Where does the huge amount of "<unknown>" iCloud Keychain items come from and what is their purpose?
Solution 1:
Messages and FaceTime does per device encryption, so these would map to key pairs generated for device to cloud encrypted devices.
The com.apple is simply a naming convention for the subsystem that claims the entry - and not an actual dns name.
I wouldn’t worry about them till you have tens of thousands and you can always sign out of messaging on all your devices and then try and clean things, but in my experience these self regulate and don’t impair performance if you just focus on the items you know and interact with.