Zerotier relaying my home devices but direct on friends devices

I am self-hosting Zerotier and having the interesting issue that while all my friends’ computers get direct connections, the computers on my home network are all relayed. I have spent the last hour or so making sure each computer’s firewall allows zerotier but this has been fruitless. I am hosting the service through docker and the strangest thing is the machine the container is hosted on is being relayed.

My best guess to the issue is that I am on Tmobile’s weird isp and behind cgnat. though I’m not sure why this would cause issues with connecting on my lan.

any help would be appreciated.