What is Tailscale on Mac, and why is it using network data?

Last updated: 2026-08-05

Tailscale is a third-party encrypted networking client, not an Apple system process. Its traffic can include both Tailscale connection-management data and application traffic carried through your tailnet, but macOS attribution has not been officially confirmed.

What it is

Tailscale is a third-party encrypted networking client. It is not part of macOS and is not an Apple system daemon. It may have been installed by the person using the Mac or by an organization managing the device.

There are two graphical macOS variants. The Mac App Store version works through a Network Extension, while the independently distributed version works through a System Extension. Both use WireGuard to create a private virtual network called a tailnet. Depending on the installed variant, you may see names such as Tailscale Tunnel, Tailscale Network Extension, IPNExtension, or tailscaled alongside Tailscale itself.

The tailnet lets devices that have permission communicate over end-to-end encrypted connections. Ordinary application data usually travels directly between the participating devices. If a direct connection cannot be established, Tailscale can pass the encrypted data through a DERP relay or a configured peer relay. Its coordination service handles login, keys, access policies, and connection information, but it does not carry ordinary user data.

Why it talks to the network

Tailscale has several reasons to make connections even when you are not actively transferring a file. During startup, login, or updates to keys and access policies, it contacts the relevant identity provider and Tailscale coordination services. While preparing connections, it performs NAT discovery and contacts DERP services so that it can determine how approved devices can reach one another.

When you open a tailnet device, use Taildrop, connect to a remote subnet, or resolve a MagicDNS name, Tailscale sends end-to-end encrypted traffic to the appropriate device. It prefers a direct UDP connection. If that direct path is unavailable, it can use a configured peer relay or DERP instead.

The routing scope depends on your configuration. Without an exit node, Tailscale normally routes only tailnet addresses and subnet routes that the Mac has accepted. If you select an exit node, ordinary internet traffic from other applications also enters the Tailscale tunnel and travels through that node. This configuration difference can change the amount attributed to Tailscale substantially.

How much traffic is normal

There is no independently verified numerical range that is reliable across all Tailscale versions and configurations. A fixed allowance in megabytes would be misleading because Tailscale can be nearly idle in one setup and carry most of a Mac’s active traffic in another.

While idle, its network activity is mainly associated with coordination, discovery, and connection keepalives. Qualitatively, that is usually much smaller than an active file transfer or video stream. During actual use, however, Tailscale traffic may reach the same scale as the activity passing through it. Remote desktop use, Taildrop transfers, backups, remote-subnet access, and traffic sent through an exit node can all make the displayed total much larger.

There is also an attribution limit to keep in mind. Official documentation has not confirmed exactly how macOS or Bytetally assigns the inner and outer bytes of a Tailscale tunnel to processes. A total shown under Tailscale may include application traffic carried by the tunnel as well as Tailscale’s own control and connection-maintenance traffic. It is therefore not justified to label every displayed byte as forwarded traffic from another application.

Can you turn it off

You can turn off a graphical Tailscale client that has installed a VPN configuration. The usual path is:

Apple menu > System Settings > VPN > Tailscale Tunnel > Off

The VPN service name can be customized through device management, so a managed Mac may display a different name. The CLI-only open-source tailscaled variant cannot be managed through this macOS VPN switch.

After disconnection, the Mac can no longer use Tailscale to reach tailnet devices, send or receive through Taildrop, resolve MagicDNS names, or access remote subnets. If an exit node was active, internet access through that node stops and ordinary internet traffic returns to the Mac’s normal local network path.

On an organization-managed Mac, Always On or VPN On Demand policies may prevent disconnection or reconnect Tailscale automatically. Ending the process does not avoid those consequences: active connections that depend on the tailnet, a subnet route, or an exit node will still be interrupted, and policy may start the service again.

What people get wrong

Seeing what it actually used

First compare Tailscale’s traffic timeline with the periods when you used remote access, Taildrop, backups, remote subnets, or an exit node. Bytetally can show Tailscale’s per-process totals and timing, which helps distinguish steady maintenance activity from larger usage periods. Treat the result as observed attribution rather than proof that every byte came from Tailscale itself or from another application.

Related processes

Common questions

Is Tailscale a built-in macOS process?

No. Tailscale is third-party VPN and private-networking software installed by a user or organization.

Why is Tailscale using so much data on my Mac?

The total may include remote desktop sessions, Taildrop transfers, backups, subnet traffic, or internet traffic sent through an exit node, as well as Tailscale's own control and connection-maintenance traffic. The exact macOS attribution behavior has not been officially confirmed.

Can I turn off Tailscale Tunnel?

Yes, for graphical clients with a Tailscale VPN configuration, unless an organization enforces Always On or VPN On Demand. Turning it off disconnects access to tailnet devices, Taildrop, MagicDNS names, remote subnets, and any active exit-node route.

Does Tailscale send all internet traffic through its servers?

Not by default. It normally routes only tailnet addresses and accepted subnet routes; ordinary internet traffic enters Tailscale when you select an exit node.

See exactly how much it used

Bytetally tracks every process on your Mac separately — upload and download, live and historical. All on-device.

Download Free on the Mac App Store

macOS 14 Sonoma or later · 100% on-device · No account