Guide ยท Tools compared
MAC Vendor Lookup Tools Compared: IEEE, macvendors.com, Wireshark, and This Site
Every MAC vendor lookup option traces back to the same five IEEE registries. Where they differ is how current the data is, what shape it comes in, and what happens once you're doing more than one lookup by hand.
There is only one source of truth for MAC vendor data: the IEEE Registration Authority's own MA-L, MA-M, MA-S, IAB, and CID registries. Every tool below reads from that same source, directly or indirectly. What actually differs between them is how often they resync, what format they hand back, and whether they're built for a person doing one lookup or a system doing thousands.
At a glance
| Update cadence | Format | Works offline | No account | |
|---|---|---|---|---|
| IEEE's raw registry files | Live, but unparsed | Fixed-width text, one file per block type | No, needs a fetch first | Yes |
| macvendors.com API | Unpublished | Plain text, JSON on error | No | Yes, 1,000/day |
| maclookup.app API | Regularly updated, with a per-record date | JSON, XML or JSONP; free database downloads | No (downloads work offline) | Yes, shared limits; new API keys are no longer issued |
| Wireshark / tshark (built-in) | Frozen at the Wireshark release | Vendor label on-screen, or a local manuf file | Yes, once installed | Yes |
| nmap (built-in) | Frozen at the nmap release | Vendor label on-screen, or the bundled data file | Yes, once installed | Yes |
| macadress.com web / keyless endpoint | Twice daily | Plain text or a rendered page | No | Yes, 1,000/day |
| macadress.com CSV / JSON downloads | Twice daily | CSV or JSON, full block list | Yes, once downloaded | Yes |
| macadress.com keyed API / self-hosted | Twice daily | JSON, with OUI, block, country, randomization | Self-hosted only | Free key required |
IEEE's own registries
Nothing beats going straight to standards-oui.ieee.org for authority, since it's the actual source, not a copy. The tradeoff is that it's five separate files with no unified schema, fixed-width text meant for a parser rather than a person, and no country, no address, and no help telling a /24 MA-L block apart from a /28 MA-M block carved out of someone else's /24. Worth reading directly if you're auditing a third-party tool's data. Not worth reaching for on a normal day.
macvendors.com
A long-running free API: one path, one MAC, a plain-text vendor name back, no key. It's the right call if you're already integrated, under its 1-per-second limit, and only ever need the name. See the migration guide for the handful of things that differ if you outgrow it: a tighter rate limit, a JSON error body instead of plain text on a miss, and no way to tell an unregistered address from a privacy-randomized one.
maclookup.app
A free API and database download that returns the vendor, address, country and block range as JSON, XML or JSONP, with a per-record update date. It no longer issues new API keys; the API works without one under shared rate limits. It's a good fit if you're already integrated and inside those limits. See the comparison and field-by-field migration guide if you want batch lookups, a randomization analysis or a self-hosted option.
Wireshark and nmap's built-in tables
Both ship a vendor table so you get a name for free while you work, no network call needed. Both also freeze that table at whatever IEEE looked like on the day that release was cut. Wireshark compiles its default table into the binary as of the 4.2 line; nmap's nmap-mac-prefixes is a plain data file. Either one can drift months behind IEEE between upgrades, which is the whole reason the Wireshark and nmap guides on this site exist: both tools accept a replacement file without needing a new release.
macadress.com
Where this fits depends on how many lookups and how much detail. The web lookup and the keyless /v1/vendor/:mac endpoint match macvendors.com's shape (free, no key, name only) but on a per-minute limit instead of per-second, and tell a privacy-randomized address apart from a genuinely unregistered one. A free key adds the keyed JSON API: OUI, IEEE block type, country, randomization confidence, a best-effort vendor-level device category, virtualization and special-use flags, and batch lookups. For a bulk job or an offline environment, the CSV and JSON downloads carry the full registry, resynced twice a day, no per-request call at all. And for traffic that can't leave the network, self-hosting runs the same engine on your own infrastructure.
Which one to actually reach for
- One address, right now, in a browser: the web lookup or macvendors.com. Either works; this one also flags randomization.
- Already have a capture open in Wireshark or a scan running in nmap: the built-in label is fine for a quick read. Refresh the underlying file (Wireshark, nmap) if it's guessing wrong on anything assigned in roughly the last year.
- A script doing a handful of lookups a day: the keyless endpoint on either service.
- A batch job, an offline environment, or anything that would rather hold the whole list in memory: the CSV or JSON download.
- A live path, production traffic, or anything that needs more than a name: the keyed JSON API, or self-hosted if the lookup can't leave your network.
More guides