I don’t know the answer to most of your questions, as I haven’t tried using the free plan since the message limits were introduced.
To understand the message flow better, you should probably add #define BLYNK_DEBUG to your sketch (if you don’t have it already, you’ll also need #define BLYNK_PRINT Serial in your sketch as well).
This rather old, and I suspect somewhat outdated, topic will help you decode some of the messages…
There is an authentication exchange at startup, but this doesn’t use that many messages. If you’re using Blynk.syncAll() or multiple Blynk.syncVirtual(Vpin) in BLYNK_CONNECTED() then this could easily create many more messages. Don’t forget that every sync request will trigger a response, so each virtual datastream synchronised is two messages.
Also, if you’re doing setProperty commands then these are messages too.
Pete.