How do you handle duplicate, non-verifiers email? Would you create two non-verified records?
If the first user created the record, but the second one legitimately owns it, then the second user will not be able to use their email address - that doesn't seem right to me