MAC Address Regex
Check six pairs of hex digits separated by colons or hyphens. A backreference makes sure the same separator is used all the way through.
One case per line; the m flag makes ^ and the end anchor work line by line.
Link optionspattern only
The address bar holds the pattern, flags and replacement, so Copy link shares them. Your test text stays out of it unless you include it (up to 2,000 characters), because it may be private. Nothing is sent to a server.
Matches
5matches
The first is “00:1A:2B:3C:4D:5E”, at position 0.
- Group
- 1
- Characters matched
- 85 of 185
What the pattern meansHover or tap a part to see it in the pattern and what it matched
How this works: Method, 4 sources, Checked against 1 worked example,
How this works
Method
Your pattern runs in your own browser’s JavaScript engine, in a background worker that is stopped after 1.5 seconds, so a pattern that backtracks catastrophically can’t freeze the page. The explanation comes from our own parser of the ECMAScript pattern grammar, checked against the engine; what each part matched is found by wrapping that part in one more group and running the pattern again. Conversions to other flavours only rewrite the syntax and list what their documentation says works differently.
Sources
How it’s tested
One worked example for this page is checked by automated tests before every release: given the inputs, the tool must show the expected answer.
Changes
- First published, with a library of 19 common patterns and their test cases.
Worked example
Take 00:1A:2B:3C:4D:5E, the first case in the tester. Reading the pattern left to right, each part takes its share of the text:
^The start of the text (matches a position, no characters)[0-9a-f]{2}Exactly two characters, each 0–9 or a–f (either case) matches 00([:-])Group 1: matches :(?:[0-9a-f]{2}\1){4}A group (not captured), exactly four times: matches 1A:2B:3C:4D:[0-9a-f]{2}Exactly two characters, each 0–9 or a–f (either case) matches 5E$The end of the text (matches a position, no characters)
How the MAC address regex works
A MAC address in the common notation is six octets, each written as exactly two hex digits. [0-9a-f]{2} reads one octet, and the i flag accepts both 5E and 5e.
The first separator is captured with ([:-]), so group 1 holds either a colon or a hyphen. Every later separator is \1, a backreference that must repeat whatever group 1 caught. That is why 00:1A-2B:3C:4D:5E fails: once the address starts with colons, a hyphen can no longer match.
(?:[0-9a-f]{2}\1){4} reads the second to fifth octets, each followed by the same separator, and a final [0-9a-f]{2} closes the address with no trailing separator. Six octets of eight bits each make the 48-bit identifier.
- An EUI-48 MAC address is a 3-octet Organizationally Unique Identifier followed by 3 octets assigned by the OUI holder, written as two hex digits per octet separated by hyphens. Source: RFC 7042, IANA considerations for IEEE 802 parameters, section 2.1.
- In the first octet, the bit with value 01 marks a group (multicast) address and the bit with value 02 marks a locally administered one. Source: RFC 7042, IANA considerations for IEEE 802 parameters, section 2.1.
Test cases
Every case runs as an automated test of this page’s pattern, so the table can’t drift from what the pattern really does.
| Text | Result | Why |
|---|---|---|
| 00:1A:2B:3C:4D:5E | Passes | colons, upper case |
| 00-1a-2b-3c-4d-5e | Passes | hyphens, the IEEE style, lower case |
| 01-00-5E-00-00-FB | Passes | a multicast address |
| aa:bb:cc:dd:ee:ff | Passes | letters only |
| 02:42:ac:11:00:02 | Passes | a locally administered address |
| 00:1A:2B:3C:4D | Fails | only five octets |
| 00:1A-2B:3C:4D:5E | Fails | colons and hyphens mixed |
| 001A.2B3C.4D5E | Fails | dotted groups of four, a different notation |
| 00:1G:2B:3C:4D:5E | Fails | G is not a hex digit |
| 001A2B3C4D5E | Fails | no separators |
| 0:1A:2B:3C:4D:5E | Fails | a single digit in the first octet |
What it doesn’t check
- Cisco-style dotted notation (001a.2b3c.4d5e) and bare 12-digit strings are common in device output but do not match; normalise them before testing, or add alternatives.
- The pattern says nothing about whether an address is unicast or multicast, or globally or locally assigned; those are bits in the first octet that you check in code.
- EUI-64 identifiers, with eight octets, need {6} instead of {4} in the middle.
The same pattern in other languages
Converted automatically from the JavaScript version; the tester above always runs JavaScript.
| Flavour | Pattern | Notes |
|---|---|---|
| Python | (?i)^[0-9a-f]{2}([:\-])(?:[0-9a-f]{2}\1){4}[0-9a-f]{2}\Z | |
| PCRE | (?i)^[0-9a-f]{2}([:\-])(?:[0-9a-f]{2}\1){4}[0-9a-f]{2}\z | |
| Go | not possible | Go’s RE2 has no backreferences. Capture the text and compare it in code.Go’s RE2 engine has no backreferences, so replace \1 with two alternatives: one written with colons throughout and one with hyphens. |
| Java | (?i)^[0-9a-f]{2}([:\-])(?:[0-9a-f]{2}\1){4}[0-9a-f]{2}\z | |
| .NET | (?i)^[0-9a-f]{2}([:\-])(?:[0-9a-f]{2}\1){4}[0-9a-f]{2}\z |
Sources
Frequently Asked Questions
Does the regex accept lower-case MAC addresses?
Yes. The i flag makes the hex digits case-insensitive, so 00:1a:2b and 00:1A:2B both pass. Normalise to one case before storing so comparisons work.
Why does it reject a mix of colons and hyphens?
The first separator is captured and every later one must repeat it. A mixed address is almost always a typing error, and rejecting it keeps stored addresses consistent.
How do I match the Cisco 0000.0000.0000 format?
Use three groups of four hex digits separated by dots, anchored at both ends. If you accept several notations, strip all separators and check for exactly twelve hex digits instead.