To get the process name/PID, run the folowing command as root:
lsof -i TCP
and look for pop3s (995). Note, that the process must be connected at the time you run the command.
Wireshark can be then used to log the communication to see what is send/received, but the communication will be probable encrypted.