The main reason I haven't jumped into hosting wireguard rather than using Tailscale is mainly because I reach for Tailscale to avoid exposing my home server to the public internet.
It works over UDP so it doesn't even send any acknowledgement or error response to unauthenticated or non-handshake packets.