A MAC OUI lookup can identify the organization associated with a registered MAC address block. It cannot identify the person using a device, prove the device brand, reveal a live location, or show activity outside the local network.
Use the result as a hardware or network-management clue. The most reliable source is the IEEE Registration Authority's public listing, which maintains assignments for OUI and related MAC address blocks.
Quick MAC OUI lookup workflow
- Copy the MAC address from a router or device you are authorized to manage.
- Confirm that it contains 12 hexadecimal characters, usually displayed in six pairs.
- Check whether the address is locally administered or private before expecting a vendor match.
- Search the prefix in the IEEE Registration Authority public listing.
- Treat the organization name as a component or block-assignment clue, not owner identity.
- Compare the clue with your own device inventory and router connection details.
Do not paste network identifiers from systems you do not own into random lookup sites. For routine troubleshooting, the current IEEE registry and your own router are usually enough.
What OUI means
OUI stands for Organizationally Unique Identifier. In the familiar 48-bit MAC address format, the first 24 bits were traditionally associated with an OUI. IEEE now offers several assignment sizes, including MA-L, MA-M, and MA-S, so a modern lookup may need to consider more than one registry type.
A MAC address such as 80:7B:85:12:34:56 contains a prefix and a device-specific portion. A registry can connect the assigned block to an organization. The organization then uses addresses from that block in products or interfaces.
| Lookup clue | Reasonable interpretation | What it cannot prove |
|---|---|---|
| Registered organization | The block was assigned to that organization | The retail brand or exact model |
| Matching vendor prefix | The address fits a published assignment | Who owns or is using the device |
| No registry result | The address needs more checking | That the device is malicious |
| Locally administered address | The address may be generated or managed locally | The original hardware address |
| Router device name | A label supplied by a device or router | Verified identity of the user |
Why the vendor can look wrong
The registry result often surprises people. A television may show the name of a Wi-Fi chip maker. A laptop may expose a virtual adapter. A mesh-network node may use an address tied to a component supplier. A company can also acquire product lines or use manufacturing partners.
Common explanations include:
- The vendor made the network interface, not the finished device.
- The device uses a module purchased from another manufacturer.
- A virtual machine, container, VPN, or software bridge created an adapter.
- The router saved an old label after the device changed.
- The address is private or randomized.
- The lookup site's copy of the registry is outdated.
Use the vendor as one filtering clue. Device hostname, connection time, signal strength, assigned IP address, and your own inventory may provide better context on a network you control.
Private and randomized MAC addresses
Modern devices can use private Wi-Fi addresses to reduce tracking. Apple explains that its devices can use a different Wi-Fi address for each network and may rotate that address. Android also supports MAC randomization, including randomized addresses when connecting to Wi-Fi networks.
As a result:
- The address shown by your router may not be the factory hardware address.
- The same phone can appear with different addresses on different networks.
- A device can appear new after privacy settings or network settings change.
- A vendor lookup may return no useful match for a locally administered address.
- Router access rules based only on MAC addresses can require maintenance.
Randomization is a privacy feature, not evidence of intrusion. First check devices you control and their private-address settings.
How to recognize a locally administered address
The second-least-significant bit of the first octet indicates whether an address is universally or locally administered. In common hexadecimal notation, a first byte whose second character is 2, 6, A, or E often indicates a locally administered unicast address.
Examples include prefixes such as:
02:...26:...6A:...AE:...
This shortcut is useful, but it does not explain which device generated the address or why. Check the device and operating-system settings you manage.
A MAC address is not an IP address
MAC and IP addresses answer different networking questions.
| MAC address | IP address |
|---|---|
| Identifies a network interface on a local link | Identifies a network endpoint for IP communication |
| Usually visible to the local router or network segment | Can be private on a local network or public on the internet |
| May contain a registered vendor prefix | Does not encode a hardware vendor |
| Can be randomized or locally assigned | Can change through DHCP, mobile networks, or providers |
| Does not provide a public live location | Public IP geolocation is approximate and not person identity |
A MAC OUI lookup does not reveal browsing history, account ownership, a street address, or a person's name.
Troubleshoot an unknown device safely
If an unfamiliar client appears on a Wi-Fi network you own or administer:
- Check phones, tablets, watches, TVs, speakers, printers, cameras, consoles, and smart-home devices.
- Compare the first-seen time with when guests or new devices joined.
- Review whether trusted devices use private Wi-Fi addresses.
- Rename known clients in the router if that feature is available.
- Remove or pause the unknown client without confronting anyone.
- Change the Wi-Fi password if the device remains unexplained.
- Use WPA2 or WPA3, disable obsolete security modes, and update router firmware.
- Reconnect trusted devices intentionally and review the client list again.
MAC allowlists alone are not strong security because addresses can change or be copied. Use modern Wi-Fi encryption and a strong unique password as the foundation.
Privacy and responsible use
A vendor lookup is appropriate for inventory, troubleshooting, and security on systems you own or are authorized to administer. It is not a people-search tool. Do not use a MAC address to accuse a neighbor, employee, guest, or family member, and do not collect identifiers from networks you do not manage.
For a broader view of what technical and personal details can appear online, see what information is public online. The online privacy checklist covers practical exposure reduction, while this guide stays focused on local network identifiers.
Lookup Plainly does not operate a MAC-address database. Use the current IEEE registry and official device documentation for authoritative assignments and privacy behavior.
