Tailscale vs WireGuard-Only: When the Coordination Server Is the Feature You Didn’t Want

Julian Park

Julian Park

September 18, 2026

Tailscale vs WireGuard-Only: When the Coordination Server Is the Feature You Didn't Want

WireGuard is a tunnel. Tailscale is a company that distributes WireGuard keys, assigns 100.x addresses, punches NAT, and keeps a list of who is allowed to talk. People install Tailscale because they wanted WireGuard without the spreadsheet. Six months later they notice the spreadsheet was the part they did not want in someone else’s datacenter. The coordination server is the product. The encryption was never the argument.

I self-host coordination planes for small tailnets and I still keep a paid Tailscale account for relatives who will not tap a custom server URL. That split is not purity. It is who I will help on a Sunday. WireGuard-only is the third option: no plane, just peers, just files, just you.

What you actually wanted

If you wanted “my laptop can reach the NAS without a port-forward,” Tailscale is the feature. MagicDNS, a phone app your parent will install, ACLs you can read. The coordination server is how that happens without you SSHing into four machines to paste pubkeys every time a phone is replaced.

If you wanted “WireGuard but I do not like SaaS,” you wanted a mesh you operate. Headscale is still a coordination server. It is yours. Raw WireGuard is not a mesh product. It is N times (N minus one) configuration, or a simple hub-and-spoke you pretend is a mesh.

The search collapses these. “Tailscale versus WireGuard” is a category error unless you mean Tailscale versus a WireGuard config you will maintain. I mean that.

Laptop and a home router on a desk, network cables, daylight

What the coordination server gives you — and takes

Tailscale Inc. knows your device list, your advertised routes, roughly when nodes are online, and the identity you used to log in. DERP relays see ciphertext and metadata. That is the deal. It is a good deal for a household that will not run Headscale. It is a bad deal if the requirement was “no third party knows the membership.”

The server also gives you features people forget are features until they leave: key rotation that is not a weekend, a shared node that a contractor can lose without you rewriting five configs, SSH over the tailnet, an exit node checkbox. WireGuard-only will do exit-node-shaped routing if you build it. You will build it.

I have watched people “just use WireGuard” and then invent a poor coordination server in a git repo of configs. That repo is the plane. It does not punch NAT. It does not rotate. It does not tell you a key is stale. It is a plane that cannot see.

When WireGuard-only is the right stubbornness

Two machines, stable public IPs or a cheap VPS hub, you like wg-quick, you will update the peer list when a laptop dies. Site-to-site between two houses with routers that already speak WireGuard. A single travel VPS that is only egress. These are WireGuard-only jobs. Adding Tailscale is adding a membership directory you do not need.

A phone that must roam on hotel NAT without a VPS hub is not a WireGuard-only job unless you enjoy suffering. Tailscale’s NAT traversal is the reason the product exists. Copying that with raw WireGuard means a hub the phone always dials. The hub is your coordination server. You already have a plane. You just named it “the VPS.”

I run WireGuard-only for a pair of routers that have not changed roles in two years. I run Tailscale for the messy humans. I run Headscale when the humans will tolerate a URL. Three tools, three jobs. The mistake is using one name for all three.

Two home routers and a small VPS-style box, evening

Headscale is not WireGuard-only

If the objection is Tailscale Inc. and not “I refuse a plane,” Headscale is the next sentence. You still have a coordination server. You operate it. Relatives must use a custom control URL. Some clients are worse at that than the official app. That trade-off is already written down as Headscale versus Tailscale for a household. This piece is the other fork: no plane at all.

Do not install Headscale to be closer to “just WireGuard” and then be angry that you still have a server. You wanted a server you can grep. You got one.

NAT, DERP, and the lie of “I will just open 51820”

WireGuard-only behind CGNAT — Starlink, many mobile networks, a lot of apartments — needs a rendezvous. Tailscale’s DERP is that rendezvous with nicer branding. Your VPS hub is that rendezvous with an hourly bill. “I will open 51820 on the house” is a sentence CGNAT does not honor. I have written it, then used Tailscale anyway, then pretended I had a principle.

If both sites have real IPv4, WireGuard-only is pleasant. If one site is a phone, you will build a hub or you will use a plane. There is no third physics. People who say they run “just WireGuard” on travel laptops almost always have a hub. Call the hub a coordination server and the comparison gets honest.

IPv6-only fantasies help until a hotel has no IPv6. Then you are back to a plane or a hub. I keep the hub for a couple of stubborn boxes. I do not tell a relative to find the hub’s IP from a café.

Key distribution is the unglamorous plane

Tailscale’s login is key distribution. WireGuard’s wg set is key distribution. A USB stick between two routers is key distribution. The difference is revocation and adding the third device. The third device is when people come back to Tailscale. Two is a couple. Three is a network. Networks want a plane.

I have rotated WireGuard keys on a schedule I wrote down and then missed. I have removed a Tailscale node in twenty seconds after a laptop theft scare. Both are valid. Only one is a feature I will promise a household. If you are the household, you may promise yourself the rotation. Write the date. I did not, once. The old laptop’s key still worked. That is the cost of a plane you cannot see.

ACL, identity, and the feature you did not want until you did

Tailscale ACLs are why a guest node cannot see the NAS. WireGuard-only ACLs are firewall rules on each box, or a hope. When the family laptop gets malware, I want a plane that can drop a node. When I have two routers, I want iptables I wrote. Different threat, different tool.

SSO and identity are the other surprise. Tailscale can tie nodes to a Google account. That is convenient and it is a dependency. WireGuard-only ties nodes to a file you copied. Losing the file is your problem. Losing the Google account is a different problem. Pick the problem you can explain at 1 a.m.

Performance theater

Raw WireGuard on a good path is fast. Tailscale on a good path is also WireGuard and is fast. Tailscale on a bad path that falls to DERP is slower, and that slowness is the price of “it works in the hotel.” People benchmark Tailscale versus WireGuard on a LAN and declare a winner. On a LAN I would use neither for bulk copies. I would use the LAN. The overlay is for when the LAN is not there.

If you exit through Tailscale to “be a VPN,” you wanted a different article. If you exit through a WireGuard VPS, you wanted egress, not a mesh. Keep the jobs straight and the benchmarks get less religious.

How I choose on a new pair of machines

If a human who is not me must connect, Tailscale or Headscale. If the machines are routers I own and the topology is boring, WireGuard-only. If I am avoiding a company and I still need phones on hotel Wi-Fi, Headscale plus the pain of the URL, not a fantasy of wg-quick on iOS that I will not maintain.

If I am avoiding a company and I only need two sites, WireGuard site-to-site and a note in the homelab doc. No 100.x. No MagicDNS. Hostnames in /etc/hosts or a DNS I already run. That is allowed. It is not lesser. It is smaller.

The coordination server is the feature you did not want when you thought you were buying encryption. Encryption was free in WireGuard in 2018. You bought a control plane. Keep it if the plane is the value. Delete it if the plane is the fear. Do not delete it and then rebuild it badly in a folder of configs you will not rotate. I have done that. I named it “simple.” It was a plane that could not see, and I still had to be the server. Relatives do not want to be the server. I do not want to be the server on a holiday. That is the whole product, said without a landing page. Keep Tailscale when the plane is the gift. Keep WireGuard when the topology is two boxes and a note. Keep Headscale when the gift must live in your rack. I have all three on purpose, not because I could not choose.

More articles for you