Help & documentation

What this tool tells you

Every network interface has a MAC address, and its first three bytes (the OUI) are registered with the IEEE Registration Authority. This lookup resolves that prefix against the complete IEEE registries using longest-prefix matching, so small blocks resolve to the correct organization rather than a generic parent block.

  • Vendor and registered organization, with block type and address range
  • Randomization detection: modern phones randomize Wi-Fi addresses, which have no vendor
  • Virtual-machine prefixes for VMware, VirtualBox, Hyper-V, Parallels, Xen, QEMU/KVM, and Docker
  • Prefix lineage: acquisitions and renames, with the dates each change was first observed
  • Format conversions: colon, hyphen, Cisco dot, plain hex, EUI-64, and IPv6 link-local

How MAC address lookup works

A MAC address is 48 bits, usually written as six hex pairs such as 00:1B:21:3C:4D:5E. The IEEE assigns the leading bits to organizations as registered blocks: MA-L blocks are 24 bits, MA-M blocks are 28 bits, and MA-S and IAB blocks are 36 bits. A lookup tries the longest registered prefix first, so a device inside an MA-S block is attributed to the company that holds that block, not the parent MA-L. The first octet also carries two flag bits: the I/G bit marks multicast addresses, and the U/L bit marks locally administered addresses such as randomized privacy addresses and virtual machines.

The interface runs in 31 languages (English plus 30 translations; Urdu, Arabic, and Persian render right-to-left): switch it with the language picker in the header's toolbar.

MAC address block types

Registry Prefix length Addresses per block Typical use
MA-L24 bits (6 hex)16,777,216Classic OUI; the vast majority of network hardware
MA-M28 bits (7 hex)1,048,576Mid-size allocations, common for newer vendors
MA-S36 bits (9 hex)4,096Small allocations; IoT modules and niche hardware
IAB36 bits (9 hex)4,096Legacy Individual Address Blocks from reserved ranges
CID24 bits (6 hex)-Company identifiers, not assigned to network interfaces

How to find your own MAC address

  • Windows: run getmac /v, or open Settings → Network & internet → Hardware properties.
  • macOS: open System Settings → Network → Details, or run ifconfig en0 | grep ether.
  • Linux: run ip link and read the link/ether value.
  • iPhone / Android: open the Wi-Fi network details. The "private Wi-Fi address" shown there is randomized and will not resolve to a vendor.

Browse by registration dimension

Besides prefix pages, the site pre-renders reference pages organized by the registration itself, each with its complete table. The home page links every index under "MAC address by":

  • Country index - /country: every country with at least one registered MAC address block, with organization, block, and address totals, each row linking the country's full page.
  • Vendor index - /vendor: every organization with two or more registered MAC address blocks, with block and address totals, each row linking the organization's full page.
  • Vendor pages - /vendor/<name>: every MAC block registered to one organization, with block types, address space, countries, registration dates, and an allocation timeline.
  • Country pages - /country/<code>: every organization with blocks registered in that country, sorted by address space, with an allocation timeline.
  • Former-owner pages - /former/<name>: organizations that no longer hold any of the prefixes once registered to them, showing what happened to each block, including acquisitions where a single new owner took over all of them (for example Apple Computer, whose blocks are now registered to Apple, Inc.).
  • Registry index - /registry: MA-L, MA-M, MA-S, IAB, and CID totals and per-type pages.
  • Year index - /year: blocks grouped by the year they were first observed in public data.
  • Region index - /region: registration countries grouped into continents.
  • History index - /history: observed ownership changes by year, plus /history/country/<code> historical-country views.
  • Successor index - /successor: current owners of blocks that changed hands and the former portfolios they absorbed.

Frequently asked questions

Why does my MAC address show no vendor?

Phones, tablets, and laptops often randomize their Wi-Fi MAC address per network. Randomized addresses set the locally administered bit and deliberately carry no manufacturer information, so no vendor can be resolved. Look up the hardware address from the device settings instead.

What is an OUI?

The Organizationally Unique Identifier is the first three bytes (24 bits) of a MAC address. The IEEE Registration Authority assigns each OUI to one organization, which is why the prefix identifies the manufacturer. Modern registries also contain smaller MA-M (28-bit) and MA-S (36-bit) blocks.

What do MA-L, MA-M, MA-S, IAB, and CID mean?

They are the IEEE assignment registries. MA-L is the classic 24-bit OUI with 16,777,216 addresses per block, MA-M is a 28-bit block with 1,048,576 addresses, MA-S and IAB are 36-bit blocks with 4,096 addresses each, and CID is a 24-bit company identifier that is not used for network interfaces.

Why does a MAC address show a company that no longer exists?

MAC prefixes are registered once and are rarely reassigned when a company is acquired or renamed. The hardware keeps its original prefix forever, so the current registry entry may show the acquiring company. For example, Tekelec blocks now show Oracle. Prefix lineage on each result shows when those changes were observed.

What is prefix lineage?

When a registered prefix changes hands or the organization name changes, this site shows a timeline of the organizations associated with that prefix and the dates the changes were first observed in public registration data. Lineage is shown only for the exact prefix, never inherited from a parent or child block.

Can a MAC address be spoofed?

Yes. Operating systems and network tools can set any MAC address, including one that belongs to a registered vendor block. A lookup tells you which organization registered the prefix, not which device actually sent the traffic.

What is a locally administered address?

The second-least-significant bit of the first octet distinguishes universally administered addresses (assigned by the IEEE to a vendor) from locally administered addresses (set by software). Randomized privacy addresses, virtual machines, and manual assignments are all locally administered.

Is this lookup private?

Yes, for lookups you run on this website. The IEEE dataset is downloaded once and the search runs entirely in your browser: the addresses you type are never processed by a server. Normal website requests do still reach the host — opening a direct link such as mac.jasontally.com/apple sends that URL path to the CDN so it can serve the right static file, and the app fetches its public data files by URL — but the host only serves files and runs no search code. The app sets no cookies and does no tracking. The site is hosted on Cloudflare, which collects privacy-first, aggregate web analytics that use no cookies or client-side state and do not fingerprint individuals. One exception to the browser-only rule is the MCP server for AI assistants: it is an HTTP endpoint, so an address submitted there is visible to the host in the request. No session is created and no lookup is linked to anything else. The privacy policy describes that difference in full.

Does the vendor match identify the exact device?

No. The prefix identifies the organization that registered the block, not a model or serial number. Many vendors use dozens or hundreds of prefixes, and contract manufacturers build devices for other brands.

How do I find my own MAC address?

On Windows, run "getmac /v" or open Settings, then Network and Hardware properties. On macOS, open System Settings, Network, Details, or run "ifconfig en0 | grep ether". On iPhone and Android, open the Wi-Fi network details; the private Wi-Fi address shown there is randomized.

Connect an AI assistant to this lookup

This site publishes an MCP server at https://mac.jasontally.com/mcp. It is open, unauthenticated, and read-only. There is no API key, no account, and no session. Point an assistant that supports MCP servers at that URL and ask it about a MAC address or OUI prefix; it will get one resolved answer, including the vendor, block type, address count, and registration country.

If your assistant does not support MCP servers, give it this request instead. It is a plain POST of JSON, and the reply is JSON:

POST /mcp
Content-Type: application/json

{"jsonrpc":"2.0","id":1,"method":"tools/call",
 "params":{"name":"lookup","arguments":{"mac":"8C:1F:64:AF:A4:B2"}}}

Machine-readable catalogs are at /.well-known/ai-catalog.json and /.well-known/ard.json, and a plain-text summary is at /llms.txt. Full setup notes are in the repository.

Lookups you make here run entirely in your browser and are never sent to a server. An MCP lookup differs, because it is an HTTP request. The privacy policy explains the difference, and the terms of service explain what a registry match does and does not mean, including that results can be wrong or out of date and that this site is not affiliated with IEEE.

Data sources and accuracy

Current assignments come from the IEEE Registration Authority's MA-L, MA-M, MA-S, IAB, and CID registries, refreshed on every deploy. Historical changes come from runZero mac-tracker (MIT), which records when an organization name changed in the public data. Those dates are observation dates, not legal transfer dates, and the registries do not reassign most prefixes. An acquisition usually leaves the old vendor name on existing hardware forever.

Both datasets are downloadable as machine-readable files: one JSON object per line, no keys: registry.ndjson for every assignment and lineage.ndjson for every ownership change and its historical registration country. The most recent registrations are listed on the Latest OUIs page, refreshed on every deploy.