Tailscale: The Mesh-VPN Market Leader for Private Cloud Access
Mesh VPNs are replacing the old concentrator model. Anyone stepping into this space cannot avoid one name: Tailscale. The service has been the UX gold standard

Mesh VPNs are replacing the old concentrator model. Anyone stepping into this space cannot avoid one name: Tailscale.
The service has been the UX gold standard in the mesh VPN segment for years. More than 5 million monthly active users, BSD-3 licensed clients, MagicDNS, and one of the smoothest onboarding experiences on the market speak for themselves.
We evaluated Tailscale in the same lab environment we used to test NetBird. This time with two lenses: once as a pure product, and once along the EU sovereignty axis that runs through this series.
As of May 2026, evaluated on Tailscale Cloud with Standard and Premium features.
Tailscale is a WireGuard-based peer-to-peer mesh with a hosted control plane. The idea: WireGuard is great, but key distribution and authentication are painful, so Tailscale delivers exactly that layer as a managed service.
Three properties define the profile:
This last property is the central difference to NetBird and also the reason why a community reimplementation of the control plane, Headscale, exists (covered in Post 3 of this series).
Five points explain the setup without a diagram:
Important: The coordination server runs on AWS Linux hosts in the United States, with metadata in SQLite and backups to S3. As of May 2026, no EU region is offered for the control plane.
What sets Tailscale apart from a bare WireGuard setup or a pure mesh implementation is the set of product-grade features around it:
db.tailnet-name.ts.net are resolved automatically across your entire tailnet, with no need to run DNS or maintain a hosts file.Tailnet Lock is the product's most honest security move: Tailscale puts itself into the threat model as a potential attacker.
Tailscale is consistently IdP-driven. There is no email-and-password sign-up. Every account hangs on an external identity provider. Supported natively:
| Category | Providers |
|---|---|
| Native | Apple, Google/Workspace, GitHub, Microsoft (including Entra ID), Okta, OneLogin |
| Custom OIDC | Any OIDC-compliant provider (Keycloak, Zitadel, Authentik theoretically usable) |
| Additional | Passkey auth for authorized tailnets |
For mature enterprise setups this is pleasant, because SSO and MFA run through your existing IdP. For very small hobbyist setups, the mandatory external IdP can be a hurdle, especially if you do not already have a Workspace or Microsoft license.
Self-hosting the control plane is not officially supported. If you need that, Headscale is the answer, which we will cover in the next post in this series.
Tailscale simplified its pricing model in 2025/2026. These tiers are active:
| Tier | Price | User limit | Devices | Highlights |
|---|---|---|---|---|
| Personal | $0 | up to 6 | unlimited | Full feature set for individuals and homelabs |
| Standard | $8/user/month | unlimited | unlimited | SCIM, MDM integration, device posture, 10 ACL groups |
| Premium | $18/user/month | unlimited | unlimited | 300 ACL groups, network flow logs, log streaming, just-in-time access, advanced Tailscale SSH, priority support |
| Enterprise | Custom | unlimited | unlimited | Solutions engineer, MSA/SLAs, premium support |
Important: Existing customers on the older Personal+, Starter, or Business tiers stay on their current pricing for the time being. Anyone signing up new in 2026 starts on the current model with the tiers listed above.
Two observations for the practical comparison: Tailscale bills per user, not per active user like NetBird. Devices are unlimited, which can be cheaper in device-heavy scenarios (server fleets, IoT). Per user, Standard at $8 sits noticeably above NetBird Team at $5, which adds up on larger teams.
Platform coverage is broad: Linux, Windows, macOS, iOS, Android, plus NixOS, Synology, FreeBSD, Docker, and router integrations (OPNsense, pfSense via add-on).
What we noted positively during the evaluation:
If any one product has shaped this entire genre, it is this one. Tailscale is the bar that other vendors have to clear.
EU sovereignty is the running thread in this series, and Tailscale deserves an honest assessment here. Without bashing, but without sugar-coating the gaps:
Important: For NIS2 and DORA contexts, we recommend not deploying Tailscale without an additional sourcing assessment. The product quality is excellent. The EU sovereignty story is not.
If you want Tailscale's feature set together with sovereignty, the path leads to Headscale, covered in the next post in this series.
Four scenarios where Tailscale clearly moves to the front of the field:
Tailscale is the reference here. Employees install in minutes, MagicDNS and Tailscale SSH make internal services immediately reachable, and the mobile apps pick up field staff without friction.
Funnel, Serve, and Tailscale SSH fit perfectly into DevX stacks. You can make preview environments, local dev servers, and CI runners reachable without a public IP.
Then the trade-offs are acceptable. You get the most mature product in this market without sovereignty pulling you back.
Then the path leads to Headscale, an open-source community reimplementation of the Tailscale control plane that works with the official Tailscale clients. That is exactly where we pick up in the next post.
Tailscale is the most mature mesh VPN on the market in May 2026 and, in many contexts, the most productive choice. The UX is unmatched, the feature set is broad, and Tailnet Lock shows that the company takes security seriously. If EU sovereignty is a hard requirement, however, it is worth looking at NetBird or the upcoming introduction of Headscale.
If you are currently making the mesh VPN choice for your company, setting up a NIS2 or DORA program, or building sovereign access into your private cloud, we at Infralovers are happy to support you. We would be glad to advise you on our Sovereign Cloud offering and combine that with our training portfolio on NIS2 Compliance and Cloud Native Essentials.
You are interested in our courses or you simply have a question that needs answering? You can contact us at anytime! We will do our best to answer all your questions.
Contact us