Tailscale

A mesh VPN built on WireGuard: every device you own joins 1 private network and reaches the others directly, with no ports to open and no VPN server to run. Free for personal use.

Tailscale puts all your devices on 1 private network, wherever they are. Your laptop in a hotel, your phone on 5G, the Mac Studio at home and a server in the cloud all see each other as if they sat on the same desk. There's no router to configure and no port to open: you install the app, sign in, and the device joins your tailnet.

It started as a better VPN for developers. Today it sells itself as connectivity for everything, including AI agents, but the personal use is still the best way in.

Tailscale banner: the Tailscale logo of 9 dots in a 3 by 3 grid and the lowercase wordmark tailscale in white, on a dark grey background

Company Tailscale Inc., founded in 2019, headquartered in Toronto
Founders Avery Pennarun (CEO), David Crawshaw, David Carney and Brad Fitzpatrick
Funding $160M Series C in 2025, about $275M raised in total
Customers 40,000 businesses, per Tailscale
Protocol WireGuard, with Tailscale's own coordination and relay layer
Platforms macOS, iOS, Windows, Linux, Android, Apple TV, routers (OpenWrt, GL.iNet), NAS, Docker, Kubernetes
Open source The clients are open source. The coordination server is closed, but Headscale is an open-source replacement

What it does

Feature What it gives you
MagicDNS Every device gets a name, so ssh studio works instead of an IP address
Subnet router 1 device shares a whole home network, so the NAS and printers are reachable without installing Tailscale on them
Exit node Route all your internet traffic through a chosen device, for example home, when on hotel Wi-Fi
Mullvad exit nodes An add-on that routes traffic through Mullvad VPN servers in other countries
Tailscale Serve Share a local web app, such as a dashboard on port 9000, with your own devices over HTTPS
Tailscale Funnel Publish a local service to the public internet through Tailscale, without opening a port
Taildrop Send files between your devices, like AirDrop across platforms
Tailscale SSH SSH into machines with your Tailscale identity instead of managing keys
Access controls Rules in 1 policy file decide which device or user can reach what

For business people

The problem: classic VPNs send all traffic through a central gateway. They're slow, fiddly to set up, and once you're in, you can usually reach everything.

What Tailscale changes: devices connect directly to each other, encrypted, and each connection is checked against your identity and your rules. Remote staff, servers in different clouds and office equipment join the same private network in minutes. That's what the industry calls zero trust: nothing is trusted just because it's on the network.

Where it fits: remote access to internal tools, admin access to servers without a bastion host, connecting cloud and on-premise systems, and more and more, giving AI agents controlled access to internal data.

Pricing

Plan Price For
Personal Free Up to 6 users, unlimited devices, nearly all features
Standard $8 per user per month Teams: unlimited users, SCIM, device posture checks
Premium $18 per user per month Just-in-time access, advanced SSH, network flow logs
Enterprise Custom Contracts, SLAs, invoicing

The limits:

  • A North American service. Your traffic is end-to-end encrypted between devices, but the coordination servers that manage keys and devices belong to Tailscale. For full control, Headscale replaces them with a server you run yourself.
  • It's not a privacy VPN by default. Your traffic only leaves through another country if you add exit nodes.
  • Corporate networks can block it, which is a common reason it fails on a work laptop.

For technical people

How a connection works:

  1. Coordination: each device registers its WireGuard public key with Tailscale's coordination server, which distributes keys and policy to the other devices.
  2. NAT traversal: devices punch through firewalls and NAT to connect peer to peer. Most connections end up direct.
  3. DERP relays: when a direct path is impossible, traffic goes through Tailscale's relay servers, still end-to-end encrypted.

Typical commands:

tailscale up                          # join the tailnet
tailscale status                      # list devices and how they connect
tailscale up --advertise-exit-node    # offer this machine as an exit node
tailscale serve --bg 9000             # share localhost:9000 with your tailnet over HTTPS
tailscale funnel 9000                 # publish it to the internet instead
tailscale file cp report.pdf phone:   # Taildrop a file to another device
  • Identity: sign-in goes through an existing provider: Google, Microsoft, GitHub, Apple or an OIDC provider.
  • Access rules: a JSON-based policy file with grants, groups and tags.
  • Tagged and ephemeral devices: for servers and CI jobs, which join without a person's identity and disappear when done.
  • On a router: the GL.iNet Brume 2 runs Tailscale natively, so the whole LAN can sit behind 1 subnet router.

Value

My home setup is a set of machines that only make sense together: the Mac Studio running NicAI and my local apps, the NAS, the Linux mini PC, and the GL.iNet gear. Tailscale is the simplest way to reach all of it from my phone or a hotel without opening a single port.

The first use I'd set up: tailscale serve for my local app dashboard on port 9000, so I can start and stop my tools from the phone. The second: the Brume 2 as subnet router, so the NAS is reachable without installing anything on it (see GL.iNet Brume 2 (GL-MT2500) ). For remote control of machines, the same idea sits behind the IP-KVM setup in GL.iNet Comet KVM .

Further Reading

NicAI
Written by NicAI, Nic's AI assistant, for his personal knowledge base. Researched and drafted by the model, not hand-written by Nic. Verify anything you plan to act on.