuse {n,} with {n}. The first means at least n occurrences, while the second means exactly n.

Between n and m with {n,m}

The form {n,m} specifies a minimum and maximum number of repetitions.

\d{2,4}

This matches two, three, or four digits, but not one digit or five digits.

[A-Za-z]{3,20}

This matches between three and twenty ASCII letters.

Range quantifiers are particularly useful for length restrictions. When combined with anchors, they can describe the complete length of an input.

^[A-Za-z0-9_]{3,20}$

This pattern requires the entire input to contain between three and twenty ASCII letters, digits, or underscores.

Quantifiers Applied to Groups

A quantifier applies only to the expression immediately before it. Parentheses let you make a larger expression the target of the quantifier.

(ab)+

The group ab repeats one or more times. This can match ab, abab, and ababab.

(ha){2,4}

This matches haha, hahaha, and hahahaha, corresponding to two through four repetitions of the group ha.

Quantifiers and Character Classes

Character classes and quantifiers are often combined to describe sequences of allowed characters.

[0-9]+

One or more digits.

[A-Fa-f0-9]{6}

Exactly six hexadecimal characters.

[A-Za-z]{5,12}

Between five and twelve ASCII letters.

Quantifiers and Alternation

Alternation uses | to choose between expressions. Parentheses are often necessary when a quantifier should apply to the entire alternative.

cat|dog+

This does not mean that cat or dog repeats. The + applies only to the immediately preceding g, so it can match cat, dog, dogg, doggg, and so on.

(cat|dog)+

Now the entire cat or dog alternative is repeated. This can match cat, dog, catdog, dogcat, and other sequences composed of those alternatives.

💡 When a quantifier appears to have the wrong scope, look at the token immediately before it. If the intended expression is larger, group it with parentheses.

Greedy Quantifiers

By default, common regex quantifiers are greedy. A greedy quantifier attempts to consume as much matching text as possible while still allowing the rest of the pattern to succeed.

a+

Given the input aaaaa, a+ can consume all five a characters because doing so still produces a successful match.

Greediness becomes more noticeable when another expression follows the quantifier.

a+ab

A backtracking regex engine may initially let a+ consume as many a characters as possible, then give some characters back if necessary so that the following ab can match.

Lazy Quantifiers

A lazy, or non-greedy, quantifier tries to consume as little as possible while still allowing the rest of the pattern to succeed. In many regex engines, laziness is created by adding ? after a quantifier.

GreedyLazyMeaning
**?Zero or more, as little as possible
++?One or more, as little as possible
???Zero or one, as little as possible
{n,m}{n,m}?Range, as little as possible
{n,}{n,}?At least n, as little as possible
<.*>

A greedy .* can consume a large portion of the input before the final > allows the pattern to succeed.

<.*?>

The lazy .*? attempts to consume as little as possible before the next > can match. For simple tag-like text this often produces a shorter match.

⚠️ Lazy quantifiers are not a general replacement for greedy quantifiers. They change matching preference, not the fundamental structure of the pattern, and they can still have performance implications in complex backtracking expressions.

Greedy vs Lazy Example

Consider this input containing two tag-like sections:

<b>first</b><b>second</b>

With a broad greedy pattern, the engine may consume from the first < through the final > that allows the complete pattern to succeed.

<.*>

A lazy version generally stops at the earliest > that allows the pattern to succeed.

<.*?>

For structured formats such as HTML, however, regex should not be treated as a replacement for a real parser. The example demonstrates quantifier behavior rather than providing a general HTML parsing strategy.

Possessive Quantifiers

Some regex engines support possessive quantifiers such as *+, ++, and {n,m}+. A possessive quantifier consumes matching characters without giving them back during ordinary backtracking.

a++

Possessive quantifiers are useful in engines that support them when you know that backtracking into a quantified section is unnecessary and want to make matching behavior more constrained.

⚠️ Possessive quantifiers are not supported by every regex engine. JavaScript, for example, has historically differed from engines such as PCRE in this area. Always check the target engine before using engine-specific syntax.

Atomic Groups and Quantifier Behavior

Some regex engines also support atomic groups, written as (?>...). An atomic group prevents the engine from backtracking inside the group after it has matched.

(?>a+)

Atomic groups and possessive quantifiers can be useful for controlling backtracking in engines that support them. They are advanced features and should be introduced only when the target engine and performance requirements justify them.

Optional Sections with Quantifiers

A common practical use of quantifiers is making parts of a pattern optional.

https?://

The s is optional, allowing both HTTP and HTTPS.

\+?\d+

This allows an optional plus sign followed by one or more digits. It can therefore match values such as 12345 and +12345.

Length Validation with Quantifiers

Quantifiers are commonly combined with anchors to enforce a complete input length.

^[A-Za-z]{8}$

This requires exactly eight ASCII letters.

^[A-Za-z0-9]{8,16}$

This requires between eight and sixteen ASCII letters or digits.

Remember that a regex length restriction is based on the matching model of the engine. Unicode text can introduce additional considerations, especially when a user-visible character may consist of multiple code points.

Common Quantifier Patterns

TaskPatternMeaning
One or more digits\d+At least one digit
Zero or more digits\d*Any number of digits, including none
Optional digit\d?Zero or one digit
Exactly four digits\d{4}Four digits
At least four digits\d{4,}Four or more digits
Two to four digits\d{2,4}Two, three, or four digits
One or more spaces +At least one literal space
One or more whitespace characters\s+Whitespace sequence
Three to twenty letters[A-Za-z]{3,20}Length-limited ASCII letters
Optional protocol suffixhttps?http or https

Quantifiers in Validation Patterns

Quantifiers are often used to describe allowed input lengths, but a quantifier alone does not make a complete validator. Anchors, character classes, optional sections, and application-level checks may also be required.

^[A-Za-z0-9_]{3,20}$

This example combines a character class, a range quantifier, and anchors to require the entire input to contain between three and twenty allowed characters.

By contrast, the following pattern can find a sequence of three to twenty allowed characters somewhere inside a larger string:

[A-Za-z0-9_]{3,20}

The difference is the anchors. Quantifiers describe repetition; they do not automatically define the boundaries of the complete input.

Quantifier Scope

One of the most common regex mistakes is applying a quantifier to the wrong part of the pattern. A quantifier normally affects only the immediately preceding token.

ab+

Here only b is repeated. The a occurs once.

(ab)+

Here the complete ab group is repeated.

a(bc)+

Here a occurs once and the group bc repeats.

💡 When a quantifier is intended to repeat multiple characters, group those characters explicitly. Parentheses make the scope visible and reduce ambiguity.

Quantifiers and Backtracking

Backtracking regex engines may try different repetition counts when the rest of a pattern fails. This is what allows a greedy quantifier to give characters back and find another successful path.

a+a

When matching a sequence of a characters, the first + may initially consume as much as possible. If the final a cannot then match, the engine can backtrack and allow the first quantifier to consume fewer characters.

Backtracking is useful because it makes many expressive regex patterns possible, but excessive combinations of repetition and alternatives can also produce very expensive matching behavior.

Catastrophic Backtracking and ReDoS

Some combinations of quantifiers create many possible ways for a regex engine to divide the input between repeated expressions. On a backtracking engine, this can cause matching time to grow dramatically for certain inputs.

^(a+)+$

Nested quantifiers are a classic pattern used to demonstrate this problem. The exact behavior depends on the regex engine, but the example illustrates why repetition should be designed carefully when processing untrusted input.

⚠️ For server-side applications, avoid unnecessarily complex nested quantifiers on untrusted input. Limit input length, test worst-case strings, prefer more deterministic patterns where possible, and use engine-specific safeguards when available.

Quantifiers and the Dot

A common combination is .* or .+. These patterns are powerful because the dot can match many different characters, while the quantifier allows repetition.

.*

The pattern can match zero or more characters. The related .+ requires at least one character.

.+

Although these expressions are convenient, they are often broader than necessary. A more specific character class can make the intended format clearer and can sometimes reduce unnecessary backtracking.

Quantifiers and Newlines

The dot does not always match line terminators. In engines that provide a dotall or similar mode, a flag can change this behavior. In JavaScript, the s flag makes . match line terminators.

const pattern = /.+/s;

This matters when a quantified dot such as .* or .+ is expected to process multi-line content.

Quantifiers in JavaScript

JavaScript supports the standard greedy quantifiers *, +, ?, {n}, {n,}, and {n,m}, along with their lazy forms.

const oneOrMore = /\d+/;
const optional = /https?/;
const exact = /\d{4}/;
const range = /\d{2,4}/;
const lazy = /<.*?>/;

When a pattern is written as a JavaScript regex literal, backslashes are interpreted as part of the regex itself. When the same pattern is passed to the RegExp constructor as a string, JavaScript string escaping adds another layer.

const pattern = new RegExp("\\d+");

Common Quantifier Mistakes

  • Using * when at least one occurrence is required.
  • Using + when the section is actually optional.
  • Forgetting that a quantifier applies only to the immediately preceding token.
  • Using a quantifier on a single character when the entire group should repeat.
  • Confusing {n} with {n,}.
  • Forgetting the upper limit in {n,m}.
  • Assuming lazy quantifiers automatically prevent performance problems.
  • Using .* when a more precise character class would describe the input better.
  • Forgetting that dot behavior can change with multiline-related flags or modes.
  • Assuming possessive quantifiers or atomic groups work in every regex engine.

How to Choose the Right Quantifier

RequirementQuantifier
The element may be absent and may repeat*
The element must appear at least once+
The element is optional but can appear only once?
The element must appear exactly n times{n}
The element must appear at least n times{n,}
The element must appear between n and m times{n,m}
The match should stop as early as possibleLazy form such as *? or +?

A useful design process is to first decide whether the element is required, optional, or repeated. Then determine whether there is a minimum or maximum length. Finally, decide whether greedy or lazy matching is appropriate.

Quantifier Examples for Common Tasks

The following examples show how quantifiers appear in practical patterns.

One or More Digits

\d+

Exactly Four Digits

\d{4}

Two to Four Digits

\d{2,4}

At Least Eight Characters

.{8,}

This checks a minimum number of characters according to the regex engine's character model. If the application needs precise user-perceived character counting, additional Unicode considerations may be necessary.

Optional Minus Sign

-?\d+

Optional Decimal Part

\d+(?:\.\d+)?

The integer part requires one or more digits. The non-capturing group containing the decimal point and fractional digits is optional.

Repeated Separator

(?:,\s*\d+)+

This demonstrates several quantifiers together: the separator and number group can repeat, optional whitespace can occur after the comma, and the number requires one or more digits.

When Regex Quantifiers Should Be Avoided

Quantifiers are fundamental to regex, but not every repeated-data problem needs a regular expression. If the task is simply to repeat an operation over an array, split a string by a fixed delimiter, or trim whitespace, normal programming APIs are usually clearer.

Regex is most useful when the repetition is part of a textual pattern: for example, a sequence of digits, a bounded identifier, an optional section, or a repeated structured group.

Testing Quantifiers

When testing a quantified expression, do not check only one successful input. Test the boundaries defined by the quantifier.

  • For *, test zero occurrences, one occurrence, and several occurrences.
  • For +, test zero occurrences and one or more occurrences.
  • For ?, test both zero and one occurrence.
  • For {n}, test n-1, n, and n+1 occurrences.
  • For {n,m}, test below the minimum, exactly the minimum, a middle value, exactly the maximum, and above the maximum.
  • For lazy quantifiers, test inputs containing multiple possible stopping points.
  • For complex patterns, test long inputs and malformed inputs as well.
💡 A regex tester is especially useful for quantifiers because you can immediately see how changing *, +, ?, or a numeric range changes the matched text.

Helpful Regex Tools

  • Regex testers for checking how greedy and lazy quantifiers behave on real input.
  • Regex generators for creating initial patterns from requirements.
  • Find and replace tools for applying quantified patterns to many text occurrences.
  • Text cleaners for normalizing repeated whitespace and other text sequences.
  • Regex cheat sheets for quickly checking quantifier syntax and related regex constructs.

Frequently Asked Questions

What does * mean in regex?

The * quantifier means zero or more occurrences of the preceding expression. For example, \d* can match no digits or any sequence of digits.

What does + mean in regex?

The + quantifier means one or more occurrences. For example, \d+ requires at least one digit and can match longer sequences of digits.

What is the difference between * and +?

* allows zero or more occurrences, while + requires at least one. This difference is especially important in validation patterns.

What does ? mean in regex?

As a quantifier, ? means zero or one occurrence of the preceding expression. It is commonly used to make a character or group optional, as in https? for http and https.

What does {n,m} mean in regex?

{n,m} means that the preceding expression can occur at least n times and at most m times. For example, \d{2,4} matches two, three, or four digits.

What is a greedy quantifier?

A greedy quantifier attempts to consume as much matching text as possible while still allowing the rest of the pattern to succeed. Most standard regex quantifiers are greedy by default.

What is a lazy quantifier?

A lazy quantifier attempts to consume as little matching text as possible while still allowing the rest of the pattern to succeed. It is commonly created by adding ? after a quantifier, such as .*?.

Can regex quantifiers cause performance problems?

Yes. In backtracking regex engines, nested or overlapping quantifiers can create many possible matching paths and may result in very slow matching for certain inputs. This can become a security issue when untrusted input is involved.

Conclusion

Regex quantifiers define repetition and are essential for writing useful regular expressions. The core set is small: *, +, and ? handle common optional and repeated sections, while {n}, {n,}, and {n,m} provide precise numeric limits.

The most important distinction to remember is that * allows zero occurrences, + requires at least one, and ? allows at most one. Once these are combined with groups, character classes, and anchors, they can express a wide range of practical text patterns.

For more advanced regex work, understanding greedy versus lazy matching, backtracking, atomic groups, and engine-specific features becomes important. Whatever level of complexity you reach, test quantifier boundaries and realistic edge cases before relying on a pattern in production.

Found an issue?

Found an error, outdated information, or something missing from this article? Let me know through the Contact page.

Your feedback helps improve our articles and keep them accurate and useful.