Legal is a referral business, and assistants are becoming a referral channel: someone asks for an employment lawyer nearby, and the answer is assembled from whatever each firm's raw HTML provides. The 60 law firm websites in our corpus average 53 out of 100 on those signals — exactly the corpus average — with 32% under 50.
Firms do the fundamentals better than most sectors: 57% had schema.org business data, 67% had SPF on the domain and only 3% were missing a page title. The recurring gap is the description layer — 28% had no meta description, so nothing in their HTML says what kind of law they practise — and DMARC adoption was just 33%, which for a profession that moves money by email is its own risk.
A domain without SPF and DMARC can be impersonated in email that looks like it came from the firm. The records are public DNS entries — checking them sends no mail — and adoption among the firms we scanned (67% SPF, 33% DMARC) means most firms have the first record and not the one that tells receiving servers to enforce it. For a business whose email routinely carries engagement letters and wire instructions, that is a cheap fix with a real payoff.
In order: a meta description that names your practice areas and city; one populated JSON-LD block with name, full address and telephone in the served HTML; a DMARC record on the domain. Then confirm nothing upstream blocks the AI crawlers in robots.txt. The free scan measures each of these for your domain in about a minute — no account, and results you can hand to whoever runs your site.
On fundamentals, yes — 57% schema adoption and 67% SPF in the 60-firm cut are both above the corpus averages of 46% and 53%. Overall they land exactly on the corpus average: 53 out of 100, with 32% of sites under 50.
No. A directory can rank for your name, but an assistant answering a who-should-I-hire question reads your site's own HTML for practice areas, address and phone. If those only exist behind JavaScript, they are invisible to the crawlers that matter.
Because the domain is the firm. In our lawyer cut only 33% of domains had DMARC — the record that tells receiving mail servers to reject mail impersonating you. It is one DNS TXT record, and the scan reads it without sending any email.
No — at most thirteen read-only requests to publicly served pages, one at a time, only when a person asks for the scan. It does not log in, submit forms, or read anything not already public.
Where does your site stand? The scan is free, takes about 60 seconds, and needs no account. It fetches your homepage exactly the way GPTBot, ClaudeBot and PerplexityBot do and tells you what they receive.