Last updated: · By

Identifier Validator: IBAN, BIC, IMEI, ICCID, Card BIN, ABA Routing, VAT

Bank accounts, phones, SIM cards, payment cards and companies are identified by numbers with built-in check digits, so a mistyped or invented number usually fails a simple calculation. Paste an IBAN, BIC/SWIFT code, IMEI, ICCID, card number, US routing number or EU VAT number below, one per line, and the validator tells you whether the number is well-formed, which country, bank, network or reporting body it points to, and what it cannot tell you. Everything runs in your browser; nothing is uploaded.

Card numbers: only paste test numbers or cards you are authorised to handle — never live card numbers that belong to someone else. Card numbers are masked, never put in links, and nothing you paste leaves this browser tab.

Enter validates · Shift+Enter adds a line · up to 500 rows · prefix a line with iban:, bic:, imei:, iccid:, card:, aba: or vat: to force its type. Pure arithmetic in your browser — no network requests, no storage.

Which identifiers can be checked, at a glance?

Each of these numbers is built so that a single wrong digit, and most swapped pairs, break a calculation anyone can repeat. That makes a check digit a fast first filter for typos and invented numbers in screenshots, invoices and reports — but never proof that the account, phone, card or company is real.

IdentifierLooks likeCheckRevealsCannot tell youSource
IBAN2 letters + 2 check digits + up to 30 characters (15–33 in use)ISO 7064 mod 97-10; length and BBAN pattern per countryCountry, bank code, often branch codeAccount holder, whether the account is openpython-stdnum 2.2: iban.dat “generated from iban-registry-v101.txt”, plus BIC, IMEI, routing-number and VAT modules (read 8 Oct 2026) Wikipedia: International Bank Account Number (ECBS example, mod-97 method; read 8 Oct 2026)
BIC / SWIFT8 or 11 letters/digitsFormat and ISO 3166 country only (no check digit)Institution, country, location, branch; test/passive flagsWhether the code is assignedWikipedia: ISO 9362 (BIC structure, location-code conventions; read 8 Oct 2026)
IMEI / IMEISV15 digits / 16 digitsLuhn over 14 digits (IMEISV has none)TAC, reporting body, serial number, software versionThe model name (needs the GSMA database)GSMA TS.06 v27.0 IMEI Allocation and Approval Process (6 Jan 2025)
ICCID89 + up to 18 digits (19–20 in use)Luhn (most issuers)Telecom MII, country calling code, issuer + accountPhone number or subscriberWikipedia: SIM card — ICCID and ITU-T E.118 layout (read 8 Oct 2026)
Payment card12–19 digitsLuhn; length per networkNetwork from IIN range, industry digitIssuer bank name, whether the card is liveWikipedia: Payment card number — IIN ranges table (read 8 Oct 2026)
US ABA routing9 digitsWeights 3-7-1, sum divisible by 10Prefix series, Federal Reserve districtThe bank’s current location after mergersAmerican Bankers Association: Routing Number Policy and Procedures — structure and prefix series (read 8 Oct 2026) Wikipedia: ABA routing transit number — 3-7-1 checksum and district table (read 8 Oct 2026)
EU VATPrefix (AT … SK, EL, XI) + 2–12 charactersVIES structure; national check digits for 12 countriesMember state, format validityCurrent registration (use VIES)European Commission VIES: FAQ “VAT identification number structure” table and FAQ answers (read 8 Oct 2026)

How does each check work?

IBAN

An IBAN is a two-letter ISO country code, two check digits and a country-specific Basic Bank Account Number (BBAN). The check digits are validated by moving the first four characters to the end, converting letters to numbers (A = 10 … Z = 35) and confirming that the result divided by 97 leaves 1 Wikipedia: International Bank Account Number (ECBS example, mod-97 method; read 8 Oct 2026). The SWIFT registry fixes each country’s length and BBAN pattern: the validator embeds the table that python-stdnum generated from SWIFT IBAN Registry release 101 — 89 countries, refreshed on 4 January 2026 python-stdnum 2.2: iban.dat “generated from iban-registry-v101.txt”, plus BIC, IMEI, routing-number and VAT modules (read 8 Oct 2026). SWIFT’s own site refused automated access from our build environment on 8 October 2026, so we could not read the registry file directly or confirm whether a newer release exists; we did confirm that all 89 lengths agree with an independent transcription, php-iban, whose bank and branch positions we use to extract bank codes php-iban registry.txt: bank/branch positions and example IBANs transcribed from the SWIFT registry (read 8 Oct 2026).

Show all 89 IBAN countries, lengths and BBAN formats (registry release 101)
CodeCountryIBAN lengthBBAN format
ADAndorra244!n4!n12!c
AEUnited Arab Emirates233!n16!n
ALAlbania288!n16!c
ATAustria205!n11!n
AZAzerbaijan284!a20!c
BABosnia and Herzegovina203!n3!n8!n2!n
BEBelgium163!n7!n2!n
BGBulgaria224!a4!n2!n8!c
BHBahrain224!a14!c
BIBurundi275!n5!n11!n2!n
BRBrazil298!n5!n10!n1!a1!c
BYBelarus284!c4!n16!c
CHSwitzerland215!n12!c
CRCosta Rica224!n14!n
CYCyprus283!n5!n16!c
CZCzechia244!n16!n
DEGermany228!n10!n
DJDjibouti275!n5!n11!n2!n
DKDenmark184!n9!n1!n
DODominican Republic284!c20!n
EEEstonia202!n14!n
EGEgypt294!n4!n17!n
ESSpain244!n4!n1!n1!n10!n
FIFinland183!n11!n
FKFalkland Islands (Malvinas)182!a12!n
FOFaroe Islands184!n9!n1!n
FRFrance275!n5!n11!c2!n
GBUnited Kingdom224!a6!n8!n
GEGeorgia222!a16!n
GIGibraltar234!a15!c
GLGreenland184!n9!n1!n
GRGreece273!n4!n16!c
GTGuatemala284!c20!c
HNHonduras284!a20!n
HRCroatia217!n10!n
HUHungary283!n4!n1!n15!n1!n
IEIreland224!a6!n8!n
ILIsrael233!n3!n13!n
IQIraq234!a3!n12!n
ISIceland264!n2!n6!n10!n
ITItaly271!a5!n5!n12!c
JOJordan304!a4!n18!c
KWKuwait304!a22!c
KZKazakhstan203!n13!c
LBLebanon284!n20!c
LCSaint Lucia324!a24!c
LILiechtenstein215!n12!c
LTLithuania205!n11!n
LULuxembourg203!n13!c
LVLatvia214!a13!c
LYLibya253!n3!n15!n
MCMonaco275!n5!n11!c2!n
MDMoldova242!c18!c
MEMontenegro223!n13!n2!n
MKNorth Macedonia193!n10!c2!n
MNMongolia204!n12!n
MRMauritania275!n5!n11!n2!n
MTMalta314!a5!n18!c
MUMauritius304!a2!n2!n12!n3!n3!a
NINicaragua284!a20!n
NLNetherlands184!a10!n
NONorway154!n6!n1!n
OMOman233!n16!c
PKPakistan244!a16!c
PLPoland288!n16!n
PSPalestine, State of294!a21!c
PTPortugal254!n4!n11!n2!n
QAQatar294!a21!c
RORomania244!a16!c
RSSerbia223!n13!n2!n
RURussian Federation339!n5!n15!c
SASaudi Arabia242!n18!c
SCSeychelles314!a2!n2!n16!n3!a
SDSudan182!n12!n
SESweden243!n16!n1!n
SISlovenia195!n8!n2!n
SKSlovakia244!n6!n10!n
SMSan Marino271!a5!n5!n12!c
SOSomalia234!n3!n12!n
STSao Tome and Principe254!n4!n11!n2!n
SVEl Salvador284!a20!n
TLTimor-Leste233!n14!n2!n
TNTunisia242!n3!n13!n2!n
TRTürkiye265!n1!n16!c
UAUkraine296!n19!c
VAHoly See (Vatican City State)223!n15!n
VGVirgin Islands, British244!a16!n
XKKosovo204!n10!n2!n
YEYemen304!a4!n18!c

For six countries the BBAN carries its own national check, which the validator also runs: Belgium (first ten digits mod 97), Spain (the two CCC control digits), Norway (mod 11, or Luhn for old seven-digit postgiro accounts), Montenegro (BBAN mod 97 = 1) — all cross-checked against python-stdnum — and France and Monaco, whose RIB key is 97 − ((89 × bank + 15 × branch + 3 × account) mod 97) with letters in the account converted A/J = 1, B/K/S = 2 and so on Wikipédia (fr): Clé RIB — formula and letter table (read 8 Oct 2026). A mismatch there while the IBAN check digits pass usually means the IBAN was generated from a mistyped account number.

BIC / SWIFT code

ISO 9362 codes are 8 or 11 characters: 4 for the institution, an ISO 3166-1 country code (SWIFT also uses XK for Kosovo), 2 for the location and an optional 3-character branch, with XXX or an 8-character code meaning the primary office. By convention a “0” as the second location character marks a test BIC, “1” a passive participant not connected to the SWIFT network and “2” usually reverse billing Wikipedia: ISO 9362 (BIC structure, location-code conventions; read 8 Oct 2026). BICs have no check digit, so the validator can only confirm format and country.

IMEI and IMEISV

GSMA’s allocation rules split an IMEI into an 8-digit Type Allocation Code (TAC), a 6-digit serial number and a Luhn check digit computed over the other 14 digits; the IMEISV replaces the check digit with a 2-digit software version number. The first two TAC digits are the Reporting Body Identifier: 01 CTIA, 35 TÜV SÜD (BABT), 86 TAF in China, 00 for test IMEIs, plus legacy codes such as 44 and 49 that no longer allocate GSMA TS.06 v27.0 IMEI Allocation and Approval Process (6 Jan 2025). Which model a TAC belongs to is held in the GSMA IMEI Database, in which GSMA retains all rights GSMA Terms and Conditions for TAC Allocation, clause 7.3 (rev. 1 Apr 2018); the page therefore links to third-party lookups rather than embedding a model list.

ICCID

The number printed on a SIM follows ITU-T E.118: 89 (telecommunications), a country calling code of 2–3 digits, a 1–4 digit issuer identifier and the account number, closed by a Luhn check digit; 19- and 20-digit ICCIDs are both in use. Countries sharing +1 use 01 (Canada uses 302), Russia 701 and Kazakhstan 997 Wikipedia: SIM card — ICCID and ITU-T E.118 layout (read 8 Oct 2026). Country codes are matched against Google’s libphonenumber table phonenumbers 9.0.40 (port of Google libphonenumber): E.164 country-calling-code table (read 8 Oct 2026). Because the issuer identifier length varies and the ITU’s issuer list is not embedded, the issuer split is shown as structure only.

Payment card numbers

A card number (PAN) starts with a six- or eight-digit issuer identification number and ends with a Luhn check digit. Network ranges used here: Visa 4; Mastercard 51–55 and 2221–2720; American Express 34 and 37; Discover 6011, 644–649, 65 and 622126–622925; JCB 3528–3589; UnionPay 62; Diners Club 30, 36, 38 and 39; Maestro 5018, 5020, 5038, 5893, 6304, 6759 and 6761–6763; Mir 2200–2204 Wikipedia: Payment card number — IIN ranges table (read 8 Oct 2026). Ranges overlap where cards are co-branded, so every matching network is listed. The issuing bank’s name is in the networks’ licensed BIN tables, not in the number.

US ABA routing numbers

The American Bankers Association’s policy defines the routing number as a 4-digit Federal Reserve routing symbol, a 4-digit institution identifier and a check digit, and allocates the first two digits by series: 00 U.S. Government, 01–12 regular, 21–32 thrifts (assigned until 1985), 61–72 electronic transaction identifiers and 80 traveler’s checks American Bankers Association: Routing Number Policy and Procedures — structure and prefix series (read 8 Oct 2026). The check digit makes 3(d1 + d4 + d7) + 7(d2 + d5 + d8) + (d3 + d6 + d9) a multiple of 10, and 01–12 map to the twelve districts from Boston to San Francisco Wikipedia: ABA routing transit number — 3-7-1 checksum and district table (read 8 Oct 2026).

EU VAT numbers

The European Commission publishes each member state’s VAT number structure in the VIES FAQ — for example ATU99999999, DE999999999, FRXX 999999999 and NL followed by 12 characters with B in the 10th position — but says it cannot divulge the check-digit algorithms European Commission VIES: FAQ “VAT identification number structure” table and FAQ answers (read 8 Oct 2026). The validator applies those structures to all 27 member states and Northern Ireland (XI), and runs the publicly documented algorithms for 12 countries using python-stdnum’s implementations as the reference python-stdnum 2.2: iban.dat “generated from iban-registry-v101.txt”, plus BIC, IMEI, routing-number and VAT modules (read 8 Oct 2026). Greece uses EL, not GR.

How do investigators use these checks?

  • Fraud and scam reports. Victims often submit screenshots of “payment details”. A failed IBAN or routing checksum flags an OCR or transcription error before you send a request to a bank; a pass tells you which country and bank code to ask about.
  • Phishing and invoice fraud. When an email changes the beneficiary account, compare the new IBAN’s country and bank code with the supplier’s known bank, and the BIC’s country with the IBAN’s. A mismatch is a red flag; a match proves nothing.
  • Seized-phone and device reports. Extraction reports list IMEI, ICCID and IMSI values. Checking the Luhn digits catches transcription errors, and the TAC and ICCID country code show which device family and which SIM issuer country to pursue. See our Cellebrite phone forensics guide for how those reports are produced.
  • Company due diligence. A VAT number that fails its checksum on an invoice or website is worth a second look; one that passes still needs a VIES check and a company-register search on our business OSINT page.
  • Documentation. Export the results as CSV or JSON and record them alongside your other findings in the Evidence Logger.

What can’t a valid number tell you?

  • That it exists. About one random number in ten passes a Luhn check, and one in 97 passes a mod-97 check. Scammers can generate valid-looking numbers.
  • Who holds it. No identifier here contains a name. Account-holder confirmation needs the bank, a confirmation-of-payee service or legal process.
  • The current bank or model. Routing numbers survive mergers, and TAC-to-model data sits in the GSMA database.
  • Registration status. VAT numbers can be deregistered; only VIES or the tax authority knows.

Running a check-digit calculation on a number you already hold is ordinary arithmetic, and this page neither looks anything up nor stores what you paste. What matters is where the number came from and what you do next: card numbers, bank details and device identifiers of real people can be personal or payment data, and using someone else’s card or account details without authorisation can be a crime. Only handle numbers you are entitled to process, prefer the published test numbers when learning, keep exported files secure, and take advice on your local data-protection and payment-card rules before building a workflow around real data. This page is information, not legal advice.

How was the validator tested?

The engine file that runs this page (identifier-validator.js) was run in Node.js against published examples, and the page itself in headless Chromium at 375 px and 1280 px:

  • IBAN: the ECBS example GB82 WEST 1234 5698 7654 32 (bank WEST, sort code 123456), DE89 3704 0044 0532 0130 00 (BLZ 37040044), the SWIFT registry example for every country that php-iban records (85 of 89), plus national checks on FR14 2004 1010 0505 0001 3M02 606, MC58…, ES91 2100 0418 4502 0005 1332, BE68 5390 0754 7034, NO93 8601 1117 947 and ME25 5050 0001 2345 6789 51; invalid variants (changed check digits, swapped digits, one character short) fail.
  • BIC: DEUTDEFF, DEUTDEFF500, NEDSZAJJXXX; test (…10) and passive (…A1) location codes; bad country and wrong length fail.
  • IMEI: the worked example 49 015420 323751 8 Wikipedia: IMEI (worked Luhn example 49015420323751-8; read 8 Oct 2026) passes with TAC 49015420 and serial 323751, …517 fails, and IMEISV 4901542032375186 yields SVN 86 and the full IMEI.
  • Cards: processor test numbers 4111 1111 1111 1111 Braintree (PayPal) docs: Testing — test card numbers incl. 4111111111111111 (vendor documentation, read 8 Oct 2026), 4242 4242 4242 4242, 5555 5555 5555 4444, 2223 0031 2200 3222, 3782 822463 10005, 6011 1111 1111 1117, 3056 9300 0902 0004, 3566 0020 2036 0505 and 6200 0000 0000 0005 Stripe docs: Testing — test card numbers (vendor documentation, read 8 Oct 2026) are detected as the right network; a changed last digit fails.
  • ABA: 011000015, listed for the Federal Reserve Bank of Boston XE routing-number lookup: 011000015 = Federal Reserve Bank of Boston (third-party directory, read 8 Oct 2026), passes in district 1 (Boston); 011000016 fails and the tool names 5 as the correct check digit; 111000025 passes in Dallas.
  • VAT: VIES publishes structures, not example numbers, so the valid and invalid examples from python-stdnum’s documentation were used (for example ATU13585627, DE136695976, FR23334175221, IT00743110157, NL004495445B01, NL002455799B11, PL8567346215, SE123456789701).
  • 6,670 randomly generated IBANs, BICs, IMEIs, routing numbers, Luhn strings and VAT numbers for the 12 checksum countries gave the same valid/invalid verdict as python-stdnum 2.2, with no mismatches.
  • In the browser: auto-detection of a mixed batch, CSV formula escaping, JSON export, card masking, card numbers stripped from ?v= links, hostile input rendered as text, and no horizontal scrolling at 375 px.

Sources

Stripe and Braintree test numbers and XE’s directory entry are vendor or third-party statements, reported as published. External lookup links on result cards go to third-party sites, which receive whatever you type there.

Frequently asked questions

How do I check if an IBAN is valid?

Paste it into the validator. It checks that the country is in the SWIFT IBAN Registry, that the length and the BBAN pattern match that country, and that the two check digits pass the ISO 7064 mod 97-10 test: move the first four characters to the end, turn letters into numbers (A = 10 … Z = 35) and the remainder after dividing by 97 must be 1. For Belgium, Spain, France, Monaco, Montenegro and Norway it also checks the national account check digits. A valid IBAN is well-formed, not proof that the account exists.

Can an IBAN tell me which bank and branch it belongs to?

It contains the bank code and, in many countries, a branch code at fixed positions, for example the sort code in a UK IBAN, the Bankleitzahl in a German one, or the ABI and CAB codes in an Italian one. The validator extracts those codes. Turning a code into a bank name needs that country’s bank directory, so search the code there or ask the bank; the code alone is not proof of who holds the account.

What do the parts of a SWIFT or BIC code mean?

A BIC has 8 or 11 characters: 4 for the institution, 2 for the ISO country code, 2 for the location and an optional 3-character branch code (XXX or nothing means the primary office). By convention a 0 as the second location character marks a test BIC, a 1 marks a passive participant that is not connected to SWIFT, and a 2 usually marks reverse billing. The validator checks the format and the country code but cannot confirm the code is assigned.

Can I find the phone model from an IMEI?

Partly. The first 8 digits are the Type Allocation Code (TAC), whose first two digits name the reporting body that issued it, such as 35 for BABT or 86 for TAF in China. The TAC-to-model table is the GSMA IMEI Database, which GSMA does not publish openly, so this page shows the TAC, serial number and Luhn check digit and links to third-party lookup sites instead of guessing the model.

What is the difference between an IMEI, an ICCID and an IMSI?

The IMEI identifies the handset and stays with the phone. The ICCID is the serial number of the SIM card or eSIM profile, starts with 89 and carries a country code and issuer. The IMSI identifies the subscriber on the mobile network and is not printed on the card. A seized-phone report usually lists all three, and they answer different questions: which device, which SIM, which subscription.

Is it safe to paste a credit card number here?

The check runs entirely in your browser and nothing is sent or stored, but you should still only paste test numbers or numbers you are authorised to handle, never live cards belonging to other people. Card numbers are masked by default, are left out of shareable links, and are removed if someone puts one in a link. A Luhn pass and a network match only mean the number is well-formed.

How does the ABA routing number checksum work?

Multiply the nine digits by the weights 3, 7, 1, 3, 7, 1, 3, 7, 1 and add them up; a valid routing number gives a multiple of 10. The first two digits give the series: 01 to 12 are the twelve Federal Reserve districts, 21 to 32 are former thrift numbers (district plus 20), 61 to 72 are electronic transaction identifiers (district plus 60) and 80 is for traveler’s checks. For example, 011000015 passes and starts with 01, the Boston district.

Does this tool check whether a VAT number is registered?

No. It checks the country prefix and the structure published in the EU VIES FAQ, and runs the national check-digit algorithm for Austria, Belgium, Denmark, Finland, France, Germany, Italy, Luxembourg, the Netherlands, Poland, Portugal and Sweden. Only VIES or the national tax authority can say whether a number is currently registered, so use the VIES link for that; this page never contacts VIES itself.