100% local — your data never leaves your browser

XML Validator — Find Where It Breaks

Check that XML is well-formed: one root, every tag closed and nested, names and characters legal. The first break is named where it happens.

Instant Private Zero cookies

XML input

Result output

What this tool checks

Well-formedness, which is the specification’s own term for “syntactically XML”:

  • exactly one root element;
  • every tag closed, and closed in the order it was opened;
  • attribute values quoted, and no attribute repeated on an element;
  • element and attribute names that start legally and contain only legal characters;
  • entities and numeric references correctly written;
  • no character that XML forbids.

When the document passes, you get its root element and its size. When it does not, you get the parser’s complaint, with the line and column where it gave up.

Well-formed is not valid

These are two different words in the XML specification, and mixing them costs real time.

checks
Well-formedthe syntax — what this tool does
Validthe syntax and a schema: DTD, XSD, RELAX NG

A document can be flawlessly well-formed and wrong in every way that matters: a required element missing, an element in the wrong place, <price>banana</price> where a decimal was declared. Nothing in this report says otherwise, and no well-formedness checker anywhere can.

If what you need is schema validation, you need the schema — and a tool that reads it.

The DOCTYPE is not followed

A <!DOCTYPE> reference is a URL. Resolving it would mean a request going out, which would say that this document exists and who is looking at it. Nothing here leaves your browser, so the DOCTYPE is checked as syntax and otherwise left where it is.

That is also what makes external entity attacks a non-issue here: an entity that points somewhere is never fetched.

A processing instruction in front is fine

<?xml-stylesheet href="style.xsl"?> before the root element is ordinary, valid XML, and the report names the real root element rather than the instruction.

The one ordering rule enforced is the specification’s own: the XML declaration, if present, comes first. Anywhere else it is not a declaration at all but a processing instruction named xml, and that name is reserved.

Private by design

Everything runs locally in your browser with JavaScript. Your data is never uploaded, which makes the tool safe for sensitive content, and it keeps working offline.

Frequently asked questions

Does this check my document against its XSD or DTD?
No, and the distinction matters. **Well-formed** means the syntax holds: one root element, every tag closed in the right order, attribute values quoted, legal names and characters. **Valid** means it also obeys a schema — the required elements present, in the declared order, with the declared types. A document can be perfectly well-formed and still violate its schema in every line.
Why is the DOCTYPE not followed?
Because following it means fetching what it points at. A DTD reference is a URL, and resolving it would send a request — revealing the document exists, and to whom. Everything here runs in your browser and nothing leaves it, so the DOCTYPE is checked for syntax and otherwise left alone.
It says my declaration must come first. Why?
Because the XML declaration is only a declaration in the first position; anywhere else it is a processing instruction named `xml`, which the specification reserves. A `<?xml-stylesheet?>` before it is the usual cause. Move the declaration to the top and the document is accepted.

Related converters