We're talking about client request headers, right? Why even bother with such a thing? Malicious users will just spoof those, you're only going to annoy legitimate users.