- They're not using a VPS, they're using a server hosted inside their house

- Lots of ISPs use CGNAT which means you can't always have direct access, especially on mobile. Tailscale solves that via DERP (https://tailscale.com/docs/reference/derp-servers)

- Static public IP addresses for ingress cost money from the cloud provider, they're not cheap either

- Having a public IP makes the ports open to attackers, using Tailscale the attacker has to hack your tailnet before they can hack your server

- You have to buy a DNS name for your public IP, you don't need one if you use Tailscale thanks to MagicDNS

- Tailscale has a bunch of nice features like Let's Encrypt integration, OAuth support, Tailscale SSH, etc. that make the experience quite nice overall

> You have to buy a DNS name for your public IP

What are you talking about?

If you want TLS for your websites/webapps you're gonna need a DNS name to get a cert

No, Let’s Encrypt provides IP address certificates for free.

Interesting, apparently they added that as a feature a few months ago.

https://letsencrypt.org/2026/01/15/6day-and-ip-general-avail...