'mask' will not start the service, not even as a dependency to another service; instead it will rather let the dependent service fail to start.
Masking removes the unit from consideration altogether, so even if a unit depends on it, it won't start. That means that units with a Requires dependency will also fail, as a dependency is missing.
So typically a fairly top-level unit (like postgresql) will declare itself that it's wanted by a top-level target (`WantedBy=multi-user.target`) which means that enabling/disabling will actually turn the service on and off, unless something else depends on it in which case disabling it does mean the explicit dependency to multi-user.target will be missing, but the unit will be pulled in wherever it's actually depended on.
There are some differences in the details, of course. But a "disabled" service can be manually started.