Tailscale and ZeroTier both do the same thing at a distance: install a client on each of your devices, and they behave as though they share a local network no matter where they physically are. Both have a free tier. Both are popular with home users and homelab builders.
Underneath, they are less similar than they look. Different protocols, different cryptography, very different amounts of work to get past the basic setup, and free tiers that have both changed significantly in the last two years.
This comparison uses current figures from both vendors, checked in September 2026, and is explicit about the places where the marketing and the documentation disagree.
The Short Version
Tailscale is easier, has a far more generous free tier, and is built on WireGuard. Its control plane is closed source, so you cannot self-host it without switching to a third-party project.
ZeroTier is more open, and its controller can genuinely be self-hosted. It uses its own protocol rather than WireGuard, its free tier is now much tighter than Tailscale's, and anything beyond a flat private network means writing firewall rules by hand.
If neither fits, there is a wider field of options in our guide to Tailscale alternatives for self-hosted remote access. For most home users the honest recommendation is Tailscale, and the reason is not polish. It is that routing your traffic through your home connection, which is what most people actually want, takes two clicks on one and hand-edited iptables rules on the other.
Free Tiers: Both Changed, in Opposite Directions
This is where most comparison articles are wrong, including ones published recently, because both vendors moved.
Tailscale's Personal plan is free for up to 6 users with unlimited devices. It was 3 users until April 2026, when Tailscale reworked its pricing, doubled the user allowance and retired the old Personal Plus tier by folding it into the free plan. There are two limits worth knowing: 50 tagged resources are included and additional ones cost $1 per month each, and you get 3 ACL groups. The tagged-resource cap is the one that surprises homelab users who tag a lot of servers.
One restriction matters: Tailscale states the Personal plan "is only suitable for non-commercial use." If you are running a business on it, you are outside the terms.
ZeroTier's free Personal plan covers 10 devices, 1 network and 1 network admin. This is the number most articles get wrong, because the free tier used to be 25 devices. ZeroTier restructured its pricing in July 2024, and existing free users were grandfathered, so you will find plenty of people online who still have 25 and plenty of articles that still quote it. New accounts get 10.
The paid tiers have moved too, and one of them moved a lot. Tailscale is $8 per user per month for Standard and $18 for Premium. ZeroTier's entry paid tier, Essential, is $18 per month with 10 included devices and $2 per additional device per month. When Essential launched in July 2024 it was announced at $5 per month. If you are relying on an older article's pricing, check before you plan around it.
The Protocol Difference, and Why It Matters
Tailscale is built on WireGuard. That is a well-known, independently audited protocol with a small codebase, and it is the same protocol underneath most of the modern VPN landscape.
ZeroTier is not WireGuard. It uses its own two-layer protocol: VL1 handles peer-to-peer transport, VL2 handles Ethernet virtualisation on top. Key exchange uses Curve25519/Ed25519, and the documented symmetric cipher is Salsa20 with Poly1305 authentication.
There is one genuinely important difference here, and ZeroTier documents it plainly rather than hiding it: "As of today we do not implement forward secrecy or other stateful cryptographic features in VL1." Their documentation recommends running SSL or SSH over ZeroTier if you need it. WireGuard, and therefore Tailscale, provides forward secrecy through periodic rekeying.
Forward secrecy means that if a key is compromised in future, previously recorded traffic still cannot be decrypted. For most home users copying files off a NAS, this is theoretical. If you are moving anything sensitive, it is not.
Worth flagging honestly: ZeroTier's own materials are inconsistent about the cipher. The pricing page advertises AES-256 on every tier, the protocol documentation says Salsa20/Poly1305, and the source code implements AES-GMAC-SIV. The likeliest explanation is that AES is negotiated on hardware that supports it and the protocol doc is out of date, but ZeroTier publishes no current statement reconciling the three. The same gap appears on forward secrecy, and it is starker: the protocol documentation says VL1 does not implement it, while the pricing page lists "Perfect Forward Secrecy" on every tier including the free Personal plan. Read both before assuming either.
The Setup Gap Is Bigger Than It Looks
Getting a flat private network running is easy on both. Install, join, done. Tailscale authenticates with an existing Google, Microsoft or GitHub account. ZeroTier gives you a 16-digit network ID and requires you to manually authorise each device in its web console.
The gap opens the moment you want to do the thing most people bought this for: route your internet traffic through your home connection, or reach devices on your home LAN that are not running the client.
Tailscale exit node. Install the client on a machine at home, toggle "advertise as exit node," approve it once in the admin console, then pick it from a menu on your phone. Tailscale's documentation confirms "exit nodes are available for all plans," including the free one. Subnet routers, which let you reach devices with no client installed, take one sysctl line and one CLI flag.
ZeroTier exit node. From ZeroTier's own documentation, on the gateway machine you enable IP forwarding in /etc/sysctl.conf, then write three iptables rules for masquerading and forwarding, then install iptables-persistent so they survive a reboot, then add a 0.0.0.0/0 managed route in the web console. Then on every client you set allowDefault=1. Then, on Linux clients, you set rp_filter=2, because otherwise reverse path filtering silently drops the traffic and nothing tells you why.
Also documented: full tunnel mode does not work on FreeBSD at all after version 1.10.6, and the routed-LAN mode "can't initiate connections from the LAN to an external ZeroTier client."
This is not a matter of taste. One of these is a toggle and one is a networking exercise.
A related default worth knowing: ZeroTier ships with allowDNS=0, so name resolution is off until you turn it on per client. Tailscale's MagicDNS is enabled by default on any tailnet created since October 2022, so ping nas just works.
Openness and Self-Hosting
Here ZeroTier has the stronger structural position, and it deserves credit for it.
Tailscale's client is open source under BSD-3-Clause, and its DERP relay servers are open source. Its coordination server is not. You cannot self-host Tailscale's own control plane. What you can do is run Headscale, an independent open-source reimplementation with more GitHub stars than Tailscale's own client repo, which works with the official Tailscale apps.
Headscale is genuinely good, and one of its maintainers is employed by Tailscale and permitted to work on it. But read its own description before committing: it is still pre-1.0, it states "Headscale is not enterprise software and our focus is homelabbers and self-hosters," it does not implement Funnel or Serve, and its README says they "do not support nor encourage the use of reverse proxies and container to run Headscale," though the project does publish container images and its FAQ describes Docker as unsupported rather than impossible.
ZeroTier's client and controller are MPL-2.0, with a small source-available subtree. You can run the controller yourself, officially, using ZeroTier's own code. The catch is what that actually means in practice: management is raw HTTP API calls against localhost:9993 with curl, and there is no web interface. ZeroTier's documentation says so directly: "This is a low tech way to setup a controller for example purposes. You'd likely build yourself something fancier around this API." Everyone who does this in practice installs a community project such as ZTNET or ztncui for the UI.
One regression to note: ZeroTier's "moons," the mechanism for running your own root discovery servers, are now marked deprecated and "no longer recommended."
Speed: Nobody Actually Knows
You will find articles claiming one is twice as fast as the other. Both claims trace back to the same two benchmarks, they are old, and they contradict each other.
A 2022 independent single-stream iperf3 test measured ZeroTier at 546 Mbit/s and Tailscale at 268 Mbit/s. A 2024 multi-host test measured Tailscale at roughly 10 Gbps and ZeroTier at roughly 3 Gbps, though it was published by a vendor of a competing product, which the write-up disclosed.
The likely explanation is thread count. Tailscale's userspace WireGuard scales across cores with parallel streams; ZeroTier is single-threaded. A single large file transfer looks like the first test. Many simultaneous connections look like the second.
There is no current head-to-head benchmark from 2025 or 2026. Anyone who tells you which is faster today is extrapolating.
For a home user on a connection of 1 Gbps or less, the dominant variable is not the protocol anyway. It is whether you get a direct peer-to-peer connection or fall back to a relay. Both products relay as a last resort when NAT traversal fails, and relayed throughput is worse on both.
Head to Head
| Tailscale | ZeroTier | |
|---|---|---|
| Protocol | WireGuard | Own protocol (VL1/VL2) |
| Forward secrecy | Yes, via WireGuard | Not in VL1 per docs; advertised on all tiers |
| Free tier | 6 users, unlimited devices | 10 devices, 1 network |
| Entry paid tier | $8 per user per month | $18 per month |
| Device onboarding | SSO login | Network ID plus manual authorisation |
| Exit node setup | Toggle and approve | sysctl, iptables, per-client flags |
| DNS by default | On (MagicDNS) | Off |
| Client licence | BSD-3-Clause | MPL-2.0 |
| Control plane self-hostable | Not officially (Headscale) | Yes, API only, no UI |
| Works behind CGNAT | Yes, relay fallback | Yes, relay fallback |
| File transfer built in | Taildrop (alpha, own devices only) | No |
| Official mobile and desktop apps | macOS, iOS, Windows, Linux, Android, tvOS | macOS, iOS, Windows, Linux, Android, OpenWRT, Docker |
What Neither of Them Is
Worth stating clearly, because a lot of people arrive at these tools with the wrong expectation.
Neither is a privacy VPN. Neither hides your IP address from websites. Neither gives you servers in other countries. If you want to appear to be in Japan, neither of these is the tool, and no amount of configuration changes that.
Neither routes your internet traffic by default. Out of the box you get a private overlay between your own devices and nothing else. Everything beyond that is configuration.
Neither works without software on the device. Every machine that needs access runs a client. On a borrowed laptop, a work machine with locked-down software installation, or a hotel browser, neither helps you.
Which One Should You Use?
Choose Tailscale if you want the least work, you want exit nodes and subnet routing without writing firewall rules, you have more than 10 devices, or forward secrecy matters to you. For the large majority of home users this is the right answer, and the free tier is genuinely generous.
Choose ZeroTier if you specifically want to self-host the control plane on officially supported code, you prefer not to attach an identity provider to your network, or you need its Layer 2 bridging capabilities. Be realistic about the setup effort and the 10-device ceiling.
Choose Headscale if you like Tailscale's clients but want the coordination server on your own hardware, and you have the skills and patience for pre-1.0 software that its own maintainers describe as not enterprise ready.
If Software on Every Device Is the Problem
There is a third category that neither of these belongs to, and it is worth knowing about if the recurring friction in your household is not the network but the maintenance.
Both Tailscale and ZeroTier are software meshes. Somebody has to install the client, keep it updated, re-authenticate when keys expire and reinstall it after a factory reset. In most households that somebody is one person, and they are the only one who understands it.
Purpose-built hardware moves that job onto one box, and we compared the options in whether your home network needs a hardware VPN device. vploq is one example: a small device that plugs into your home router over Ethernet and creates an encrypted WireGuard tunnel back to your home network, with no port forwarding and no router configuration, and which is built to work behind CGNAT.
Being straight about the trade-offs, because they are real. You still install an app on each device you connect from, so it does not solve the borrowed-laptop problem either. It handles up to 5 devices at a time against Tailscale's unlimited. It tops out at 300 Mbit/s, and it wants at least 50 Mbit/s upload at home because everything routes through your own connection. It costs $249 once where Tailscale's free tier costs nothing, and it currently ships to the United Kingdom only, with pre-orders shipping from November 2026.
If you are technical and Tailscale's free plan covers you, use Tailscale. The case for hardware is not that it beats a free product on price. It is that it removes the ongoing job of keeping software running on other people's devices.
Frequently Asked Questions
Is Tailscale or ZeroTier better for home use?
Tailscale, for most people. Its free tier covers 6 users with unlimited devices against ZeroTier's 10 devices, and the features home users actually want, exit nodes and subnet routing, take a toggle rather than hand-written iptables rules. ZeroTier is the better choice if you specifically want to self-host the control plane on officially supported code.
How many devices does Tailscale's free plan allow?
Unlimited user devices, for up to 6 users. Older articles quoting 3 users or 100 devices are out of date: Tailscale reworked its plans in April 2026 and increased the free user allowance from 3 to 6. The free plan is restricted to non-commercial use.
How many devices does ZeroTier's free plan allow?
10 devices, on 1 network, with 1 network admin. The widely quoted figure of 25 devices reflects the old free tier, which was replaced in July 2024. Existing accounts from before that change were grandfathered, which is why both numbers circulate.
Does ZeroTier use WireGuard?
No. Tailscale is built on WireGuard, but ZeroTier uses its own protocol, with Curve25519 key exchange and Salsa20/Poly1305 documented as the symmetric cipher. ZeroTier's documentation states that it does not implement forward secrecy and recommends layering SSL or SSH on top if you need it.
Can I self-host Tailscale?
Not Tailscale's own coordination server, which is closed source. You can run Headscale, an independent open-source implementation of the control server that works with the official Tailscale clients. Its maintainers describe it as aimed at homelabbers rather than enterprises, and it does not implement every upstream feature.
Which is faster, Tailscale or ZeroTier?
There is no current benchmark that answers this. The two most-cited tests are from 2022 and 2024 and reach opposite conclusions, most likely because one used a single stream and the other used many, and ZeroTier is single-threaded. On a home connection the bigger factor is whether you get a direct connection or fall back to a relay.
Do Tailscale or ZeroTier work behind CGNAT?
Both usually do. Both attempt a direct peer-to-peer connection and fall back to relaying through the vendor's infrastructure when NAT traversal fails. Traffic stays end-to-end encrypted in either case, but relayed connections are slower.
Will Tailscale or ZeroTier hide my IP address like a commercial VPN?
No. Neither is a privacy VPN and neither has servers in other countries. If you configure an exit node you can route traffic through one of your own devices, which presents that device's IP address, typically your own home IP. For appearing to be in a country where you have no connection, you need a commercial VPN service.
Does ZeroTier route my traffic through my home internet by default?
No. By default ZeroTier gives you a private overlay network only, with allowDefault and allowGlobal both off. Routing internet traffic through a home gateway requires enabling IP forwarding, adding masquerading and forwarding rules with iptables, adding a managed route, and enabling the setting on each client individually.



