DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
Cupertino desk4 min

What Is a Message Authentication Code (MAC), and How Does It Work?

A message authentication code uses a shared secret key to create and verify a tag that checks message integrity and origin within the key-sharing group.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A message authentication code (MAC) is a fixed-length cryptographic tag made from a message and a secret key shared by the sender and receiver. The receiver uses that key to check the tag: a mismatch means the message or tag is not valid. This provides integrity and authentication within the group that knows the key, but it does not hide the message or prove to outsiders which key-holder created it.

How a message authentication code works

A MAC system has two inputs: the message and a secret key. The sender runs them through a MAC algorithm to produce a tag, then sends the message and tag. The receiver uses the same key and algorithm to verify the received pair. If verification fails, the receiver rejects it as unauthenticated or altered.

As an Amazon Associate I earn from qualifying purchases.

  1. Share and protect a key. The sender and receiver must have access to the same secret key through a secure key-management process.
  2. Generate a tag. The sender computes a MAC over the message using the agreed algorithm and key.
  3. Send the pair. The message and its tag travel together; the MAC does not encrypt the message.
  4. Verify before trusting. The receiver checks the tag with the same key and accepts the message only if verification succeeds.

A secure MAC is designed to make it computationally infeasible for someone without the key to predict a valid tag for a new message, even after observing tags for other messages, within the algorithm’s supported security level. Use a vetted cryptographic implementation and the parameters required by the relevant protocol.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What a MAC proves—and what it does not

A valid tag provides evidence that the message has not changed since a party with access to the shared key generated the tag. It authenticates the message’s origin only in that shared-key context: every party holding the key can generally create valid tags. Consequently, a MAC alone cannot prove to an outside observer which participant authored a message, and it does not provide non-repudiation.

  • Integrity: a change to the message should cause verification to fail.
  • Shared-key data-origin authentication: a valid tag indicates that someone able to use the shared key generated it.
  • Not confidentiality: the message remains readable unless it is separately encrypted.
  • Not public authorship proof: the verifier also possesses the key and could generate a tag.

MAC vs. hash vs. digital signature

These mechanisms address related but different needs. A hash is unkeyed, a MAC uses a shared secret, and a digital signature uses a private signing key with a corresponding public verification key.

Mechanism Key arrangement What verification establishes
Cryptographic hash No secret key is required. It produces a digest for data. A digest alone does not authenticate who supplied the data; the expected digest must be trusted separately.
MAC Generating and verifying parties share a secret key. Integrity and data-origin authentication among parties able to use that key.
Digital signature The signer uses a private key; others can verify with a public key. Can support public verification, unlike a shared-key MAC.

Choose according to who must verify the message and what the evidence needs to show. If only parties sharing a secret need to check integrity and origin, a MAC may fit. If independent parties need to verify a signer without possessing the signing secret, a digital-signature scheme addresses a different requirement.

Common MAC algorithm families

NIST identifies HMAC, KMAC, and CMAC as approved general-purpose MAC algorithms. They use different underlying constructions, so follow the algorithm and parameters specified by the protocol rather than treating the families as interchangeable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Family Construction NIST reference
HMAC A cryptographic hash function used with a shared secret key. FIPS 198-1
KMAC A keyed hash based on KECCAK; variants include KMAC128 and KMAC256. SP 800-185
CMAC A MAC based on a symmetric-key block cipher, such as AES. SP 800-38B

HMAC

HMAC combines a hash function with a secret key. NIST FIPS 198-1, published in July 2008, specifies HMAC. NIST’s June 23, 2025 planning note proposed withdrawing FIPS 198-1 and moving the specification to SP 800-224; that note describes a proposal, not confirmation that the transition is complete. See NIST’s FIPS 198-1 publication page for status.

KMAC

KMAC is based on KECCAK and is specified in NIST SP 800-185, which defines KMAC128 and KMAC256. Consult the standard and the protocol’s requirements for the appropriate variant and parameters.

CMAC

CMAC uses a symmetric-key block cipher construction. NIST SP 800-38B specifies CMAC; its publication page lists May 2005 as the original publication date and October 6, 2016 as the update date. On April 10, 2025, NIST noted that it had decided to revise the publication. The page does not establish that a revised final version has appeared: NIST SP 800-38B.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

MACs and authenticated encryption

A MAC by itself protects integrity and supports shared-key authentication; it does not encrypt content. Some authenticated-encryption constructions can be specialized for authentication-only use. NIST calls the authentication-only specialization of GCM GMAC. See NIST’s Message Authentication Codes project for its overview and references.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What to check when choosing or implementing a MAC

  • Use the MAC family and parameters required by the applicable protocol and current standards.
  • Use a vetted cryptographic library rather than designing a construction yourself.
  • Keep the secret key protected and restrict access to parties that need to generate or verify tags.
  • Use the implementation’s verification function to check received tags before acting on the message.
  • Check current standard and validation status: NIST’s MAC project page links to references and Cryptographic Algorithm Validation Program resources.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.