A private network between your machines built on WireGuard: devices find each other wherever they are, with the key exchange and NAT traversal handled by a coordination service.
Do not build this — and check the free tier first, because it covers most people entirely. **NAT traversal that actually connects** is the product. Two machines behind different home routers establishing a direct connection, with a relay when they cannot, and coordination so it happens without any port forwarding, is genuinely difficult and it is the part everyone underestimates. WHEN TO KEEP PAYING - More devices or users than the free tier allows - Access controls per user and per service, which is what a team needs WHEN TO BUILD - **Plain WireGuard**, if your server has a public address. Then there is no traversal problem: your devices connect to it directly, and the configuration is a dozen lines. That is the honest answer for the common case of a VPS plus a laptop and a phone - **Headscale**, an open implementation of the coordination server, if you want the mesh behaviour on your own infrastructure. The clients stay the official ones, which is the sensible division WHY THIS IS ONE OF THE BEST WEEKENDS AVAILABLE Once your machines share a private network, nothing needs to be exposed publicly. The media server, the notes, the dashboards, the database — all reachable only from your own devices. That single change removes more risk than any amount of hardening, because a service nobody can reach is a service nobody can attack. WHAT TO DO WITH IT - Move every self-hosted service off the public internet and behind the network - Keep only what genuinely must be public — a website, a webhook endpoint — and put those behind a reverse proxy with proper headers - Use it for backups: a nightly copy to a machine at another location, over the private network, with no port open anywhere AND THE THING PEOPLE FORGET Key rotation and device removal. A laptop that was lost still has a key. Whatever you run, know how to revoke a device and do it once as a rehearsal. THE ONE-LINE VERSION Check the free tier. If you need your own, WireGuard covers a public server and Headscale covers the mesh — and either way, get your services off the public internet.
What you lose
- NAT traversal that gets two machines behind home routers talking directly, which is genuinely difficult networking
- Key distribution, device authorisation and single sign-on across a fleet
- Relay servers for the connections that cannot be made direct
If you would rather not build
- Plain WireGuard through one public hub
What it costs
read from their page 15 Aug 2026
| Plan | Billed monthly | Billed yearly | Last read |
|---|---|---|---|
| — | $8/mo | — | 15 Aug 2026 |
Their pricing page is where these came from. Seeing a different price? Tell us.
The escape hatch
open source · no votes, no paid placement
Headscale
$0An open coordination server that the official Tailscale clients connect to.
juanfont/headscalefree · open source
NetBird
$0An open mesh VPN with its own clients and a self-hosted control plane.
netbirdio/netbirdfree · open source
Why this verdict
our own opinion · changed only by a person
30/100
Verdict no at 30. WireGuard is free and easy; the coordination and NAT traversal are the product. Headscale is the honest middle route.
History
tracked since 10 Aug 2026 · nothing is ever overwritten
Questions about Tailscale
answered from the record above
Is Tailscale free?
No — the plan we track is $8 a month. Standard at $8 per user per month; Personal is free for up to six users, which covers a lot of households.
Can you replace Tailscale by building your own?
KEEP IT. The value is the network, the data or the infrastructure. Keep paying. Replacement score 30 out of 100, build time longer than it saves. Read what you lose before you decide.
How much does Tailscale cost?
$8 a month on Starter — $96 a year. Recorded 14 Aug 2026.
What do you lose by replacing Tailscale?
NAT traversal that gets two machines behind home routers talking directly, which is genuinely difficult networking; Key distribution, device authorisation and single sign-on across a fleet; Relay servers for the connections that cannot be made direct. If any of those carry weight for you, keep paying.
Is there an open-source alternative to Tailscale?
Yes: Headscale, NetBird. The prompt on this page is for when you want it your way instead.
Related entries
same category first, most replaced first
Every week, something stops being worth paying for.
New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.
free forever · no tracking pixel · stored here, never passed to anyone

