Need help on securing dovecot - Postfix

What is the use of this process dovenull (Dovecot’s unauthorized user) ? Are these processes for real users?
I only have 4 users but i constantly see a few processes under : dovenull (Dovecot’s unauthorized user)

Can you give a few quick steps on how to secure Postfix and dovecot from hacking attempts or unauthorized users please?

deploy fail2ban and be strict… 3 times and ban for month or longer