If a website has a reset password facility (which will e-mail the account holder a reset link), does this facility reveal too much information by allowing someone to probe who holds an account by entering various e-mail addresses?
On a login screen you can get around it revealing who holds an account by giving a generic "E-mail or password is incorrect" message when incorrect details are entered. Which could mean an account doesn't exist or that the password is wrong.
The only way I can think of not revealing who holds an account through a password reset link is to provide a generic message saying "You have been sent a reset link to your e-mail address, if you had an account, otherwise you'll need to create a new account" or words to that effect, whether or not a reset link could be successfully sent.