Authentication is a lifecycle
Sign-in is one part of the system. Enrollment, recovery, sensitive account changes, and session termination also influence the security of user accounts.
Avoid revealing unnecessary information
Responses that disclose whether an account exists can assist unwanted discovery. Review messages and behavior across login and recovery flows, rather than focusing only on the visible wording.
Make verification deliberate
Consider stronger verification for sensitive actions. Design the experience with the risks of the application in mind, and review the full flow as the product changes.
Further reading
This is an introductory overview, not a comprehensive security assessment. For deeper implementation guidance, see OWASP: Authentication Guidance.