Randomized MAC addresses
On a modern wireless network, many addresses are locally generated rather than factory-assigned. A vendor lookup often cannot identify their hardware manufacturer, and some addresses rotate over time. Here is how to recognize them and what to do instead.
One bit distinguishes local from universal
The second least significant bit of the first octet is the universal/local bit. Clear, and the address is universally administered, so an IEEE registry lookup may identify an assignee. Set, and the address is locally administered. Most randomized client addresses have no vendor assignment, but CID-backed local identifiers are an important exception.
Because that bit lives in the first octet, the second hex digit of a unicast address gives it away without any arithmetic. If it is
2, 6, A,
or E, the address is locally administered.
Illustrative addresses, not a capture from a real network:
00:1b:21:3c:4d:5e second digit 0 universally administered, registry lookup applies
a2:9c:44:7b:10:e3 second digit 2 locally administered, no hardware vendor implied
The local bit does not prove randomization: an administrator, virtual machine, or protocol can also assign a local address. A missing hardware vendor is therefore expected for many local addresses. CID prefixes are a separate kind of registration.
Who randomizes, and when
Randomization arrived in two waves. First for scanning, then for association, and the second wave is the one that changed network operations.
| Platform | Behaviour |
|---|---|
| iOS and iPadOS | A private address per network since iOS 14, on by default. iOS 18 and iPadOS 18 or later offer Off, Fixed, or Rotating per network. |
| Android | Randomized by default per network since Android 10. Persistent is the default; Android 12 and later use non-persistent mode only in certain configurations. |
| Windows | On supported Wi-Fi hardware, random hardware addresses can be enabled for all networks or for an individual network. Availability depends on the adapter and driver. |
| macOS | Private addresses in macOS Sequoia 15 and later. Secure networks default to Fixed; weak or open networks default to Rotating every two weeks; Off is available per network. |
| Linux | NetworkManager can scramble the scanning address and set a per-connection address, either random each time or stable per network. |
The word "random" oversells it in the common case. Android's default persistent address stays with a network until factory reset, even after forgetting and rejoining it. Apple Fixed mode does not rotate routinely, while Rotating mode changes the address every two weeks. Forgetting a network or resetting network settings can also change an Apple private address, subject to the platform’s retention rules. Other implementations and configurations follow their own schedules.
Separately, many modern clients scramble their address while scanning, before joining anything. This makes passive presence-counting from probe requests unreliable and can make a capture show more addresses than devices. Scanning and association are separate behaviours; an address seen in a probe request need not be the one used after joining.
Virtual interfaces can use local addresses too
A virtual interface can use either an IEEE-registered prefix or a locally administered address. The local bit cannot distinguish a phone’s private Wi-Fi address from an address generated by virtualization software or configured by an administrator.
Repeated prefixes can be useful clues when you already know the environment, but software can override them. A registry match identifies a prefix holder, not a physical device, hypervisor host, or operating system. Check the virtual machine or container configuration before turning a familiar-looking prefix into an inventory fact.
Structured local space has four quadrants
IEEE 802c defines an optional Structured Local Address Plan, or SLAP, that divides local unicast space into four quadrants selected by the same second hex digit. The labels describe addresses intentionally assigned under SLAP; they do not establish the source of an arbitrary randomized or legacy local address.
| Second digit | Quadrant | Meaning |
|---|---|---|
| 2 | AAI | Administratively assigned under SLAP; not based on a CID. |
| 6 | Reserved | Held for future use. |
| A | ELI | Extended local identifier, built on a CID the IEEE assigned to an organization. |
| E | SAI | Standard Assigned Identifier: assigned by a protocol specified in an IEEE 802 standard. Not every protocol-assigned address is an SAI. |
When the sender is known to follow SLAP, 2 denotes an AAI and
A denotes an ELI whose first 24 bits are an assigned CID. Ordinary randomizers need not follow
SLAP: Android, for example, randomizes all 46 bits beyond the universal/local and individual/group bits. The second digit alone therefore
cannot prove AAI, ELI, SAI, or reserved provenance. The
registries guide covers CID in detail.
Older equipment predates SLAP, and many current randomizers simply choose the other 46 bits. Treat the quadrants as a plan a sender may follow, not provenance you can infer from the digit alone.
What private addresses can break
| What can stop working | Why, and what to do |
|---|---|
| MAC filtering and MAC authentication bypass | A factory-address allow-list misses the private address, and a persistent entry fails after rotation or reset. Move to 802.1X, which authenticates the user or device rather than a number the device picks. |
| DHCP reservations | A MAC-based reservation works only while the client presents the same address. Where supported, use an authenticated or deliberately stable identifier; do not assume every DHCP client identifier is stable. |
| Captive portals and per-device quotas | After rotation, a returning device looks new. Tie sessions to accounts. |
| Asset inventories keyed on MAC | One device accumulates several identities over its life. Key on a serial number or an agent identity. |
| Counting devices from a wireless capture | Randomized scanning addresses can inflate the count. Associations are a better measure, but still count addresses. |
There is one mercy in all of this. Persistent modes keep the day-to-day picture inside a single SSID reasonably stable. What breaks is anything that assumed an address is a property of the hardware rather than of the relationship between a device and a network.
What still identifies a device
A randomized address takes away one weak identifier and leaves plenty of others in place:
Other signals can support correlation, but none is universal. DHCP hostnames and option lists may reveal a device name or operating system family. An 802.1X credential can identify an enrolled user or device, and network-supplied attachment data can identify location. IPv6 is not necessarily a stable companion identifier: clients may use both stable per-network and rotating temporary addresses.
In the other direction, a stable address proves less than it looks. MAC addresses can often be changed or spoofed in software, so an address matching an allow-list is not proof of identity. Randomized addresses are a privacy feature for people, not a security feature for networks, and a permanent address was never a security feature either.
What macs4days does with them
macs4days keeps local unicast addresses classified as [special] Locally Administered Address. The details explain the SLAP quadrant indicated by the bits. That classification does not prove that the address was generated randomly or assigned under SLAP.
For the ELI bit pattern (second hex digit A), the app checks the exact first 24 bits against its CID records. When a match exists, it shows the CID prefix registrant separately beneath the local-address classification. It does not use ordinary MA-L, MA-M, or MA-S vendor matching for local addresses. CID prefixes that collide with MA-L entries are excluded from attribution.
A random address can happen to begin with a registered CID. The displayed registrant names the organization assigned that prefix; it does not establish who generated the address or manufactured the hardware. No CID match also does not prove randomization.
Supported IP, hostname, VLAN, interface, and entry-type fields are still extracted from the surrounding text. Keep that context when investigating an address: the ARP guide and DHCP guide explain what those records can and cannot establish.
Sources and further reading
- Apple: private Wi-Fi addresses (opens in a new tab)
- Android: MAC randomization behaviour (opens in a new tab)
- Microsoft: Wi-Fi connections and random hardware addresses (opens in a new tab)
- NetworkManager: wireless connection settings (opens in a new tab)
- IEEE: EUI, OUI, and CID guidelines (opens in a new tab)
- RFC 9542: local address quadrants, section 2.3 (opens in a new tab)