how to design a policy enforcement system, that prevents dictionary attack on forget password flow? [on hold]

Use case is to prevent any dictionary attack on forget password flow, where attacker can trigger any no. of emails using forget password flow.