If you have received a Threat Alert, this means the volume of DMARC failure samples received in the last hour, originating from outside of your Sender Inventory, has exceeded a preset statistical threshold. This may indicate the start of a phishing attack against the domain reported.
To review the messages being reported, you can go to Analyze > Failure Samples. Failure Samples are comprised of the forensic data we receive from our participating receivers. Forensic data is reported in real-time. You do not have to worry about doing anything further. Agari will be sending the URI's found to the takedown vendor you have configured. We will send you an alert when the attack has ended.