Best Cheap VPS for a VPN in 2026: Transfer Allowances Compared, WireGuard Setup

A VPN server needs almost no CPU or RAM. What it burns is monthly transfer, so this page ranks US plans by transfer per dollar, then walks through a WireGuard setup that takes about ten minutes (September 2026).

✓ US datacenters only
✓ Prices and allowances from provider pages and APIs
✓ Updated September 2026

Short answer

  • Best transfer per dollar on a monthly plan: InterServer, $3 for 2 TB (plus 2 GB of RAM you will not need), with New York, Los Angeles or Dallas as the exit.
  • Cheapest monthly price: Vultr, $2.50 (IPv6-only) or $3.50 with 0.5 TB, hourly billing, nine US exits.
  • Unlimited transfer, slower port: Contabo, $6.60 for unlimited traffic at 200 Mbit/s.
  • Cheapest per year: RackNerd, $26.99 a year for 512 MB with 500 GB.
See current InterServer plans →

Affiliate link: BestUSAVPS may earn a commission if you buy from InterServer through it. Other provider links on this page are plain links.

The only spec that matters: monthly transfer

WireGuard encrypts and forwards packets; it does not compute anything. A 512 MB server with one shared core saturates a home connection without effort. What a VPN does consume is the provider's monthly transfer allowance, because every byte you route through the tunnel leaves the server again on its way to the site you asked for. Browsing and messaging for a couple of devices is a small number; streaming video through the tunnel every evening is a large one. Buy the plan whose allowance covers the second case if you do it, and the cheapest box on the page if you do not.

Two things do not matter and are often sold as if they did: CPU count and disk size. One thing matters more than people expect: the exit city, because it decides both your latency and where the internet thinks you are.

US plans ranked by transfer per dollar

Monthly price and included transfer from each provider's page or public API on the same day (September 2026). Transfer per dollar is the allowance divided by the monthly price; "unlimited" plans are listed with their port speed instead.

Provider, planMonthlyTransferPer dollarRAMUS exitsNote
Contabo, Cloud VPS 4$6.60Unlimited at 200 Mbit/sn/a8 GBCarlstadt NJ, St. Louis, SeattleIntro price for 24 months; fair-use terms apply
InterServer, 1 slice$32 TB667 GB per $2 GBNew York City, Los Angeles, DallasMonthly only, no refund
RackNerd, 512 MB KVM$26.99 per year500 GB222 GB per $ (annualised)512 MBMany, including New York, LA, DallasA year paid up front
Vultr, vc2-1c-1gb$51 TB200 GB per $1 GB9 citiesHourly
Vultr, vc2-1c-0.5gb-v6$2.500.5 TB200 GB per $512 MBNew Jersey, AtlantaIPv6 only: no use as a VPN for IPv4 sites
DigitalOcean, Basic 1 GB$61 TB167 GB per $1 GBNew York, San Francisco and othersPer-second billing
Vultr, vc2-1c-0.5gb$3.500.5 TB143 GB per $512 MBNew JerseyCheapest with IPv4
Hetzner, CPX11 (Ashburn)$20.491 TB49 GB per $2 GBAshburn, HillsboroEU plans include 20 TB but are not US exits

Two caveats on the table. Vultr's $2.50 plan has no IPv4 address, which makes it useless as a VPN for the ordinary internet, so its per-dollar figure is theoretical. And Hetzner's famous 20 TB allowance belongs to its German and Finnish servers; as a US exit it offers 1 TB for $20.49, which is the worst ratio on the page.

InterServer: 2 TB for $3

InterServer's 1-slice plan (1 core, 2 GB, 40 GB SSD, 2 TB transfer, shared 10 Gbps port) costs $3 a month in New York City, Los Angeles or Dallas (September 2026). For a VPN that is four times Vultr's allowance at three-fifths of the price, with three US exits to choose from and an IPv4 address included. The 2 GB of RAM is beside the point for WireGuard but means the same box can also run a small web app, a Pi-hole style DNS filter or a Nextcloud instance next to the tunnel.

The trade is InterServer's usual one: month-to-month billing with no trial, no refund and no hourly option. For a VPN you intend to keep, that is fine; for a one-evening experiment, Vultr's hourly $3.50 box is the better tool. The InterServer review has the ordering steps and the first-hour checklist; the WireGuard section below picks up after that.

See current InterServer plans →

Vultr, Contabo, RackNerd, DigitalOcean, Hetzner

Vultr is the pick when you want the exit in a specific city (it has nine in the US) or want to spin the server up for an evening and destroy it: $3.50 with IPv4 and 0.5 TB, or $5 for 1 TB, billed hourly. Contabo is the pick if you will stream heavily: unlimited transfer for $6.60, with the 200 Mbit/s port as the ceiling, which is still several times a typical home upload; read the fair-use terms. RackNerd is the pick for the lowest annual cost, at $26.99 a year for 512 MB with 500 GB, if you are sure you will keep it. DigitalOcean matches Vultr's allowances at $6 for 1 TB. Hetzner only makes sense as a VPN exit if you want a European exit, where its 20 TB allowance is unmatched; in the US it is the expensive option.

WireGuard in ten minutes

On any Ubuntu or Debian VPS from the table. Do the basics first (updates, a non-root user, key-only SSH; the InterServer review has the commands), then:

1. Install and generate keys

apt install -y wireguard
umask 077
wg genkey | tee /etc/wireguard/server.key | wg pubkey > /etc/wireguard/server.pub
wg genkey | tee /etc/wireguard/phone.key | wg pubkey > /etc/wireguard/phone.pub

2. Server config

Replace eth0 with your interface name (ip route | grep default shows it) and paste the key contents where indicated.

# /etc/wireguard/wg0.conf
[Interface]
Address = 10.8.0.1/24
ListenPort = 51820
PrivateKey = <contents of server.key>
PostUp   = iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
PostDown = iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE

[Peer]
PublicKey = <contents of phone.pub>
AllowedIPs = 10.8.0.2/32

3. Forwarding, firewall, start

echo 'net.ipv4.ip_forward=1' >> /etc/sysctl.conf && sysctl -p
ufw allow 51820/udp
systemctl enable --now wg-quick@wg0
wg show

4. Client config

Put this in the WireGuard app on the phone or laptop (or make a QR code from it with qrencode -t ansiutf8 < phone.conf after apt install qrencode). AllowedIPs = 0.0.0.0/0 sends all traffic through the tunnel; the DNS line stops leaks.

[Interface]
PrivateKey = <contents of phone.key>
Address = 10.8.0.2/32
DNS = 1.1.1.1

[Peer]
PublicKey = <contents of server.pub>
Endpoint = YOUR_SERVER_IP:51820
AllowedIPs = 0.0.0.0/0
PersistentKeepalive = 25

Add a second device by generating another key pair and another [Peer] block with 10.8.0.3/32, then systemctl restart wg-quick@wg0. Check your public IP from the client afterwards; it should be the server's.

What providers will and will not tolerate

A personal VPN for your own devices is an ordinary use of a VPS everywhere on this page. What gets accounts closed is what comes through the tunnel: torrent traffic that triggers copyright notices, scraping that trips abuse filters, or reselling access so that strangers' traffic exits from your IP. Keep the tunnel for your own devices, read the acceptable-use policy of the provider you pick, and remember that the IP is the provider's: a complaint about it lands on your account.

One more point of hygiene: the VPS is a single-hop VPN, and the provider can see that your traffic exits from its server. That is fine for privacy from a coffee-shop network, for region-locked content, and for a stable IP to whitelist. It is not anonymity, and no page selling a $3 server should tell you it is.

If you would rather not run a server: a commercial VPN

Everything above assumes you want your own server: a fixed IP that is yours, one exit location, and ten minutes of setup. If what you actually want is an app that connects from a phone or laptop to servers in many countries, with no administration, a commercial VPN service is the right product and a VPS is the wrong one. The trade is control for convenience: on a VPS the provider sees only that traffic exits from your server; with a VPN service, the service itself is the party you are trusting, and its no-logs statement is the thing to read.

One such service, priced from its own site in September 2026: Turbo VPN sells a Gold plan billed at $89.99 every 27 months (its page shows $3.33 a month as the equivalent) and a Platinum plan at $109.99 every 24 months ($4.58 a month equivalent), each with a 30-day money-back guarantee, apps for Windows, macOS, Android, iOS and Chrome, and IKEv2, OpenVPN and L2TP/IPsec protocols. Its site states a no-logs policy and a free tier with a handful of servers and ads on mobile. We have not tested it and make no claim about its speed or its logging beyond what it publishes; compare its per-month figure with a $3 slice that is yours alone, and decide by whether you want an app or a server.

See Turbo VPN plans →

Affiliate link: BestUSAVPS may earn a commission if you buy a Turbo VPN plan through it. The comparison above is unchanged by that.

Frequently Asked Questions

What is the cheapest VPS for a VPN?

By monthly price, Vultr's $2.50 IPv6-only instance or its $3.50 IPv4 one, both with 0.5 TB of transfer. By transfer per dollar, InterServer's $3 slice with 2 TB. On an annual plan, RackNerd's $26.99 a year 512 MB box with 500 GB. Which is cheapest depends on how much you will route through it: a phone and a laptop use a fraction of 500 GB; streaming video through the tunnel does not (September 2026).

How much transfer does a personal VPN use?

Everything you send through the tunnel counts twice at the server: once in from you, once out to the site, and providers count outbound (or both directions, check the terms). Browsing and messaging for two devices is typically tens of gigabytes a month. Video streaming through the tunnel is what pushes usage into the hundreds of gigabytes. Size the plan to the streaming, not the browsing.

Do VPS providers allow running a VPN?

A personal VPN for your own devices is a normal use on all the providers on this page. Reselling VPN access, running a public exit node, or torrenting copyrighted material through it are the things acceptable-use policies prohibit, and the provider's abuse team will act on complaints about the IP. Read the acceptable-use policy before you buy, and keep the VPN for your own traffic.

WireGuard or OpenVPN?

WireGuard. It is built into the Linux kernel, its configuration is a few lines, its clients exist for every phone and desktop, and it reconnects cleanly when your phone changes networks. OpenVPN still makes sense if a client device only supports OpenVPN or you need TCP port 443 to get through a restrictive network.

Is 512 MB enough for a VPN server?

Yes. WireGuard uses almost no memory and little CPU at personal-VPN speeds. The reasons to buy more than 512 MB are that you also want to run something else on the box, or that the only 512 MB plans are IPv6-only or annual. InterServer's 2 GB at $3 is often the same price as a smaller box elsewhere; the InterServer setup guide covers the account side and the backup guide what to do about the fact that it has no snapshots.

Which US location should the VPN exit from?

Wherever you want to appear to be, and near you for speed. InterServer offers New York City, Los Angeles and Dallas; Vultr covers nine US cities; DigitalOcean has New York and San Francisco among others. For a US user on the East Coast, a New Jersey or New York exit keeps latency low; for content that checks region, any US exit works.

Sources

Prices and transfer allowances were read from the providers' own pages or public APIs on the same day (September 2026). The WireGuard steps are standard Ubuntu and Debian configuration. This page contains no throughput measurements of our own.

Disclosure: the InterServer links and the Turbo VPN plans link on this page are affiliate links and BestUSAVPS may earn a commission if you buy through them. Other provider links are plain links. Neither changed the table above.