MAC Address Analyzer

Identify the vendor and decode any MAC address — OUI, cast and UAA/LAA.

Runs locallyWorks offlineShare link carries settings, never your data

Frequently asked questions

How is the manufacturer identified?

The first three bytes of the MAC (the OUI) are matched against the public IEEE OUI registry of roughly 40,000 vendor assignments. If a prefix isn't in the registry (or is locally administered), the tool says so rather than guessing. This lookup lets you instantly identify which vendor manufactured a network interface, useful for inventory tracking, security auditing, or understanding what devices are on your network. The OUI registry is the authoritative source for MAC vendor information and is updated regularly as manufacturers receive new allocations.

What do unicast/multicast and UAA/LAA mean?

The lowest bit of the first byte marks the address as unicast (one interface) or multicast (a group). The next bit marks it as universally administered (assigned by the manufacturer) or locally administered (set by software or a VM/hypervisor). Unicast addresses are used for normal device-to-device communication, while multicast addresses deliver packets to multiple devices at once (like Ethernet broadcasts). Locally administered addresses (LAA) are often used in virtual machines, while universally administered addresses (UAA) are burned into network interface hardware by the manufacturer and never change.

Is my MAC address uploaded?

No. Everything runs locally in your browser using standard web APIs — your text, files and inputs are never uploaded to a server, so the tool works even offline once the page has loaded.

Pro tips

  • Treat a missing vendor as information: it usually means the address is randomised, not that the lookup failed.
  • Check the individual/group bit before chasing an unfamiliar address — multicast and broadcast traffic uses addresses no device owns.
  • Use the vendor name to triage an unknown device on a home network; the manufacturer is often enough to recognise the smart plug you forgot about.
  • Do not rely on MAC filtering as a security control. Addresses are trivially spoofed, and randomisation means legitimate devices change theirs.
  • The Modified EUI-64 output is what you want when tracing how an IPv6 interface identifier was derived from hardware.

About MAC Address Analyzer

A locally administered bit is what phone MAC randomisation sets, which is why a vendor lookup returns nothing for many devices on a network scan. That is the feature working as intended rather than a failed lookup.

Every network interface has a 48-bit MAC address whose first 24 bits — the OUI (Organizationally Unique Identifier) — are assigned by the IEEE to a specific manufacturer. This analyzer looks that OUI up against the full IEEE registry to name the vendor, then decodes the rest of the address: it splits the OUI and NIC portions, reads the individual/group bit to tell you whether the address is unicast or multicast, and reads the universal/local bit to show whether it is universally administered (UAA, burned in) or locally administered (LAA, software-set).

It also normalises the address into every common notation — colon, hyphen, Cisco dot and bare — and derives the Modified EUI-64 interface identifier used in IPv6. The IEEE vendor database is fetched only when this tool is opened, so no other page pays for it.

The vendor lookup fails for a growing share of devices, and that is a privacy feature rather than a fault. Because a fixed hardware address let anyone track a phone as it passed within range of WiFi scanners, iOS and Android now present a different randomised address to each network. A randomised address sets the locally administered bit, so the analyser reports LAA and no manufacturer — which is the correct answer, and the reason MAC-based access control lists are no longer a dependable way to manage devices.

One structural point is worth holding on to: a MAC address does not travel beyond the local network segment. Routers rewrite the layer-two addressing at every hop, so the address a remote website sees is not yours and cannot be. That makes these addresses useful for auditing what is attached to your own network, and useless as a way for anyone on the internet to identify a particular machine.

Common use cases

  • Identifying an unrecognised device on a home or office network scan.
  • Network administrators confirming which vendor's hardware is behind an address in a switch table.
  • Support teams normalising an address between colon, hyphen and Cisco dot notation before pasting it into a different system.
  • Engineers deriving or checking an IPv6 EUI-64 interface identifier.
  • Anyone auditing a DHCP lease list and trying to attach names to hardware.
How it comparesNetwork scanners such as Fing or nmap discover devices and look up vendors in one pass, which is what you want for surveying a whole network. This is the single-address version: paste one you already have and get the full decode without installing anything.