In practice
They usually appear on a site after a compromise, not by the owner’s choice. Finding them is a security task first.
Check the rendered page rather than the source, and review any template a third party can edit.
Why it matters
They are an explicit spam policy violation with no legitimate use.
On a hacked site they are the payload, which means the real problem is an unpatched system, not the links.
Related terms