The best measure? Let any login pass, just generate a fake account if the credentials were wrong.
You can prove ownership of the email? You can log in - worst case, after a password reset. So why have a password?
email: ______________ [Log in]
The "Log in" button results in a "Check your inbox and click the link in the email that we just sent you" page.
Source: https://appear.in/ used this flow from the very beginning, before it was destroyed in a trademark dispute. EDIT: now it is https://whereby.com/user/login
Though the amount of times I went a long time between logging in, got the wrong credentials and got scared very quickly when all of my notes had vanished :P