I'd have an improvement suggestion to make this process less fragile:
- let the user log in even if their email address hasn't been verified yet (this would also solve the pw right/wrong indication issue)
- when a new user creates a new account, keep it in a 'limited' state (before asking for credit card data for example...) to make it obvious that the email has not been verified yet.
- right beside the email address please provide a "Resend verification email" button which the user could press without support staff intervention
- in case existing users changing their email address, keep the original one fully active as long as the new one has not been not verified successfully.
