I think the spec should say that, when a receiver makes a verification request, it MUST include such a header, in order to mitigate abuse. The value should be set to the sender's IP address.
It looks like Akismet/WordPress settled on X-Pingback-Forwarded-For, but I think X-Forwarded-For is sufficient and has the right semantics. (We don't need X-whatever-Forwarded-For for every different type of pingback/linkback/etc., right? They're all doing the same thing.)
A little more detail on the indiewebcamp wiki.