monero address validator
keccak checksumpaste any monero (xmr) address below and it gets checked instantly: the base58 structure, the address type and the embedded keccak checksum. if the checksum fails, that exact string cannot be a real monero address - it was mistyped or invented. it understands all three shapes: standard addresses (plain wallet), integrated addresses (with a payment id baked in) and subaddresses. one caveat: a passing checksum proves an address is well-formed, not that the recipient is honest - clipboard malware swaps in valid addresses too, so eyeball the first and last characters against your source. everything is decoded locally in your browser - nothing leaves your machine.
two ways this runs: with javascript on you get instant feedback as you type - nothing leaves your browser. with javascript blocked the form posts to our server instead, where the check runs once in memory and is never stored or logged - but the pasted address does cross the network.
how monero addresses are built
- standard address - starts with 4
- a plain wallet address: exactly 95 characters starting with "4". inside it hides a 32-byte public spend key plus a 32-byte public view key, wrapped in monero's base58 variant.
- subaddress - starts with 8
- also exactly 95 characters but starting with "8". subaddresses let one wallet generate unlimited separate receive addresses without linking them publicly. wallets handle them transparently.
- integrated address - starts with 4, 106 characters
- a standard address with an 8-byte payment id folded in, which makes it 106 characters long. services like exchanges use payment ids to tell deposits apart - the integrated format just saves you pasting the id separately.
- why the checksum catches typos
- the last 4 bytes of every address are the first 4 bytes of a keccak hash over everything before them. flip one character anywhere and the hash changes completely - the address fails instead of silently eating your funds.
- testnet & stagenet
- other networks use different leading characters than mainnet, so a testnet or stagenet address looks slightly odd next to a "4..." mainnet one. this validator detects the network and names it in the verdict instead of rejecting it.
- a valid checksum is not a guarantee
- passing the checksum proves the string is well-formed - nothing more. scammers generate perfectly valid addresses and swap them in via clipboard malware or phishing pages, betting you won't look closely. after pasting, compare the first few and last few characters against your source. the same applies to bitcoin - there's a dedicated bitcoin address validator for that too.