iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
A message authentication code (MAC) is a fixed-length value created from a message and a secret key shared by the sender and receiver. The sender sends the message with its MAC; the receiver uses the same key to verify the tag. A valid match helps show that the message was not altered and that it came from someone able to use the shared key.
How does a message authentication code work?
- Share and protect a secret key. The sender and receiver must have access to the same secret key.
- Create a tag. The sender runs the message and key through a MAC algorithm, producing a fixed-length tag.
- Send the message and tag. The tag accompanies the message; it does not conceal the message contents.
- Verify the tag. The receiver uses the shared key and the received message to verify the tag. If verification fails, the receiver rejects the message as unauthenticated or altered.
The key makes a valid tag difficult for someone without the key to predict for a new message, even if that person has observed tags for other messages, within the algorithm’s supported security level. NIST describes the role of MACs in its Message Authentication Codes project.
What does a MAC protect—and what does it not prove?
Integrity and data origin within a shared-key group
A successful check supports the conclusion that the message has not changed since a valid tag was created and that the tag was generated by someone able to use the shared key. This is data-origin authentication in the context of the parties that share that key.
Recommended Free Tools
Not confidentiality or public proof of authorship
A MAC alone does not encrypt a message, so it does not hide the contents. It also cannot establish to an outside observer which particular key holder created a valid tag: any party with the shared key can generally generate one. For that reason, a MAC does not provide non-repudiation. A digital signature uses a private signing key and a corresponding public verification key, allowing verification without giving verifiers the ability to create signatures.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How is a MAC different from a hash?
A hash function maps data to a digest without requiring a secret key. A hash can help detect differences if the expected digest is trusted separately, but a plain hash does not authenticate who supplied the message: an attacker who changes the message could also calculate a new hash. A MAC combines the message with a shared secret, making valid-tag generation dependent on access to that key.
What are HMAC, KMAC, and CMAC?
NIST identifies HMAC, KMAC, and CMAC as approved general-purpose MAC algorithm families. They use different underlying constructions, so selection should follow the protocol’s requirements and applicable standards rather than an assumption that one is universally faster or safer.
Rank #2
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
| Family | Construction | Reference |
|---|---|---|
| HMAC | Uses a cryptographic hash function with a shared secret key. | NIST FIPS 198-1 |
| KMAC | A keyed hash based on KECCAK; includes KMAC128 and KMAC256 variants. | NIST SP 800-185 |
| CMAC | Based on a symmetric-key block cipher, such as AES. | NIST SP 800-38B |
NIST’s MAC project page also lists GMAC, an authentication-only specialization of GCM. It is another option in the authenticated-encryption family, not a reason to treat ordinary MACs as encryption.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →What should you consider when using a MAC?
- Protect the key. A MAC depends on the shared secret remaining confidential. Anyone who obtains it can create valid tags.
- Use the protocol’s specified algorithm and parameters. The correct choice depends on the protocol and applicable standards; do not substitute an algorithm or parameters without checking those requirements.
- Use a vetted cryptographic implementation. Rely on the platform or library’s verification function rather than implementing MAC calculations yourself. Verification should use the implementation’s appropriate comparison method.
- Do not mistake a valid MAC for encryption. If message contents must be hidden, a MAC by itself is insufficient; use the cryptographic construction required by the protocol.
What is the current status of NIST’s MAC standards?
Standards status can change. NIST published FIPS 198-1, its HMAC specification, in July 2008. A NIST planning note dated June 23, 2025 proposed withdrawing it and moving the specification to SP 800-224; that note describes a proposal, not confirmation that the transition is complete.
Rank #3
- Passwordless World - A revolutionary new way to protect your account info. By being FIDO2 certified by the world’s largest ecosystem for standard-based, interoperable authentication, FIDO2 makes everyday log-in experience effortless and passwordless yet more secure than generic password style security. **Note: FIDO2 does NOT support Mac log-in.
- Online Account Protection - FIDO2 key is backward compatible with U2F protocol and works with the newest Chrome browser with operating systems such as: Windows, macOS, or Linux. U2F can be supported and protected on all websites that follow U2F protocols.
- Multi-factored Authentication - Built-in, advanced HOTP (One Time Password) technology that completes the unique multi-factored authentication process. Eliminate worry and help prevent losing your account info to theft, phishing, hacking, or other online scams. Note: Only Enterprise Users using Azure Active Directory can access Windows Hello log-in via Thetis FIDO2 Security Key.
- Compact And Durable - 360° design with rotating aluminum alloy cover that shields the USB connector when not in use. Tough and durable alloy protects FIDO2 key from daily wear-and-tear, accidental drops, and scratches.
- Portable Design - ultra-portable design allows you to take your FIDO key anywhere you need it.
NIST SP 800-38B specifies CMAC. Its publication page records an original publication date of May 2005 and an update dated October 6, 2016. A planning note dated April 10, 2025 says NIST decided to revise the publication, but the page does not establish that a revised final version has appeared. Check the linked NIST pages for the latest publication status before relying on a specific standards edition.
Quick Recap
Best Value
- Ultra-Compact FIDO2 Security Key – Plug-and-stay or carry on a keychain. This USB-C hardware security key offers portable, always-on protection for desktop and mobile use.(Item Size: 0.73 X 0.60 X 0.30 inches)
- USB-C Hardware Key for All Devices – Works with USB-C ports on PC, Mac, Android, and USB-C iPhones. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key – Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey – Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication – Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Rank #4
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

