This would appear to be a Dmarcian question rather than a DMARC one as the
Threat/Unknown is a Dmarcian classification rather than a DMARC one. More
broadly, a/some receiver(s) and/or Dmarcian would appear to have decided at
about the time that you made your change to reclassify a bunch of mail
We have Google Apps for Business set-up with our domain name for our business.
Since making the change to fully reject mail that fails dmarc, the number of
messages counted as coming through "Forwarders" on our dmarc reports when run
through this tool https://dmarcian.com/dmarc-xml/