Is the redirect at the registrar or the server?
Time to do a password audit.
Search the email on Google, 1 result:
http://netcomber.com/pornmaxim.com
a quick search of pornset.com reveals SOA info for DNS as:
pornset.com SOA 1 day ns55.pornset.com. cicasouris.gmail.com. 2013101501 86400 7200 3600000 86400
Do a historical Domain search of that email and find an old not privacy protected domain registration maybe for countrypoll.com, see what comes back.