Your configuration is okay.
Declude sends you an E-Mail if the second threshold was reached. Hijack moves now all sending mails from the affected IP-Address to the folder spam\hold2. To release the IP-Address, the service of Declude needs to be restarted, which is a bit boring.
So you get one E-Mail per captured IP-Address. To be honest, i never had the case, that several IP-Addresses where be captured on one day. Therefore i can't confirm, that you get a warning for the following attacks.
Hope this helps.