Short answer: In Tailscale vs WireGuard, WireGuard is a VPN protocol and a free, open-source tool. You configure every tunnel yourself, and usually one side needs a reachable UDP port. Tailscale is a service built on WireGuard that handles keys, NAT traversal and access rules for you, so devices connect without port forwarding. Tailscale’s free Personal plan covers up to 6 users with unlimited user devices, for non-commercial use. Paid plans start at $8 per user per month. Use plain WireGuard for a simple fixed tunnel you control end to end. Use Tailscale to link many devices across networks with little setup. Headscale is a community project that replaces Tailscale’s coordination server if you want to self-host it.
What WireGuard is
WireGuard describes itself as “an extremely simple yet fast and modern VPN that utilizes state-of-the-art cryptography.” It started in the Linux kernel and is now available for Windows, macOS, BSD, iOS and Android.
It works like SSH keys. Each device has a private key, and you give each peer the other’s public key and the addresses it’s allowed to use. WireGuard then carries encrypted IP packets over UDP.
What WireGuard deliberately leaves out matters just as much. Its own site says: “All issues of key distribution and pushed configurations are out of scope of WireGuard.” You create keys, write config files and copy them to each device yourself. From WireGuard’s “Known Limitations” page:
- It “explicitly does not support tunneling over TCP.”
- It “does not focus on obfuscation,” so networks that block VPN traffic can block it.
WireGuard’s kernel components are licensed under the GPLv2, and its other projects use MIT, BSD, Apache 2.0 or GPL. It costs nothing. Official apps and packages are linked from wireguard.com and on our WireGuard app page.
What Tailscale is
Tailscale’s documentation describes it as a way to connect devices across networks using “the open source WireGuard protocol.” Instead of routing everything through one central server, Tailscale builds “a peer-to-peer mesh network (known as a tailnet).” You can still send all your traffic through one device, called an exit node, like a traditional VPN.
Tailscale’s “About WireGuard” page lists what it adds on top: NAT traversal, TCP transport capabilities and access control policies. Its overview says connections “work seamlessly across firewalls and Network Address Translation (NAT) without requiring port forwarding or complex firewall rules.” You sign in on each device and they find each other.
When two devices can’t connect directly, Tailscale relays their traffic, first through peer relays you set up, then through its own DERP relay servers. Tailscale says traffic through DERP is encrypted with WireGuard and its private keys “never leave the local device,” so a DERP server “blindly forwards already-encrypted traffic.”
How open is it? Tailscale’s open-source page says the client is “mostly open source.” The daemon is open source on every platform, but the GUI is closed source on Windows and macOS. The DERP relay servers are open source. The coordination server, which hands out keys and addresses, is closed source.
Tailscale pricing and free-tier limits
From Tailscale’s pricing page on September 26, 2026:
| Plan | Price | Users | Notable limits |
|---|---|---|---|
| Personal | $0, “Free forever” | Up to 6 | Unlimited user devices, up to 3 ACL groups, 50 tagged resources, 1,000 minutes a month of ephemeral resources |
| Standard | $8 per user per month | Unlimited | Up to 10 ACL groups, SCIM user provisioning |
| Premium | $18 per user per month | Unlimited | Up to 300 ACL groups, 10,000 ephemeral minutes a month, priority support |
| Enterprise | Custom | Custom | Premium support, custom agreements |
Tagged resources, such as servers or exit nodes that aren’t tied to a person, are included up to 50. Tailscale charges $1 a month for each one beyond that.
The key condition on the free plan is use. Tailscale says the Personal plan “is only suitable for non-commercial use.” It lists homelabs, home VPNs, gaming with friends and connecting a Raspberry Pi or home camera as examples. How you sign up decides your plan: a tailnet created with a Gmail, Apple or personal GitHub account is treated as personal, while one created with a custom email domain is treated as business use and starts a 14-day free trial. You can opt out of the trial, but Tailscale notes the Personal plan still isn’t meant for commercial use.
Tailscale vs WireGuard side by side
| WireGuard | Tailscale | |
|---|---|---|
| What it is | VPN protocol and tools | Networking service built on WireGuard |
| Cost | Free | Free Personal plan; paid from $8 per user per month |
| Key management | Manual | Automatic, through Tailscale’s coordination server |
| Port forwarding | Usually needed on at least one side | Not needed |
| Behind NAT | Works with persistent keepalive set | NAT traversal built in, relays as fallback |
| Topology | Whatever you configure | Mesh by default |
| Accounts | None | Sign-in through an identity provider |
| Self-hosted control | Fully self-hosted | Coordination server is Tailscale’s, or use Headscale |
| Source code | Open source | Mostly open client, closed coordination server |
On NAT: WireGuard’s quick start explains that a peer behind NAT or a firewall that wants to receive incoming packets must keep the mapping alive by sending keepalives. It suggests an interval of 25 seconds. You still need at least one peer the other can reach, which at home usually means forwarding a UDP port on your router.
Self-hosting: Headscale
If you like Tailscale’s clients but don’t want to depend on Tailscale’s servers, there’s Headscale. It’s a community project, not a Tailscale product. Its README describes it as “an open source, self-hosted implementation of the Tailscale control server,” aimed at “self-hosters and hobbyists.” It implements a single tailnet, “suitable for a personal use, or a small open-source organisation.” Headscale is licensed under BSD-3-Clause.
Two points to be clear on:
- It’s independent. Headscale’s README says the project “is not associated with Tailscale Inc.” Tailscale’s open-source page says Headscale “is developed independently and separately from Tailscale,” and that Tailscale “does not set Headscale’s product direction.” Headscale’s README adds that one active maintainer is employed by Tailscale and is allowed to spend work hours on the project.
- You own the operations. Updates, uptime and security of the control server become your job. The README also says: “we do not support nor encourage the use of reverse proxies and container to run Headscale.”
For help, Headscale’s README points to its own documentation and Discord server. Treat it as a hobbyist tool and read its documentation for which clients and features it supports.
When to use which
Use plain WireGuard when:
- You want one fixed tunnel, such as your phone to your home router or a site-to-site link, and you can open a UDP port.
- You want no accounts and no third party involved at all.
- Your router or firewall already has WireGuard built in.
Use Tailscale when:
- You can’t forward ports, for example behind carrier-grade NAT or on a network you don’t control.
- You’re connecting many devices that move between networks, such as laptops and phones.
- You want to reach home services like Home Assistant or Immich without exposing them to the internet. Immich’s own FAQ recommends a VPN for remote access over experimental options such as self-signed certificates.
- Your use fits the Personal plan’s limits and non-commercial terms, or you’re willing to pay.
Consider Headscale when you want Tailscale-style convenience with your own control server, and you’re comfortable running it.
One practical note from Tailscale: it has had reports of conflicts when running alongside other WireGuard-based VPNs, such as Mullvad VPN, which need specific configuration to run together.
What neither one does
- Neither hides your activity from the websites you visit unless you route traffic through an exit node or server, and then that device’s internet connection is what sites see.
- Neither replaces updates and passwords on the services you reach through them.
- Tailscale’s free plan isn’t for business use. Tailscale says so on its pricing page.
Download links for both are on our Tailscale and WireGuard app pages, from the developers’ own sites and official app stores only.
Questions
Is Tailscale just WireGuard?
No. Tailscale uses the WireGuard protocol for encryption and adds key management, NAT traversal, relays and access controls.
Is Tailscale free?
Its Personal plan is free forever for up to 6 users with unlimited user devices, for non-commercial use.
How many devices can I use on Tailscale’s free plan?
Unlimited user devices, plus up to 50 tagged resources such as servers.
Is WireGuard free?
Yes. WireGuard is free and open source.
Do I need port forwarding for WireGuard?
Usually at least one peer must be reachable, which at home means forwarding a UDP port. Tailscale doesn’t need port forwarding.
Is Tailscale open source?
Partly. Tailscale says its client is mostly open source and its relay servers are open source, but its coordination server is closed source.
Is Headscale made by Tailscale?
No. It’s an independent community project. Its README says it is not associated with Tailscale Inc.
Can Tailscale see my traffic?
Tailscale says its private keys never leave your devices, and its DERP relays only forward traffic that’s already encrypted.
Can I use Tailscale for my business for free?
Tailscale says the Personal plan is only for non-commercial use. Businesses get a 14-day trial, then need a paid plan.
Can WireGuard run over TCP?
No. WireGuard’s documentation says it explicitly doesn’t support tunneling over TCP.
Sources
- WireGuard: fast, modern, secure VPN tunnel (overview, license), WireGuard
- Known Limitations, WireGuard
- Quick Start (NAT and firewall traversal persistence), WireGuard
- Installation, WireGuard
- Tailscale pricing and FAQ, Tailscale, checked September 26, 2026
- What is Tailscale?, Tailscale Docs
- About WireGuard, Tailscale Docs
- DERP servers, Tailscale Docs
- Open source at Tailscale, Tailscale
- Headscale README, GitHub (community project)
- Immich FAQ (remote access), Immich docs