Advertisement

Tailscale vs WireGuard: What Each Is, Free-Tier Limits, and When to Use Which

By the Softwares Academy editors Updated Checked against official sources on 26 Sep 2026

Short answer: In Tailscale vs WireGuard, WireGuard is a VPN protocol and a free, open-source tool. You configure every tunnel yourself, and usually one side needs a reachable UDP port. Tailscale is a service built on WireGuard that handles keys, NAT traversal and access rules for you, so devices connect without port forwarding. Tailscale’s free Personal plan covers up to 6 users with unlimited user devices, for non-commercial use. Paid plans start at $8 per user per month. Use plain WireGuard for a simple fixed tunnel you control end to end. Use Tailscale to link many devices across networks with little setup. Headscale is a community project that replaces Tailscale’s coordination server if you want to self-host it.

What WireGuard is

WireGuard describes itself as “an extremely simple yet fast and modern VPN that utilizes state-of-the-art cryptography.” It started in the Linux kernel and is now available for Windows, macOS, BSD, iOS and Android.

It works like SSH keys. Each device has a private key, and you give each peer the other’s public key and the addresses it’s allowed to use. WireGuard then carries encrypted IP packets over UDP.

What WireGuard deliberately leaves out matters just as much. Its own site says: “All issues of key distribution and pushed configurations are out of scope of WireGuard.” You create keys, write config files and copy them to each device yourself. From WireGuard’s “Known Limitations” page:

  • It “explicitly does not support tunneling over TCP.”
  • It “does not focus on obfuscation,” so networks that block VPN traffic can block it.

WireGuard’s kernel components are licensed under the GPLv2, and its other projects use MIT, BSD, Apache 2.0 or GPL. It costs nothing. Official apps and packages are linked from wireguard.com and on our WireGuard app page.

Advertisement

What Tailscale is

Tailscale’s documentation describes it as a way to connect devices across networks using “the open source WireGuard protocol.” Instead of routing everything through one central server, Tailscale builds “a peer-to-peer mesh network (known as a tailnet).” You can still send all your traffic through one device, called an exit node, like a traditional VPN.

Tailscale’s “About WireGuard” page lists what it adds on top: NAT traversal, TCP transport capabilities and access control policies. Its overview says connections “work seamlessly across firewalls and Network Address Translation (NAT) without requiring port forwarding or complex firewall rules.” You sign in on each device and they find each other.

When two devices can’t connect directly, Tailscale relays their traffic, first through peer relays you set up, then through its own DERP relay servers. Tailscale says traffic through DERP is encrypted with WireGuard and its private keys “never leave the local device,” so a DERP server “blindly forwards already-encrypted traffic.”

How open is it? Tailscale’s open-source page says the client is “mostly open source.” The daemon is open source on every platform, but the GUI is closed source on Windows and macOS. The DERP relay servers are open source. The coordination server, which hands out keys and addresses, is closed source.

Tailscale pricing and free-tier limits

From Tailscale’s pricing page on September 26, 2026:

Plan Price Users Notable limits
Personal $0, “Free forever” Up to 6 Unlimited user devices, up to 3 ACL groups, 50 tagged resources, 1,000 minutes a month of ephemeral resources
Standard $8 per user per month Unlimited Up to 10 ACL groups, SCIM user provisioning
Premium $18 per user per month Unlimited Up to 300 ACL groups, 10,000 ephemeral minutes a month, priority support
Enterprise Custom Custom Premium support, custom agreements

Tagged resources, such as servers or exit nodes that aren’t tied to a person, are included up to 50. Tailscale charges $1 a month for each one beyond that.

The key condition on the free plan is use. Tailscale says the Personal plan “is only suitable for non-commercial use.” It lists homelabs, home VPNs, gaming with friends and connecting a Raspberry Pi or home camera as examples. How you sign up decides your plan: a tailnet created with a Gmail, Apple or personal GitHub account is treated as personal, while one created with a custom email domain is treated as business use and starts a 14-day free trial. You can opt out of the trial, but Tailscale notes the Personal plan still isn’t meant for commercial use.

Tailscale vs WireGuard side by side

WireGuard Tailscale
What it is VPN protocol and tools Networking service built on WireGuard
Cost Free Free Personal plan; paid from $8 per user per month
Key management Manual Automatic, through Tailscale’s coordination server
Port forwarding Usually needed on at least one side Not needed
Behind NAT Works with persistent keepalive set NAT traversal built in, relays as fallback
Topology Whatever you configure Mesh by default
Accounts None Sign-in through an identity provider
Self-hosted control Fully self-hosted Coordination server is Tailscale’s, or use Headscale
Source code Open source Mostly open client, closed coordination server

On NAT: WireGuard’s quick start explains that a peer behind NAT or a firewall that wants to receive incoming packets must keep the mapping alive by sending keepalives. It suggests an interval of 25 seconds. You still need at least one peer the other can reach, which at home usually means forwarding a UDP port on your router.

Self-hosting: Headscale

If you like Tailscale’s clients but don’t want to depend on Tailscale’s servers, there’s Headscale. It’s a community project, not a Tailscale product. Its README describes it as “an open source, self-hosted implementation of the Tailscale control server,” aimed at “self-hosters and hobbyists.” It implements a single tailnet, “suitable for a personal use, or a small open-source organisation.” Headscale is licensed under BSD-3-Clause.

Two points to be clear on:

  • It’s independent. Headscale’s README says the project “is not associated with Tailscale Inc.” Tailscale’s open-source page says Headscale “is developed independently and separately from Tailscale,” and that Tailscale “does not set Headscale’s product direction.” Headscale’s README adds that one active maintainer is employed by Tailscale and is allowed to spend work hours on the project.
  • You own the operations. Updates, uptime and security of the control server become your job. The README also says: “we do not support nor encourage the use of reverse proxies and container to run Headscale.”

For help, Headscale’s README points to its own documentation and Discord server. Treat it as a hobbyist tool and read its documentation for which clients and features it supports.

When to use which

Use plain WireGuard when:

  • You want one fixed tunnel, such as your phone to your home router or a site-to-site link, and you can open a UDP port.
  • You want no accounts and no third party involved at all.
  • Your router or firewall already has WireGuard built in.

Use Tailscale when:

  • You can’t forward ports, for example behind carrier-grade NAT or on a network you don’t control.
  • You’re connecting many devices that move between networks, such as laptops and phones.
  • You want to reach home services like Home Assistant or Immich without exposing them to the internet. Immich’s own FAQ recommends a VPN for remote access over experimental options such as self-signed certificates.
  • Your use fits the Personal plan’s limits and non-commercial terms, or you’re willing to pay.

Consider Headscale when you want Tailscale-style convenience with your own control server, and you’re comfortable running it.

One practical note from Tailscale: it has had reports of conflicts when running alongside other WireGuard-based VPNs, such as Mullvad VPN, which need specific configuration to run together.

What neither one does

  • Neither hides your activity from the websites you visit unless you route traffic through an exit node or server, and then that device’s internet connection is what sites see.
  • Neither replaces updates and passwords on the services you reach through them.
  • Tailscale’s free plan isn’t for business use. Tailscale says so on its pricing page.

Download links for both are on our Tailscale and WireGuard app pages, from the developers’ own sites and official app stores only.

Questions

Is Tailscale just WireGuard?

No. Tailscale uses the WireGuard protocol for encryption and adds key management, NAT traversal, relays and access controls.

Is Tailscale free?

Its Personal plan is free forever for up to 6 users with unlimited user devices, for non-commercial use.

How many devices can I use on Tailscale’s free plan?

Unlimited user devices, plus up to 50 tagged resources such as servers.

Is WireGuard free?

Yes. WireGuard is free and open source.

Do I need port forwarding for WireGuard?

Usually at least one peer must be reachable, which at home means forwarding a UDP port. Tailscale doesn’t need port forwarding.

Is Tailscale open source?

Partly. Tailscale says its client is mostly open source and its relay servers are open source, but its coordination server is closed source.

Is Headscale made by Tailscale?

No. It’s an independent community project. Its README says it is not associated with Tailscale Inc.

Can Tailscale see my traffic?

Tailscale says its private keys never leave your devices, and its DERP relays only forward traffic that’s already encrypted.

Can I use Tailscale for my business for free?

Tailscale says the Personal plan is only for non-commercial use. Businesses get a 14-day trial, then need a paid plan.

Can WireGuard run over TCP?

No. WireGuard’s documentation says it explicitly doesn’t support tunneling over TCP.

Sources

Related guides