Every site (with a few rare exceptions) lets you confirm whether an email is a real account or not. You can block the reset password and login flows ("If you've entered a valid email address, we will email you instructions to reset your password" / "Your username and/or password is incorrect").
But every site still exposes it during the sign-up process ("You already have an account. Login here >"). Hiding it during the login flow is largely security theater leading to a poor user experience making people guess & check which email address they used for your service.
If you cannot do more advanced risk analysis: a) email the user after a few failed attempts, b) lock the account down for a period of time, c) lock that IP out from attempting any logins for a period of time, and most importantly, d) monitor lock outs. If an account is getting locked out frequently, be proactive and reach out. 99 out of 100 times it's the user struggling with things like your password requirements, but 1 out of 100 it might be an attacker.