0) Word you want is fingerprinting ?
1) They can already do this at the login point before the email is send
2) It is more likely, for general users, such that users reuse passwords and get stuffed often