MusicFlow

Headroom · Guide

Using Headroom with Tailscale

Reach your Mac from anywhere — without opening a port on your router.

Headroom is a client for the Screen Sharing built into macOS (RFB/VNC on TCP port 5900). There is nothing to install on the Mac: turn on Screen Sharing and Headroom can connect from your iPhone, iPad or another Mac. On your home network, it finds your Macs automatically.

Away from home, the usual answer is port forwarding — which puts Screen Sharing on the open internet. Tailscale avoids that. Install it on the device you are holding and on the Mac you want to reach, and the two join the same private network (a tailnet). Headroom then connects to the Mac's Tailscale address exactly as it would on your Wi‑Fi, and the traffic travels inside Tailscale's WireGuard tunnel. No port on your router is opened, and Screen Sharing is never exposed to the internet.

Headroom works with Tailscale, but they are separate products from separate companies. Tailscale (by Tailscale Inc.) provides the private network; Headroom provides the screen — it has no VPN or networking layer of its own, and works just as well on a plain local network without Tailscale. tailscale.com

What you need

  • Headroom on the device you will use (iPhone, iPad or Mac).
  • The Mac you want to reach, with Screen Sharing turned on (step 1 below).
  • A Tailscale account, and the Tailscale app on both devices.

Setup

  1. 1

    Turn on Screen Sharing on the Mac

    On the Mac, open System Settings › General › Sharing and turn on Screen Sharing. You will sign in with a user account on that Mac (recommended). If you prefer a separate VNC password instead, tap the ⓘ next to Screen Sharing to set one.

  2. 2

    Install Tailscale on both devices

    Install Tailscale on the Mac and on the device running Headroom, and sign in with the same Tailscale account. That puts both devices on the same tailnet.

  3. 3

    Note the Mac's Tailscale address

    In Tailscale, find the Mac's MagicDNS name (for example mac-mini.tailXXXX.ts.net) or its Tailscale IP address (100.x.y.z). Either works as the host in the next step; the MagicDNS name is easier to remember.

  4. 4

    Add the connection in Headroom

    Open Headroom. In the Remote Macs list, tap + in the top right to open Add a connection. Fill in: Name (e.g. Office iMac); Host name / IP address — the MagicDNS name or Tailscale IP from step 3; Port — 5900; Username (macOS account) — the account you sign in with on that Mac. Password is optional; if you leave it blank, Headroom asks when connecting. Tap Save.

    Automatic discovery only works on your local network. The “Macs on your network” section is populated by Bonjour, which does not cross Tailscale. A Mac reached over Tailscale will not appear there — you must add it by hand, as above.

  5. 5

    Connect

    Tap the connection you saved and sign in. From now on it is one tap from Saved connections, from anywhere your device has internet access.

The Remote Macs list on the Mac version. + in the top right opens Add a connection; “Macs on your network” only shows Macs on the same local network.
The Remote Macs list on the Mac version. + in the top right opens Add a connection; “Macs on your network” only shows Macs on the same local network.

Good to know

Wake-on-LAN does not reach across Tailscale

Headroom can wake a sleeping Mac from the list (the Wake button, when you have entered its MAC address). That works by broadcasting a magic packet on the local network, and broadcasts do not travel through Tailscale. A Mac that has gone to sleep cannot be woken from outside, so either set it not to sleep (System Settings › Energy, or Displays on a laptop) or wake it from another device on the same local network first.

If you use Tailscale ACLs

If your tailnet restricts traffic with access controls, allow TCP port 5900 to the Mac from the device running Headroom. The default Tailscale policy already allows this.

Nothing extra on the Mac

Screen Sharing is part of macOS. Tailscale is the only thing you add to the Mac, and it is the same Tailscale you would install for anything else.

Headroom is free for 3 minutes of connection per day. Headroom Pro is a one-time purchase (not a subscription) with unlimited connection time, and it is shared across iPhone, iPad and Mac on the same Apple Account.

Tailscale is a registered trademark of Tailscale Inc. WireGuard is a registered trademark of Jason A. Donenfeld. Headroom is developed by MusicFlow and is not affiliated with or endorsed by Tailscale Inc. Mac, iPhone, iPad and macOS are trademarks of Apple Inc.