A sort code is one of the few pieces of banking infrastructure almost everyone in the UK can recite and almost nobody has been told the limits of. It goes on invoices, into payroll forms and across the counter, and it is treated as though it settles a question it does not actually answer.
What the six digits identify
The sort code identifies the institution holding an account and, traditionally, the specific branch. The first two digits indicate the bank, and the remaining four narrow it down within that bank.
The branch part is largely historical now. Sort codes were allocated when accounts genuinely lived at a physical branch, and plenty still trace back to addresses that closed years ago. Newer institutions were allocated ranges that never corresponded to branches at all. The number still routes correctly; it just stopped describing a place.
Paired with an eight-digit account number, a sort code addresses one specific UK account. That is its entire job: routing. It is the domestic equivalent of the part of an IBAN that names the bank.
What it does not tell you
Here is the gap that causes trouble.
A sort code, on its own or beside an account number, does not confirm that the account exists. It does not confirm the account is open, or that it can receive the payment type you are about to send. And it does not confirm the account belongs to the person or company you think you are paying.
Those three things are what someone is usually trying to establish when they go looking for a sort code checker, and none of them is a question the number can answer by itself.
Why a checker can call a fictional sort code valid
This is the part worth understanding properly, because it runs against what the word "checker" implies.
Most free sort code checkers perform a modulus check. It is an arithmetic test, published by the card industry, that determines whether an account number could be valid for a given sort code. Each sort code range has a specified calculation and a set of weightings, published in a table that developers work from. Run the sum, and the account number either satisfies it or does not.
The problem is what happens when the sort code is not in that table. The specification is explicit: if no entry exists, no check can be applied, and the account should be treated as valid. Not "unknown". Valid.
So a sort code that has never been allocated to anyone can pass a modulus check, and a checker built on that logic will show a tick. The tick means "nothing here contradicts the format". A reader takes it to mean "this is a real account". The distance between those two statements is the whole problem, and it is why this site does not publish a checker: for a payments group to hand someone a green tick before they transfer money, on a test that passes fictional codes by design, would be worse than offering nothing.
Modulus checking is genuinely useful in its place, which is inside a payment system catching typos before a transaction is submitted. It is not a fraud control and was never designed as one.
What Confirmation of Payee does differently
Confirmation of Payee is the check that actually looks at who holds the account.
When you set up a new payee, the service compares the name you typed against the name registered on the receiving account, and answers before the money moves. You get a match, a close match with the real name shown so you can decide, or no match at all.
That is a different order of information. Modulus checking asks whether the numbers are well formed. Confirmation of Payee asks whether the account belongs to who you think. Only the second one catches an invoice with swapped details, or a payee who is not who they claimed.
It has limits worth knowing. Coverage is not universal across every institution and account type, so an unavailable result is not a red flag by itself. And crucially, a match tells you the account belongs to that name and nothing more. If someone has convinced you to pay an account genuinely held in their own name, the check passes cleanly. It defends against error and impersonation, not against persuasion.
Is it safe to share your sort code and account number?
Broadly, yes, and the anxiety here is usually pointed at the wrong risk.
Those two numbers exist to be given out. They are what you hand an employer to be paid, what appears on your invoices, and what was printed on the bottom of every cheque for decades. On their own they do not let anyone remove money from your account. Taking money out requires either your authorisation or a direct debit mandate, and mandates come with a guarantee that entitles you to a refund.
The realistic risks are indirect. Details make a scammer sound credible when they call you. And for businesses, invoice redirection is a genuine and common fraud: an invoice is intercepted or spoofed, the bank details are swapped, and payment goes to the fraudster with everything else on the document looking correct.
Which points at the only habit that reliably helps. Treat any request to change payment details as suspicious regardless of who it appears to come from, and verify it on a phone number you already had rather than one printed on the new document.
What to do before paying someone new
Use Confirmation of Payee and read the result rather than clicking past it. A close match showing a different name is information, not an inconvenience.
Send a small test payment first for a significant transfer to a new supplier, and confirm receipt before sending the balance. It costs a day.
Verify changed details out of band, on a number you already held.
And treat any tool that pronounces a sort code valid as telling you about formatting, not about safety. The reassuring answer people want from a checker is not one a checker is able to give.