Back to Utiliverse
Utiliverse Guides

All guides / Networking

Why devices use randomized MAC addresses

Understand private Wi-Fi addresses, locally administered bits, and why a vendor lookup cannot identify a person or prove randomization.

By UtiliverseLast reviewed: September 29, 2026

A link-layer address can become a tracking signal

A MAC address identifies an interface on a local network link. A device that repeatedly uses the same Wi-Fi address can present a stable identifier across observations. Private-address features reduce that consistency by using alternate addresses, often specific to a network and sometimes changing over time.

Apple documents private Wi-Fi modes and their behavior in its private Wi-Fi address guidance. Android also documents MAC randomization. The exact controls and rotation rules depend on the operating system, version, and network configuration; do not assume every phone changes its address on every connection.

What a lookup can infer from the bits

The low two bits of the first octet indicate individual/group addressing and universal/local administration. The locally administered bit is compatible with a private or manually assigned address, but it does not record why the address was chosen. A virtual interface or administrator can also use that bit.

Interpret the evidence narrowly
ObservationReasonable conclusionDoes not establish
Locally administeredThe local bit is setA phone generated it randomly
Vendor prefix foundA registry block is associated with an organizationDevice model, owner, or current location
No vendor foundThe lookup has no matching resultA malicious or nonexistent device

Worked example: 02:11:22:33:44:55

The first octet is hexadecimal 02, or binary 00000010. Its local bit is set and its group bit is clear, so this illustrative address is locally administered and unicast. A manufacturer inferred from its first three octets would not reliably identify the hardware behind it. In the tool, inspect the address characteristics even if the remote vendor lookup finds nothing.

Now compare a vendor-assigned address from a device you administer with that device’s address shown for a particular Wi-Fi network. A difference can be expected when a private-address feature is enabled. Keep the network context with your notes; the same device may use another address elsewhere.

Keep inventory useful without defeating privacy

  1. Confirm which network and interface produced the observation.
  2. Check the device’s own Wi-Fi details and your authorized network-management records.
  3. Use authenticated enrollment or another managed identifier when stable asset identity is required.
  4. If DHCP reservations depend on a MAC address, account for the address actually used on that network and the device’s supported private-address mode.
  5. Investigate repeated changes in context rather than treating every new address as a new physical device.

A MAC allowlist alone should not be treated as strong identity verification. Addresses can be changed, and network access controls need their own authentication design.

What the Utiliverse tool sends

Formatting and address-bit checks run in the browser. Vendor lookup sends the entered address or prefix to an external service and may use a fallback provider. Use a prefix when you only need organization information and do not need to submit the device-specific suffix. The tool cannot find someone’s location, access a remote device, or reveal the original hardware address hidden behind a private address.

When reporting an inventory issue, include the lookup outcome and the relevant network context. Avoid treating a registry organization’s country or postal address as the physical location of the device being investigated.

Try the related tools

Continue reading

Sources and review

Examples are illustrative. Reviewed September 29, 2026 against the listed references and the related tool behavior. Methodology · Report a correction.