Three sizes of assignment
The IEEE does not only issue 24 bit prefixes. MA-L is 24 bits, MA-M is 28 and MA-S is 36. A smaller block can sit inside a larger one, so the longest match is checked first and the result says which registry answered.
Paste a hardware address and see which organisation the IEEE assigned that prefix to. Any format is fine, with colons, dashes, dots or nothing at all.
How to read an address
A MAC address is 48 bits, written as six pairs. The first three pairs, 24 bits, are the OUI and belong to one organisation. The last three are chosen by that organisation, which is why two devices from the same maker usually agree on the first half and differ in the second.
The IEEE does not only issue 24 bit prefixes. MA-L is 24 bits, MA-M is 28 and MA-S is 36. A smaller block can sit inside a larger one, so the longest match is checked first and the result says which registry answered.
The low bit of the first octet marks multicast, a group rather than a device. The second lowest marks a locally administered address, which is what a randomised phone address is. Neither is registered, and neither is a lookup failure.
Expectations
The prefix belongs to whoever registered it, which can be a chipset maker or a contract manufacturer rather than the brand printed on the case.
A virtual network adapter carries the prefix of the platform hosting it, so it resolves to the hypervisor vendor rather than to any physical hardware.
This reads a public registry of prefixes. It cannot tell you where a device is, who owns it or what it has been doing, and a randomised address deliberately carries none of that.
No vendor found
Not the way IPv4 has one. There is no reserved block of MAC addresses set aside for private use. The mechanism is a single bit, the second lowest of the first octet, and it marks the address as locally administered. Any software may set it.
Once that bit is set the address is not globally unique, so the IEEE never allocates it and no vendor can be registered against it. A randomised phone address uses it. So do most virtual machines and containers. Seeing nothing in the registry for one of those is the correct answer, not a fault.
Whether a virtual adapter resolves depends entirely on which prefix the platform chose. A hypervisor using a registered block reports its vendor by name, which is usually how you find out a machine is virtual in the first place. The ones below all resolve here.
| Prefix | Registered to | Platform |
|---|---|---|
| 00:0C:29 | VMware, Inc. | VMware |
| 00:15:5D | Microsoft Corporation | Hyper-V |
| 00:16:3E | Xensource, Inc. | Xen |
| 08:00:27 | PCS Systemtechnik GmbH | VirtualBox |
| BC:24:11 | Proxmox Server Solutions GmbH | Proxmox |
Others deliberately use a locally administered prefix, so they never resolve. QEMU defaults to 52:54:00 and Docker uses 02:42. Neither appears in the registry, and neither ever will.
Next
A vendor name is usually the start of a question about a device you cannot identify. The next step is usually to find out whether it is answering at all.