What this validator checks
XML has two levels of correctness, and it helps to know which one you need:
- Well-formed means the text obeys XML syntax: exactly one root element, every start tag has a matching end tag with the same case, elements nest without overlapping, attribute values are quoted, and
< and & are escaped in text.
- Valid means the document is well-formed and also follows a DTD or XML Schema (XSD) that says which elements may appear, in what order, with which attributes.
This tool checks the first level. It is the check that matters when a feed reader, SOAP client, Android build, or Maven refuses a file outright, because no program can read XML that is not well-formed. It does not enforce a schema. A DOCTYPE in your document is accepted, but its rules are ignored: a <note> declared to contain only <to> still passes with a <from> inside.
How it works
Click Validate or press Ctrl + Enter. The input is trimmed and handed to your browser's DOMParser with the application/xml type. When the parser fails, it returns a document containing a parsererror element instead of your data, and the tool shows that element's text. When it succeeds, the parsed document is written back out with XMLSerializer into the right editor, so you can see exactly what a program reading your file would get.
Example: finding two errors in an RSS feed
<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
<channel>
<title>Build & Release Notes</title>
<item>
<title>v2.4 shipped</Title>
</item>
</channel>
</rss>
In Chrome or Edge the first run reports:
error on line 4 at column 19: xmlParseEntityRef: no name
The bare & in the channel title starts an entity reference that never gets a name. Change it to & and validate again. Now the parser gets further and reports "Opening and ending tag mismatch: title line 6 and Title", because </Title> does not match <title>. Only one error appears per run, since an XML parser must stop at the first fatal error. Work down the file one fix at a time.
The message text comes from the browser. Chrome and Edge wrap it in "This page contains the following errors" and "Below is a rendering of the page up to the first error"; you can ignore those two phrases. Other browsers word the message differently, but it still includes a line and column.
What the browser parser reports, and what it means
- "Entity 'nbsp' not defined": an HTML entity in XML. Only five entities are predefined (
< > & " '). Use   for a non-breaking space.
- "StartTag: invalid element name": a literal
< in text, as in 1 < 2, or a tag name that starts with a digit like <1st>. Escape the character as < or rename the element.
- "Namespace prefix xlink on a is not defined": the document uses a prefix without an
xmlns:xlink="..." declaration on that element or an ancestor. Common when copying a fragment out of an SVG or SOAP message.
- "Attribute x redefined": the same attribute appears twice on one element.
- "AttValue: " or ' expected": an unquoted attribute such as
width=100, which HTML allows and XML does not.
- "Extra content at the end of the document": more than one root element, or text after the closing root tag.
- "Double hyphen within comment":
-- is not allowed inside <!-- -->, which trips up commented-out command lines.
- "PCDATA invalid Char value 1": a control character, often from a database export. XML 1.0 forbids most characters below U+0020 other than tab, newline, and carriage return.
What the normalized output changes
The serialized copy has the same data but not always the same text. In Chrome, empty elements like <category></category> become <category/>, single-quoted attributes switch to double quotes, © is written as ©, entities declared in an internal DTD subset are expanded and the subset itself is dropped, and whitespace between the XML declaration and the root element disappears. Indentation inside the root is kept as you wrote it. If you need consistent indentation instead, run the file through the XML Formatter.
Limitations
- No DTD or XSD validation, and no way to attach a schema.
- External entities and external DTDs are never fetched, so a
SYSTEM entity resolves to nothing.
- The
encoding in the XML declaration is not tested. Pasted text is already decoded, so a file saved in the wrong encoding can pass here and still fail elsewhere.
When to use a different tool
- To indent a valid document for reading or code review, use the XML Formatter.
- To convert a validated document into an object for JavaScript, use XML to JSON.
- If your data is JSON rather than XML, the JSON Validator does the same syntax check for JSON.
Frequently asked questions
What is the difference between well-formed and valid XML?
Well-formed XML follows the syntax rules of the XML specification: one root element, every tag closed and correctly nested, quoted attributes, escaped special characters. Valid XML is well-formed and also matches a DTD or XML Schema (XSD) that defines which elements and attributes are allowed. This tool checks well-formedness only.
Can I validate XML against an XSD or DTD here?
No. Browser XML parsers are non-validating. A DOCTYPE is accepted and kept, but its element rules are not enforced and external DTD files are not downloaded. Use xmllint with --schema or --dtdvalid, or your language's schema library, for schema validation.
Why do I get "xmlParseEntityRef: no name"?
There is a bare ampersand in your text or an attribute value, for example "Tom & Jerry" or a URL query string like "?a=1&b=2". Replace each & with & or put the text in a CDATA section.
Why does the validator only show one error?
XML parsers are required to stop at the first well-formedness error, so the browser reports only that one. Fix it and click Validate again to find the next problem.
Why does the normalized output look different from my input?
The output is the parsed document written back out by the browser's XMLSerializer. Empty elements become self-closing, attributes use double quotes, character references such as © are written as the actual character, and internal DTD declarations are dropped. The data is the same, but the text is not byte-for-byte identical.
Is my XML sent to a server?
No. Validation uses the DOMParser built into your browser. Pasted text and imported files are not uploaded. Import URL fetches the file directly from your browser.