I do a lot of remote tech support, but some clients may struggle to find the Start menu on a good day. Telling them to log into a VPN account just to let me fix a single issue is too complicated. I found a way to reach those computers, apply the fix, and leave without requiring a permanently installed VPN client.
My go-to was Tailcat, a tool built by the Tailscale team. It lets two computers communicate without requiring a Tailscale account or publicly reachable IP addresses, and it tries to establish a direct connection when NAT traversal succeeds.
Two PCs, no public IP, no account
A string neither machine had a second ago connects them
It feels kind of magical. The first time I used it, I ran the command tailcat on a computer, which generated and printed a Tailcat address. Then I sent that address to the other computer on a different network, behind a separate router. Within seconds, the two machines could communicate.
My prior knowledge of home networking would have predicted that this wouldn’t work. None of the devices had a public IP, and none had port forwarding enabled. In fact, neither had even pinged the other before this connection.
The string isn’t a password itself, but it does the trick. It contains the generating device’s public key, discovery key, pre-shared key, and the information needed to bootstrap the connection through a DERP relay. In the default mode I tested, the keys are ephemeral, so the connection doesn’t become part of a persistent account or Tailnet.
I found the handshake itself quite humorous. It starts with what the project’s own source calls “Meow,” an opening signal one machine sends the other, sent through the DERP rendezvous relay. The reply I received for its opening signal was literally “Meowed.”
In my connection test, I watched the reply arrive through the first relay, and moments later the connection switched to a direct path between the two PCs. These systems were basically communicating, and they didn’t need a public address.
Unlike a traditional VPN, Tailcat’s connection stays inside the application without installing a network interface or rewriting the computer’s routing table.
What two connected PCs can actually do
The same address, put to a surprising number of jobs
As soon as the connection was created, curiosity turned to experimentation: I needed to see what it could do. I started by piping a file straight across the connection:
# On the receiving PC:
tailcat > archive.tar.gz# On my laptop:
tailcat tc8f9a2b1c4d...
This worked seamlessly without first uploading to a cloud service. Tailcat can also create a receive-only destination, so someone can send files without being given a normal browsable directory.
Being able to expose just one service instead of opening general network access was a significant shift. I could make a single dashboard reachable through the Tailcat connection without turning the whole machine or home network into something the other computer could browse.
However, it got even better. Tailcat allows me to make that remote service feel like it’s running locally. This means a browser or database will work if I point it at a local port, without knowing that it’s reaching across the internet. The single most satisfying moment was when I ran these commands:
# On the remote machine serving the app:
tailcat serve 80# On my laptop:
tailcat forward tc8f9a2b1c4d... 8080:80
I opened this address: http://localhost:8080/ in my browser, and the web app running on the other computer loaded directly, skipping configuration screens.
When you factor in that Tailcat can move files and carry TCP connections, it becomes clear that it’s more than a one-trick transfer app.
This isn’t a smaller Tailscale
What’s missing isn’t the point
An oversimplified description of this tool would be Tailscale-lite. But that would be incorrect. The Tailscale team describes it as Tailscale with no Tailscale. This is more like having that same encrypted plumbing that makes remote machines findable, without the private network built on top.
I use the full Tailscale daily, and would describe it as a tool meant for a network you keep. So it’s great if your laptop, NAS, and phone all need to stay reachable indefinitely using a single account. Tailcat is for reaching one machine, doing one job, and letting the connection remain temporary instead of adding that machine to a persistent network.
It’s what I will use if I need a file from a machine that isn’t mine to keep. I may add that machine to my network, but it’s overkill to do this for a five-minute task.
|
Tailcat |
Tailscale |
|
|---|---|---|
|
Core purpose |
One-off connection |
Ongoing private network |
|
Account needed |
No |
Yes |
|
Managed Tailnet |
No |
Yes |
|
Central management/policy |
No |
Yes |
|
Best fit |
A specific task |
Repeated access across devices |
Certain elements, like accounts, device lists to manage, and a policy layer that decides who talks to what, may feel like missing components of Tailcat, but that’s just the design.
Ease of use still requires safeguards
Before getting carried away, there’s an important detail I haven’t touched just yet. Since possession of the Tailcat address is enough to bootstrap access in the default setup, it deserves the same care as a password. It’s not the kind of link you can casually paste into a group chat.
You can publish this string as a DNS record, making your device reachable by name rather than copying a string around. However, DNS records are constantly scanned by bots, and this can end up being a security hazard. This detail made me take notice; easy access often deserves greater caution.
The entire trick behind Tailcat wasn’t to make two private computers public, but to give them a way to talk without requiring either one to be publicly reachable.