Table of Contents
The only spec that matters: monthly transfer
WireGuard encrypts and forwards packets; it does not compute anything. A 512 MB server with one shared core saturates a home connection without effort. What a VPN does consume is the provider's monthly transfer allowance, because every byte you route through the tunnel leaves the server again on its way to the site you asked for. Browsing and messaging for a couple of devices is a small number; streaming video through the tunnel every evening is a large one. Buy the plan whose allowance covers the second case if you do it, and the cheapest box on the page if you do not.
Two things do not matter and are often sold as if they did: CPU count and disk size. One thing matters more than people expect: the exit city, because it decides both your latency and where the internet thinks you are.
US plans ranked by transfer per dollar
Monthly price and included transfer from each provider's page or public API on the same day (September 2026). Transfer per dollar is the allowance divided by the monthly price; "unlimited" plans are listed with their port speed instead.
| Provider, plan | Monthly | Transfer | Per dollar | RAM | US exits | Note |
|---|---|---|---|---|---|---|
| Contabo, Cloud VPS 4 | $6.60 | Unlimited at 200 Mbit/s | n/a | 8 GB | Carlstadt NJ, St. Louis, Seattle | Intro price for 24 months; fair-use terms apply |
| InterServer, 1 slice | $3 | 2 TB | 667 GB per $ | 2 GB | New York City, Los Angeles, Dallas | Monthly only, no refund |
| RackNerd, 512 MB KVM | $26.99 per year | 500 GB | 222 GB per $ (annualised) | 512 MB | Many, including New York, LA, Dallas | A year paid up front |
| Vultr, vc2-1c-1gb | $5 | 1 TB | 200 GB per $ | 1 GB | 9 cities | Hourly |
| Vultr, vc2-1c-0.5gb-v6 | $2.50 | 0.5 TB | 200 GB per $ | 512 MB | New Jersey, Atlanta | IPv6 only: no use as a VPN for IPv4 sites |
| DigitalOcean, Basic 1 GB | $6 | 1 TB | 167 GB per $ | 1 GB | New York, San Francisco and others | Per-second billing |
| Vultr, vc2-1c-0.5gb | $3.50 | 0.5 TB | 143 GB per $ | 512 MB | New Jersey | Cheapest with IPv4 |
| Hetzner, CPX11 (Ashburn) | $20.49 | 1 TB | 49 GB per $ | 2 GB | Ashburn, Hillsboro | EU plans include 20 TB but are not US exits |
Two caveats on the table. Vultr's $2.50 plan has no IPv4 address, which makes it useless as a VPN for the ordinary internet, so its per-dollar figure is theoretical. And Hetzner's famous 20 TB allowance belongs to its German and Finnish servers; as a US exit it offers 1 TB for $20.49, which is the worst ratio on the page.
InterServer: 2 TB for $3
InterServer's 1-slice plan (1 core, 2 GB, 40 GB SSD, 2 TB transfer, shared 10 Gbps port) costs $3 a month in New York City, Los Angeles or Dallas (September 2026). For a VPN that is four times Vultr's allowance at three-fifths of the price, with three US exits to choose from and an IPv4 address included. The 2 GB of RAM is beside the point for WireGuard but means the same box can also run a small web app, a Pi-hole style DNS filter or a Nextcloud instance next to the tunnel.
The trade is InterServer's usual one: month-to-month billing with no trial, no refund and no hourly option. For a VPN you intend to keep, that is fine; for a one-evening experiment, Vultr's hourly $3.50 box is the better tool. The InterServer review has the ordering steps and the first-hour checklist; the WireGuard section below picks up after that.
Vultr, Contabo, RackNerd, DigitalOcean, Hetzner
Vultr is the pick when you want the exit in a specific city (it has nine in the US) or want to spin the server up for an evening and destroy it: $3.50 with IPv4 and 0.5 TB, or $5 for 1 TB, billed hourly. Contabo is the pick if you will stream heavily: unlimited transfer for $6.60, with the 200 Mbit/s port as the ceiling, which is still several times a typical home upload; read the fair-use terms. RackNerd is the pick for the lowest annual cost, at $26.99 a year for 512 MB with 500 GB, if you are sure you will keep it. DigitalOcean matches Vultr's allowances at $6 for 1 TB. Hetzner only makes sense as a VPN exit if you want a European exit, where its 20 TB allowance is unmatched; in the US it is the expensive option.
WireGuard in ten minutes
On any Ubuntu or Debian VPS from the table. Do the basics first (updates, a non-root user, key-only SSH; the InterServer review has the commands), then:
1. Install and generate keys
apt install -y wireguard
umask 077
wg genkey | tee /etc/wireguard/server.key | wg pubkey > /etc/wireguard/server.pub
wg genkey | tee /etc/wireguard/phone.key | wg pubkey > /etc/wireguard/phone.pub
2. Server config
Replace eth0 with your interface name (ip route | grep default shows it) and paste the key contents where indicated.
# /etc/wireguard/wg0.conf
[Interface]
Address = 10.8.0.1/24
ListenPort = 51820
PrivateKey = <contents of server.key>
PostUp = iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
PostDown = iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE
[Peer]
PublicKey = <contents of phone.pub>
AllowedIPs = 10.8.0.2/32
3. Forwarding, firewall, start
echo 'net.ipv4.ip_forward=1' >> /etc/sysctl.conf && sysctl -p
ufw allow 51820/udp
systemctl enable --now wg-quick@wg0
wg show
4. Client config
Put this in the WireGuard app on the phone or laptop (or make a QR code from it with qrencode -t ansiutf8 < phone.conf after apt install qrencode). AllowedIPs = 0.0.0.0/0 sends all traffic through the tunnel; the DNS line stops leaks.
[Interface]
PrivateKey = <contents of phone.key>
Address = 10.8.0.2/32
DNS = 1.1.1.1
[Peer]
PublicKey = <contents of server.pub>
Endpoint = YOUR_SERVER_IP:51820
AllowedIPs = 0.0.0.0/0
PersistentKeepalive = 25
Add a second device by generating another key pair and another [Peer] block with 10.8.0.3/32, then systemctl restart wg-quick@wg0. Check your public IP from the client afterwards; it should be the server's.
What providers will and will not tolerate
A personal VPN for your own devices is an ordinary use of a VPS everywhere on this page. What gets accounts closed is what comes through the tunnel: torrent traffic that triggers copyright notices, scraping that trips abuse filters, or reselling access so that strangers' traffic exits from your IP. Keep the tunnel for your own devices, read the acceptable-use policy of the provider you pick, and remember that the IP is the provider's: a complaint about it lands on your account.
One more point of hygiene: the VPS is a single-hop VPN, and the provider can see that your traffic exits from its server. That is fine for privacy from a coffee-shop network, for region-locked content, and for a stable IP to whitelist. It is not anonymity, and no page selling a $3 server should tell you it is.
If you would rather not run a server: a commercial VPN
Everything above assumes you want your own server: a fixed IP that is yours, one exit location, and ten minutes of setup. If what you actually want is an app that connects from a phone or laptop to servers in many countries, with no administration, a commercial VPN service is the right product and a VPS is the wrong one. The trade is control for convenience: on a VPS the provider sees only that traffic exits from your server; with a VPN service, the service itself is the party you are trusting, and its no-logs statement is the thing to read.
One such service, priced from its own site in September 2026: Turbo VPN sells a Gold plan billed at $89.99 every 27 months (its page shows $3.33 a month as the equivalent) and a Platinum plan at $109.99 every 24 months ($4.58 a month equivalent), each with a 30-day money-back guarantee, apps for Windows, macOS, Android, iOS and Chrome, and IKEv2, OpenVPN and L2TP/IPsec protocols. Its site states a no-logs policy and a free tier with a handful of servers and ads on mobile. We have not tested it and make no claim about its speed or its logging beyond what it publishes; compare its per-month figure with a $3 slice that is yours alone, and decide by whether you want an app or a server.
Affiliate link: BestUSAVPS may earn a commission if you buy a Turbo VPN plan through it. The comparison above is unchanged by that.