OUI and IEEE registries
A registered MAC address prefix can name an organization. How long that prefix is, and what its name tells you about a device, is what this guide is about.
The easy case, and why it misleads
Take 00:1b:21:3c:4d:5e. The first three octets,
00:1b:21, are registered to Intel Corporate, and every address under that prefix is Intel's to
hand out. Three octets in, one name out, done.
A lookup that assumes every assigned prefix is three octets long stops here. That assumption misses smaller allocations: the IEEE also assigns 28-bit and 36-bit prefixes, and the address has no length field telling you which one to use.
What an OUI actually is
An OUI, an Organizationally Unique Identifier, is a 24-bit value assigned by the IEEE Registration Authority. The product you buy to get one is called an MA-L, a MAC Address Block Large, and it includes 16,777,216 EUI-48 addresses that share those 24 bits.
In conversation, "the OUI" has drifted to mean "whatever part of this address identifies the vendor". That is a useful shorthand right up until the vendor part is not 24 bits long, at which point it is simply wrong. The rest of this guide uses OUI in the strict sense and "assigned prefix" for the loose one.
The five registries
macs4days uses five IEEE registries published as CSV files. Three of them are block sizes for sale today, one is closed, and one lives somewhere else entirely.
| Registry | Prefix | Hex digits | EUI-48 addresses | Who takes one |
|---|---|---|---|---|
| MA-L | 24 bits | 6 | 16,777,216 | Manufacturers shipping at volume. The classic OUI. |
| MA-M | 28 bits | 7 | 1,048,576 | Mid-size vendors. Sixteen of these fit in one MA-L. |
| MA-S | 36 bits | 9 | 4,096 | Low-volume and embedded products. |
| IAB | 36 bits | 9 | 4,096 | Closed to new assignments since 2014. Existing ones stay valid. |
| CID | 24 bits | 6 | n/a | Organizations needing an identifier without a universally unique MAC address allocation. |
MA-L is by far the largest of the five, holding roughly two thirds of all published records. MA-M and MA-S together account for most of the rest, IAB is a fixed historical set, and CID is tiny, in the low hundreds.
Why a short-prefix lookup can return the IEEE
The smaller blocks have to be carved out of something. The IEEE holds a set of OUIs itself and subdivides them, which means the 24-bit lookup of an address inside one of those pools returns the IEEE rather than a vendor:
70:b3:d5 IEEE Registration Authority (MA-L, an IEEE-held pool)
70:b3:d5:00:1 SOREDI touch systems GmbH (MA-S, 36 bits)
So 70:b3:d5:00:1a:2b is a SOREDI address, and a tool that reads six hex digits and stops will tell
you it belongs to the IEEE. That answer is not entirely wrong, which is what makes it dangerous: the prefix really is registered to the
Registration Authority, as a pool.
The same happens one size up. a4:11:63 is another IEEE-held pool, and
a4:11:63:0, a 28-bit MA-M, is Adetel Equipment. Other pools you will meet in the wild include
00:50:c2, 40:d8:55, and
8c:1f:64.
The rule that falls out of this is short: match the longest registered prefix, not a fixed number of octets. Try 9 hex digits, then 7, then 6, and take the first hit. Going the other way round finds the pool holder and never looks further.
You cannot see the boundary in the address
There is no flag, no length field, and no pattern that says how many bits of a given address were assigned. Two addresses that look structurally identical can split at 24 bits and at 36 bits. The registry is the only thing that knows, which is why a vendor lookup is a database question rather than a string operation.
This is also why the notation a device prints can quietly work against you. Cisco's
001b.213c.4d5e groups the address in fours, so the 24-bit boundary falls inside the middle group,
and the HPE style 001b21-3c4d5e splits exactly on 24 bits and so implies a boundary that may not
be the real one. The MAC address formats guide covers both.
IAB, the registry that ended but did not go away
The Individual Address Block was the original small allocation: 36 bits, 4,096 EUI-48 addresses, carved out of IEEE-held OUIs. The IEEE stopped issuing them at the start of 2014 and replaced the product with MA-S, which has the same EUI-48 block size and supports additional identifier types.
Existing IAB assignments were not withdrawn. They are still published, still valid, and still burned into equipment that is still racked and running, so any lookup that quietly skips IAB can miss vendor matches for thousands of registered prefixes. Practically, an IAB and an MA-S look the same in an EUI-48 lookup and are handled the same way: nine hex digits, then the device part.
CID, a registered prefix in the ELI quadrant
A Company ID is a unique 24-bit identifier, but it does not grant a block of universally unique MAC addresses. It can identify an organization in contexts such as protocol fields and locally administered addressing.
IEEE 802c's optional Structured Local Address Plan divides locally administered unicast space into four quadrants. CID assignments occupy the
Extended Local Identifier (ELI) quadrant, whose second hexadecimal digit is A. The other patterns
are 2 for administratively assigned (AAI), 6 for
reserved, and E for standards-assigned (SAI). Those bits describe a quadrant; they do not prove
how a particular address was generated.
For example, the CID registry lists 4a:19:1b for the ZigBee Alliance and
4a:07:d6 for the IEEE 802.1 Working Group. A randomizer can also produce an address starting with
either prefix. A match establishes who registered the prefix, not who generated the address or made the device.
Historical MA-L records also exist in local space. For example, 02:07:01 is listed for
RACAL-DATACOM, and aa:00:00 for DIGITAL EQUIPMENT CORPORATION. The latter even has the ELI bit
pattern, but it is not a CID assignment. Checking a mixed registry for a matching name is therefore insufficient: a CID lookup must also
establish that the prefix came from the CID registry.
Keep the locally administered classification even when a CID matches, and label the organization as the CID prefix registrant. That preserves the useful registry information without turning a possible coincidence into a claim about the device.
Why a lookup may not identify an organization
A lookup may return no organization, a special-address classification, or a placeholder such as "Private". These have different meanings:
| Reason | What it looks like |
|---|---|
| Locally administered | Second hex digit is 2, 6, A, or E. No hardware vendor is inferred; an exact registered CID match can identify the prefix registrant separately. |
| Never assigned | A prefix with no assignment in the published registry. |
| Group address | Multicast or broadcast. It identifies a protocol or an audience, not a device. |
| Withheld | The assignee asked the IEEE not to publish the name, so the record reads "Private". |
| Database unavailable | The required lookup data could not be loaded. Reconnect, check the database download status, and retry. |
| Too new | Assigned since the copy of the registry you are searching was published. |
| Mis-parsed | The address was split in the wrong place upstream, so you are looking up a prefix that never existed. |
"Private" deserves a note, because it surprises people who assume the registry is a complete public record. The IEEE lets an assignee pay to withhold its organization name and address, so some records use "Private" as a placeholder. The block is assigned; the assignee's identity is simply not publicly disclosed.
The registry names the registrant, not the manufacturer
Even a clean, unambiguous, longest-prefix match answers a narrower question than the one you probably asked. It tells you which organization registered the block. Between that organization and the box in front of you sit contract manufacturers, chipset reference designs shipped with the silicon vendor's prefix, white-label hardware rebadged three times, and modules soldered into someone else's product.
This is why so many laptops appear as Intel: the wireless interface may use Intel hardware even when Intel did not make the laptop. Treat the registered name as a clue about the interface's origin, not proof of who made the interface or the device. An address can also be overridden in software.
What macs4days does with all of this
macs4days uses all five registries, with database updates scheduled daily. The status panel shows the record count and the date of your database. Once the offline download finishes, lookups work without a network connection.
For ordinary universally administered unicast addresses, the lookup takes the longest registered prefix. MA-S and IAB use nine hex digits, MA-M uses seven, and MA-L uses six. An address in an IEEE-held pool therefore resolves to the smaller block's registrant when that assignment is available.
Locally administered addresses retain their locally administered badge and show their SLAP quadrant in the explanation. For an ELI-pattern address, macs4days checks the exact first six hex digits against prefixes confirmed to come from CID. A match appears on a separate line in the vendor cell, labeled "CID prefix registered to", and is included as a separate field in exports. It is not treated as a resolved hardware vendor. AAI, reserved, and SAI addresses receive no registry lookup.
Multicast, broadcast, and recognized protocol addresses receive their special-address classification. These labels and CID matches describe the address and its registered prefix; none authenticates the device using it.
Sources and further reading
The IEEE describes MAC address block sizes, Company IDs, and legacy IAB assignments and registry terminology. RFC 8948 explains the SLAP quadrants. The organization names in this guide were checked against the database dated 28 September 2026; registry names can change.