Signup on a site I run asked people to prove they owned their email address, and then asked them again.
First a six-digit code, emailed and typed back in. Only after that does the account get created. Then, on creation, the auth service sent its own confirmation email with a link in it.
Two emails. One address. Same question asked twice.
It read as thorough. It was actually a fork in the data, and it had already put a real user somewhere the system has no sensible answer for.
The state nobody designed






