Expose your home server to the internet
Quick answer
If you have a real public IP, forward the port on your router and point DNS at it (with dynamic DNS if it changes). If you're behind CGNAT or want a stable, all-protocol setup, use a tunnel: Cloudflare Tunnel for websites, Tailscale for private device access, or Get Real IP to route a dedicated static public IP to your server for any protocol — web, game servers, email, SSH, and more.
You've got something running at home — a website, Nextcloud, Jellyfin, a game server, Home Assistant — and you want to reach it from outside. There are five common ways to do it. Which one fits depends on whether you have a real public IP and what you're exposing.
1. Port forwarding (if you have a real public IP)
The classic method: log into your router, forward the external port to your server's LAN IP and port, and point your domain at your public IP. Works for any protocol.
Only works if you actually have a public IP on your router. If you're behind CGNAT, there's nothing to forward and this silently fails — the number-one reason "port forwarding doesn't work."
2. Dynamic DNS (for a changing public IP)
If you have a real but dynamic public IP, a dynamic DNS client updates a hostname whenever your IP changes so your domain keeps pointing at you. Pair it with port forwarding.
Trade-off: it only papers over a changing IP for DNS. IP-based firewall allowlists, TLS pinned to an address, and email reverse DNS all still break when the IP moves. And it does nothing for CGNAT.
3. Cloudflare Tunnel (websites only)
Runs an outbound tunnel from your server to Cloudflare and exposes a local web service publicly, free, bypassing CGNAT.
Trade-off: HTTP/HTTPS only — no game servers, email, SSH on custom ports, VoIP, or raw TCP/UDP — and Cloudflare terminates TLS at its edge, so it can see your traffic in plaintext.
4. Mesh VPN like Tailscale (private access)
If only you and your own devices need access, a mesh VPN is ideal — reach your server from anywhere without opening any ports, and it bypasses CGNAT.
Trade-off: it's private. People who aren't on your VPN — friends on your game server, a webhook from a third-party service, the general public — can't reach you.
5. A dedicated static IP over a tunnel (Get Real IP)
Your server opens an outbound WireGuard tunnel and gets a dedicated static public IPv4 routed to it. Inbound traffic for that IP flows down the tunnel. It combines the strengths of the others without their main limits:
- Works behind CGNAT (outbound tunnel) — like Cloudflare Tunnel and Tailscale.
- Reachable by anyone on the public internet — unlike a mesh VPN.
- Any protocol — unlike an HTTP-only tunnel.
- Stable, dedicated address with reverse DNS — unlike dynamic DNS.
- Compatible with your own domain name (optional) — point an A record at the fixed IP.
- End-to-end encrypted — TLS terminates on your server, not a middlebox.
- No router config, no VPS — works on a server, router, or even a laptop.
How to choose
Not behind CGNAT and exposing a website? Port forwarding + dynamic DNS is free and fine. Just a website and don't mind the edge seeing traffic? Cloudflare Tunnel. Only your own devices? Tailscale. Need a real public IP the whole internet can reach on any protocol — game servers, email, SSH, or you're stuck behind CGNAT? A dedicated static IP over a tunnel is the general-purpose answer.
