All systems operational 21 locations · null network Pay with crypto · ∅ KYC
Start / Solutions / Self-hosted VPN
Workload playbook

WireGuard / Outline VPN VPS — No KYC, Crypto

NulNet self-hosted VPN abstract: encrypted tunnel around a VPS cube

Self-host WireGuard, Outline, OpenVPN or Shadowsocks on a no-ID VPS from $5.49: unmetered port, your keys, your daemon. Reykjavik or Amsterdam.

Der Artikeltext ist auf Englisch. Header, Katalog und Kasse sind übersetzt.

What people actually run

Commercial VPNs run the same protocol you can put on your own box. Mullvad: WireGuard documents WireGuard as their default tunnel, Proton VPN: WireGuard configs shows Proton exporting WireGuard configs, and IVPN: WireGuard on Linux is IVPN's Linux path — those companies sell a client plus a shared fleet. The self-hosted alternative is to buy a VPS with coins, skip KYC, and install WireGuard official site or Outline (Jigsaw) directly, keeping the private key on hardware under your account. Tailscale install overlays a mesh on WireGuard (Headscale is the self-hosted control plane), Outline installs in about five minutes, and OpenVPN still works off an existing playbook. In every case the host rents the IP; it does not operate the VPN.

VPS from $3* (fund $50+), storage 1–5 TB NVMe from $24/mo annual-eff, dedicated with IPMI from $30.80/mo. Crypto invoice, no KYC.

Launch now

Who this is for

Pick a path

A few devices, friends, travel
Sentry at $7.50 list ($6.00 annual-eff), WireGuard, Amsterdam when the users are in the EU. USDT keeps the invoice dollar-shaped.
A small team, no app store
Outline (Jigsaw) on the Ranger ($12.50 / $10.00). One manager key hands out many clients.
Payment-graph privacy
Same VPS. Settle in XMR and the rail stops pointing at the tunnel.
Whole NIC, no noisy neighbour
Dedicated from $30.80/mo annual-eff — buy a dedicated server with crypto on the same account.

Playbook

From crypto invoice to a tunnel
  1. Buy a VPS with Bitcoin or USDT. No passport. Email and a 12-character password.
  2. Install from WireGuard quick start or Outline (Jigsaw). Open the UDP/TCP port you chose.
  3. Amsterdam for EU latency. Iceland if jurisdiction is the product.

Limits

A personal VPN endpoint is an allowed workload; scanning, spam and attacks launched through it are not, and one peer's abuse reads as yours in the ticket queue. The host rents root access and an unmetered port — it does not sell Mullvad, Proton or IVPN, and it does not hand out shared exit IPs, which is precisely the property that keeps a private endpoint off the blocklists shared commercial pools land on.

Is port 51820 open?

Yes — every UDP/TCP port is yours to assign, and the unmetered uplink means tunnel throughput tracks the port speed rather than a quota.

KYC to run a VPN?

No. Signup is a token or an email plus a 12-character password, then a crypto invoice; the daemon is yours to install minutes after provisioning.

Do you sell a VPN subscription?

No. You buy a VPS or a dedicated server and run WireGuard, Outline or whatever else yourself — there is no client app, fleet or shared exit on this catalog.

WireGuard in Iceland?

Yes. Reykjavik is at checkout with the +20% flag premium published up front; Amsterdam and most other flags bill base list.

Outline or Shadowsocks?

Both are allowed — you install them on your box. Nested virtualization is enabled if you wrap the daemon in Docker or need to test inside a VM.

Tailscale / Headscale?

Allowed. You run the control plane and hold the coordination data; the host neither operates a mesh nor terminates any of your tunnels.

Ready to launch?

Build the box — VPS, storage or bare metal — create the password, pay the invoice that follows.