# Help & documentation Every network interface has a MAC address, and its first three bytes (the Organizationally Unique Identifier, OUI) are registered with the IEEE Registration Authority. This lookup resolves that prefix against the complete IEEE registries using longest-prefix matching, so small blocks resolve to the correct organization rather than a generic parent block. - Vendor and registered organization, with block type and address range - Randomization detection: modern phones randomize Wi-Fi addresses, which have no vendor - Virtual-machine prefixes for VMware, VirtualBox, Hyper-V, Parallels, Xen, QEMU/KVM, and Docker - Prefix lineage: acquisitions and renames, with the dates each change was first observed - Format conversions: colon, hyphen, Cisco dot, plain hex, EUI-64, and IPv6 link-local The interface runs in 31 languages (English plus 30 translations; Urdu, Arabic, and Persian render right-to-left): switch it with the language picker, or open a pre-rendered localized home page at `https://mac.jasontally.com/lang/{locale}/` (for example [Spanish](https://mac.jasontally.com/lang/es/) or [Japanese](https://mac.jasontally.com/lang/ja/)); the lookup itself, results pages, and downloadable data are language-neutral. This document and the prefix/hub pages are English. ## How MAC address lookup works A MAC address is 48 bits, usually written as six hex pairs such as `00:1B:21:3C:4D:5E`. The IEEE assigns the leading bits to organizations as registered blocks: MA-L blocks are 24 bits, MA-M blocks are 28 bits, and MA-S and IAB blocks are 36 bits. A lookup tries the longest registered prefix first, so a device inside an MA-S block is attributed to the company that holds that block, not the parent MA-L. The first octet also carries two flag bits: the I/G bit marks multicast addresses, and the U/L bit marks locally administered addresses such as randomized privacy addresses and virtual machines. ## MAC address block types | Registry | Prefix length | Addresses per block | Typical use | | --- | --- | --- | --- | | MA-L | 24 bits (6 hex) | 16,777,216 | Classic OUI; the vast majority of network hardware | | MA-M | 28 bits (7 hex) | 1,048,576 | Mid-size allocations, common for newer vendors | | MA-S | 36 bits (9 hex) | 4,096 | Small allocations; IoT modules and niche hardware | | IAB | 36 bits (9 hex) | 4,096 | Legacy Individual Address Blocks from reserved ranges | | CID | 24 bits (6 hex) | - | Company identifiers, not assigned to network interfaces | ## How to find your own MAC address - **Windows:** run `getmac /v`, or open Settings → Network & internet → Hardware properties. - **macOS:** open System Settings → Network → Details, or run `ifconfig en0 | grep ether`. - **Linux:** run `ip link` and read the `link/ether` value. - **iPhone / Android:** open the Wi-Fi network details. The "private Wi-Fi address" shown there is randomized and will not resolve to a vendor. ## Vendors, countries, and former owners Besides prefix pages, the site pre-renders reference pages organized by the registration itself, each with its complete table: - **Vendor index** (`https://mac.jasontally.com/vendor`): every organization with two or more registered blocks, with block and address-space totals per organization, sorted by address space; each row links that organization's page. - **Vendor pages** (`https://mac.jasontally.com/vendor/{slug}`): every MAC block registered to one organization, with block types, address space, countries, and registration dates. - **Country index** (`https://mac.jasontally.com/country`): every country with at least one registered MAC address block, with organization, block, and address totals per country, sorted by address space; each row links that country's page. - **Country pages** (`https://mac.jasontally.com/country/{code}`): every organization with blocks registered in that country, sorted by address space. - **Former-owner pages** (`https://mac.jasontally.com/former/{name}`): organizations that no longer hold any of the prefixes once registered to them, showing what happened to each block, including acquisitions where one new owner took over all of them (for example [Apple Computer](https://mac.jasontally.com/former/apple-computer), whose blocks are now registered to Apple, Inc.). - **Registry, year, region, history, and successor pages**: additional dimensions with complete tables at `https://mac.jasontally.com/registry`, `https://mac.jasontally.com/year`, `https://mac.jasontally.com/region`, `https://mac.jasontally.com/history`, and `https://mac.jasontally.com/successor`; each index links its own detail pages. ## Frequently asked questions ### 1. Why does my MAC address show no vendor? Phones, tablets, and laptops often randomize their Wi-Fi MAC address per network. Randomized addresses set the locally administered bit and deliberately carry no manufacturer information, so no vendor can be resolved. Look up the hardware address from the device settings instead. ### 2. What is an OUI? The Organizationally Unique Identifier is the first three bytes (24 bits) of a MAC address. The IEEE Registration Authority assigns each OUI to one organization, which is why the prefix identifies the manufacturer. Modern registries also contain smaller MA-M (28-bit) and MA-S (36-bit) blocks. ### 3. What do MA-L, MA-M, MA-S, IAB, and CID mean? They are the IEEE assignment registries. MA-L is the classic 24-bit OUI with 16,777,216 addresses per block, MA-M is a 28-bit block with 1,048,576 addresses, MA-S and IAB are 36-bit blocks with 4,096 addresses each, and CID is a 24-bit company identifier that is not used for network interfaces. ### 4. Why does a MAC address show a company that no longer exists? MAC prefixes are registered once and are rarely reassigned when a company is acquired or renamed. The hardware keeps its original prefix forever, so the current registry entry may show the acquiring company. For example, Tekelec blocks now show Oracle. Prefix lineage on each result shows when those changes were observed. ### 5. What is prefix lineage? When a registered prefix changes hands or the organization name changes, this site shows a timeline of the organizations associated with that prefix and the dates the changes were first observed in public registration data. Lineage is shown only for the exact prefix, never inherited from a parent or child block. ### 6. Can a MAC address be spoofed? Yes. Operating systems and network tools can set any MAC address, including one that belongs to a registered vendor block. A lookup tells you which organization registered the prefix, not which device actually sent the traffic. ### 7. What is a locally administered address? The second-least-significant bit of the first octet distinguishes universally administered addresses (assigned by the IEEE to a vendor) from locally administered addresses (set by software). Randomized privacy addresses, virtual machines, and manual assignments are all locally administered. ### 8. Is this lookup private? Yes, for lookups you run on this website. The IEEE dataset is downloaded once and the search runs entirely in your browser: the addresses you type are never processed by a server. Normal website requests do still reach the host — opening a direct link such as mac.jasontally.com/apple sends that URL path to the CDN so it can serve the right static file, and the app fetches its public data files by URL — but the host only serves files and runs no search code. The app sets no cookies and does no tracking. The site is hosted on Cloudflare, which collects privacy-first, aggregate web analytics that use no cookies or client-side state and do not fingerprint individuals. One exception to the browser-only rule is the MCP server for AI assistants: it is an HTTP endpoint, so an address submitted there is visible to the host in the request. No session is created and no lookup is linked to anything else. The privacy policy describes that difference in full. ### 9. Does the vendor match identify the exact device? No. The prefix identifies the organization that registered the block, not a model or serial number. Many vendors use dozens or hundreds of prefixes, and contract manufacturers build devices for other brands. ### 10. How do I find my own MAC address? On Windows, run "getmac /v" or open Settings, then Network and Hardware properties. On macOS, open System Settings, Network, Details, or run "ifconfig en0 | grep ether". On iPhone and Android, open the Wi-Fi network details; the private Wi-Fi address shown there is randomized. ## Data sources and accuracy Current assignments come from the IEEE Registration Authority's MA-L, MA-M, MA-S, IAB, and CID registries, refreshed on every deploy. Historical changes come from [runZero mac-tracker](https://github.com/runZeroInc/mac-tracker) (MIT), which records when an organization name changed in the public data. Those dates are observation dates, not legal transfer dates, and the registries do not reassign most prefixes. An acquisition usually leaves the old vendor name on existing hardware forever. ## Using the data programmatically Two datasets are downloadable as machine-readable files: one JSON object per line, no keys or auth required: - [registry.ndjson](https://mac.jasontally.com/data/registry.ndjson) - every IEEE assignment (prefix, block type, organization, address, country, first-observed date). ~13.6 MB. - [lineage.ndjson](https://mac.jasontally.com/data/lineage.ndjson) - every ownership-change event with its first-observed date and historical registration country. For a single lookup you do not need the full registry. The fastest route is the MCP server, which resolves one address per call and returns the answer directly: - [https://mac.jasontally.com/mcp](https://mac.jasontally.com/mcp) - stateless [MCP](https://modelcontextprotocol.io) server over Streamable HTTP. No key, no auth, no session, no `initialize` handshake. One tool, `lookup`, that takes a MAC address or OUI prefix and returns the registered organization, block type, address count, country, and a link to the record page. Send `{"method":"tools/list"}` for the schema, then: curl -sS https://mac.jasontally.com/mcp -H 'content-type: application/json' \ -d '{"jsonrpc":"2.0","id":1,"method":"tools/call", "params":{"name":"lookup","arguments":{"mac":"8C:1F:64:AF:A4:B2"}}}' If your client cannot speak MCP, use the NDJSON downloads linked above and match the longest registered prefix yourself. The `https://mac.jasontally.com/data/mcp/` shards are an internal cache for the `/mcp` endpoint and are not a supported interface: most of them are keyed by the first 4 hex characters, but three dense ranges are keyed by 6, and that routing table is not published. A client guessing file names will get the site shell instead of a shard. The most recent registrations are listed on the [Latest OUIs](https://mac.jasontally.com/recent) page, refreshed on every deploy.