- Tailscale is a WireGuard VPN that joins your own devices into one private network. Traffic is end-to-end encrypted; even when it passes through Tailscale's relay servers they can't read it.
- The Personal plan is free: up to 6 users and unlimited devices, checked on September 29, 2026. iPhone needs iOS 15 or later, Android needs Android 8 or later.
- Two phones: about 10 minutes. Install Tailscale on the phone by the crib and on yours, sign both in to the same account, connect once at home. Mamoon then reaches the baby phone from anywhere.
- A Wi-Fi camera (Tapo, Hikvision…) can't run Tailscale. A Home Assistant or go2rtc server can, and a home computer can share the whole network as a subnet router. That last one is the advanced setup.
- Away from home you get the same thing as at home: sound, picture and cry alerts over mobile data. Nothing goes through a Mamoon server, because there isn't one.
Why not just use the camera maker's cloud, or open a port?
Three ways exist to see a camera at home from a phone that isn't.
- The maker's cloud. A Tapo, Nest or Nanit camera streams to the company's servers and their app fetches it from there. It works the moment you sign in, which is why people choose it. The price is that your nursery passes through, and often sits on, somebody else's servers, guarded by an account that is one reused password away from a stranger. The safety guide walks through the documented cases.
- Port forwarding. You tell the router to expose the camera to the internet. The UK's National Cyber Security Centre advises turning port forwarding and UPnP off precisely because "cyber criminals can exploit these technologies to potentially access devices on your network, such as smart cameras." TP-Link's own Tapo FAQ says RTSP and ONVIF "are not recommended for long-term exposure on a public IP" and points to a VPN instead. Don't do this one.
- A VPN. Your phone joins your home network over an encrypted tunnel, and the camera never learns it isn't at home. Tailscale turns what used to be an evening with the router manual into two app installs and a login.
Tailscale builds on WireGuard and documents that its "architecture provides end-to-end encryption for all network communications, whether devices connect directly or through a relayed connection." When a direct connection between your phones isn't possible, its DERP relays forward the packets, but "because Tailscale private keys never leave the local device that generated them, it's impossible for a DERP server to decrypt your traffic." Other options, such as WireGuard set up on the router yourself or ZeroTier (free for 10 devices), do the same job with more, or different, effort; this guide sticks to Tailscale because it is what Mamoon walks you through in its settings.
Setup 1: the camera is an old phone
This is the common case with Mamoon, where an old iPhone or Android by the crib is the camera, and the easiest one, because a phone can run Tailscale itself. Setting up the baby phone is in the old phone guide; this adds remote access on top.
- Create a Tailscale account. Go to tailscale.com and sign in with an Apple, Google, Microsoft or GitHub login; Tailscale doesn't do its own passwords. The Personal plan is free.
- Install Tailscale on the phone by the crib. App Store on iPhone (iOS 15 or later), Google Play on Android (Android 8 or later). Open it, tap Get Started, allow the VPN configuration when the phone asks, and sign in with the same account.
- Install Tailscale on your own phone the same way, with the same account. Both phones now show up in the Tailscale app as members of one private network. Leave Tailscale switched on on both.
- Connect once at home. With both phones on your Wi-Fi, open Mamoon on the baby phone and choose "Stay with the baby", then connect from your phone as usual. Mamoon notes the baby phone's Tailscale address for later.
- Leave the house. Turn Wi-Fi off on your phone to test it: Mamoon keeps showing the crib over mobile data. From now on Mamoon uses the home Wi-Fi when you are home and Tailscale when you aren't.
Setup 2: the camera runs through Home Assistant or go2rtc
If your cameras already pass through go2rtc, whether in Home Assistant or Frigate, the server is the thing to put on Tailscale, not the camera. Home Assistant has a community Tailscale add-on: install it from the add-on store, start it, open its web UI and sign in to your Tailscale account. Your phone, with Tailscale installed as in setup 1, can then reach the go2rtc stream from anywhere; in Mamoon you enter the server's Tailscale address instead of its home one. The rest, stream names and the G.711 audio requirement, is in the Home Assistant guide.
If you already reach your Home Assistant dashboard through Tailscale, Mamoon rides the same connection.
Setup 3: a Wi-Fi camera read directly (Tapo and friends)
A Tapo, Hikvision, Dahua or Imou camera that Mamoon reads over RTSP, as in the IP camera guide, can't install Tailscale. Something at home has to lend it a connection. Tailscale calls this a subnet router: a device on your network that "extends your Tailscale network to include devices that don't or can't run the Tailscale client." A Raspberry Pi, a NAS, an always-on computer or the Home Assistant add-on (its advertise_routes option) can all do it; Tailscale lists Linux, macOS, Windows, Android and Apple TV.
The gist: on that device you tell Tailscale to advertise your home subnet, typically 192.168.1.0/24, and then approve the route once in the Tailscale admin console under the machine's Subnets. From then on your phone, away from home, can reach every address on your home network, including the camera. Mamoon shows a checklist for this in its settings so you can tick it off step by step.
What do you get away from home?
The same monitor, over mobile data. Sound and picture from the crib, the Calm / Stirring / Crying states, cry alerts as ordinary notifications, and the morning overview. Cry detection still runs on the phone by the baby, so no audio goes anywhere but to you. If the connection drops, Mamoon turns gray after about 20 seconds and tells you it isn't monitoring, which over a shaky mobile signal is the alert you'll be glad of.
Video costs data, so on a small mobile plan the "Sound only" view is the thrifty choice. And what stays private at home stays private on the road: no Mamoon account, no Mamoon cloud, no clip stored anywhere. The one account in the picture is your Tailscale login, so give it two-factor authentication the way you would your email.
When Tailscale isn't the answer
- You want remote viewing with zero setup. That is what the maker's cloud sells, and for a camera used mostly from work, it is a fair trade. Just turn on two-factor authentication.
- The camera is off at the wall. A VPN can't switch on a camera in Tapo's privacy mode or on a smart plug; a Home Assistant automation can, and the Home Assistant guide shows how Mamoon triggers one.
- You need two-way talk, lullabies or recordings. Mamoon has none of those, at home or away.
- You want to watch two rooms at once. Mamoon shows one camera per parent phone.
Frequently asked questions
Is Tailscale really free for this?
Yes. The Personal plan is free with up to 6 users and unlimited devices, according to Tailscale's pricing page on September 29, 2026. Two or three phones and a home server are well inside that.
Does the video go through Tailscale's servers?
Only when your phones can't reach each other directly, and then through DERP relays that only forward already-encrypted packets. Tailscale states the private keys never leave your devices, so a relay can't decrypt the stream. Nothing ever goes through a Mamoon server; there isn't one.
Do I have to turn Tailscale on every time I leave the house?
No. Leave it on on both phones. At home Mamoon uses the Wi-Fi; away it uses Tailscale. You don't switch anything.
Do I need MagicDNS?
No. Tailscale gives every device a stable address on your private network, and MagicDNS (on by default for networks created since October 2022) adds a name to it. Mamoon remembers the baby phone by itself after the first connection at home.
What about a grandparent who watches on their own phone?
Add their phone to your Tailscale account, or invite them as one of the six free users. Then they connect like any other parent phone.
Can I watch a Tapo camera remotely without a home server?
Not through Tailscale, since the camera can't run it. Your options are the Tapo app's own cloud viewing, or a small always-on device at home acting as a subnet router. Port forwarding is the third option; TP-Link and the NCSC both advise against it.
Sources
- Tailscale pricing: Personal plan free, up to 6 users, unlimited user devices (all sources opened September 29, 2026)
- Tailscale: encryption (WireGuard, end-to-end whether direct or relayed) and Tailscale: DERP relay servers can't decrypt traffic; used when a direct connection isn't possible
- Tailscale: install on iOS (iOS 15 or later, VPN configuration prompt) and Tailscale for Android on Google Play (Android 8 or later)
- Tailscale: sign in with Apple, Google, GitHub, Microsoft and others; no email-and-password accounts
- Tailscale: subnet routers (advertise routes, approve in the admin console; Linux, macOS, Windows, Android, Apple TV)
- Tailscale: MagicDNS, enabled by default for tailnets created on or after October 20, 2022
- Home Assistant Community Add-on: Tailscale (install, sign in via the web UI, advertise_routes empty by default, routes approved in the admin console)
- UK NCSC: smart security cameras and baby monitors, disable UPnP and port forwarding
- TP-Link Tapo FAQ: RTSP and ONVIF only on trusted local networks, not for long-term exposure on a public IP; use a VPN
- ZeroTier pricing: free for 10 devices, personal use
Spotted a mistake or an outdated figure? Write to [email protected].
