Tailscale app icon

Browsers and internet

Tailscale

WireGuard-based mesh VPN client that links your own devices and servers with identity-based access, MagicDNS and exit nodes.

WindowsmacOSLinuxBSD-3-Clause

Tailscale review: a mesh VPN that removes the port forwarding

What Tailscale is

Tailscale builds a private network, called a tailnet, out of the machines you own by wrapping WireGuard in an identity and coordination layer. Instead of configuring peers and keys by hand, you sign in on each device with an identity provider such as Google, GitHub or Microsoft, and the machines find each other through NAT without any router configuration. The client source is BSD 3-Clause licensed (https://github.com/tailscale/tailscale/blob/main/LICENSE), and the coordination service is operated by Tailscale, which is why the free personal plan caps users and devices rather than pretending the backend does not exist.

What a tailnet does for you

Every device gets a stable 100.x address and a MagicDNS name, so a home server becomes reachable as a hostname from a laptop in a cafe without a dynamic DNS record or an open port. Access control lists written in the admin console decide which users and devices can reach which services, replacing firewall guesswork with a small policy file. Subnet routers advertise an entire LAN so a remote machine can reach printers and appliances that cannot run the client themselves, and an exit node routes all traffic through one chosen device, which is the closest thing here to a traditional VPN. Taildrop moves files between your own devices without a cloud account.

Settings and limits worth knowing

The Windows package is an MSI that installs a service and a tray application, and it can be deployed quietly across a fleet. Three practical points matter. First, the coordination server is a hosted service: if it is unreachable, existing sessions keep working but new key exchanges do not, and there is an open source control server if you want to run your own. Second, the free plan is limited to a small number of users and devices, and larger teams move to paid tiers. Third, ACLs and device approval only help if you actually configure them; accepting the defaults grants every device on the tailnet broad access to the others. Key expiry in particular is worth checking early, because an expired node silently stops connecting until it re-authenticates.

Who should choose something else

If you want a conventional VPN that hides your browsing from your internet provider, a commercial VPN client is the right tool; Tailscale connects your own machines and is not built to exit through an anonymous server. If you cannot depend on an external coordination service, plain WireGuard or OpenVPN with your own keys keeps everything self-contained. Tailscale is for the person with a handful of computers, a NAS and a VPS who wants them on one private network in ten minutes rather than one evening of firewall rules.

Best for
People with several own devices, a home server or a small team who want private connectivity between them without router or firewall changes.
Good to know
The client is open source but the coordination service is hosted, and the free plan caps users and devices. Review ACLs and key expiry before adding a fleet.

How to get started

  1. Create a tailnet by signing in to Tailscale with an identity provider of your choice.
  2. Download the Windows MSI from tailscale.com/download/windows and install it.
  3. Sign in from the tray icon; the machine joins the tailnet and gets a 100.x address.
  4. Install the client on your other machines and servers, signing in with the same account.
  5. Enable MagicDNS in the admin console so devices can be reached by name.
  6. Write an access control policy, and if one device should route all traffic, enable it as an exit node.

Questions & answers

Is Tailscale a replacement for a commercial VPN?

No. It connects devices you own. To hide browsing from your internet provider, use an exit node you control or a conventional VPN service.

What happens if the coordination server is down?

Existing connections keep working, but new ones cannot be established. Self-hosting the control server is possible with the open source components.

How much is free?

The personal plan covers a small number of users and devices at no cost. Larger or commercial deployments need a paid tier, and device key expiry applies on every plan.

More in browsers and internet

View category